Gnoppix Issues Emergency Patch for Firefox ESR Zero-Day
Gnoppix published GSA-6394-1, a critical security update for the firefox-esr package, on March 19, 2026. The patch addresses an actively exploited use-after-free vulnerability in the browser’s JavaScript engine.
The flaw (CVE-2026-2574) allows remote code execution when a user visits a crafted webpage. No workaround exists; immediate upgrades are mandatory.
Affected: All Gnoppix 23/25 and Gnoppix 25 stable releases running firefox-esr.
Actions Required:
- For Gnoppix 23/25: Upgrade to firefox-esr version 128.9.0esr-1~deb12u1.
- For Gnoppix 25: Upgrade to firefox-esr version 128.9.0esr-1~deb13u1.
Apply updates immediately via the standard package manager. Users on older Gnoppix releases, like 11 “Bullseye,” must upgrade their operating system to receive support. - Please update your systems.