Gnoppix Security Announcement - 2026-07-22T20:00:52.404-04:00

Gnoppix Issues Emergency Patch for Firefox ESR Zero-Day

Gnoppix published GSA-6394-1, a critical security update for the firefox-esr package, on March 19, 2026. The patch addresses an actively exploited use-after-free vulnerability in the browser’s JavaScript engine.

The flaw (CVE-2026-2574) allows remote code execution when a user visits a crafted webpage. No workaround exists; immediate upgrades are mandatory.

Affected: All Gnoppix 23/25 and Gnoppix 25 stable releases running firefox-esr.

Actions Required:

  • For Gnoppix 23/25: Upgrade to firefox-esr version 128.9.0esr-1~deb12u1.
  • For Gnoppix 25: Upgrade to firefox-esr version 128.9.0esr-1~deb13u1.

Apply updates immediately via the standard package manager. Users on older Gnoppix releases, like 11 “Bullseye,” must upgrade their operating system to receive support. - Please update your systems.