Bonum Certa Men Certa

Firefox ESR 91 Creating Massive Headache for Debian 11 (GNU/Linux)

Guest post by Ryan, reprinted with permission from the original

D

ebian and Mozilla go way back, with endless troubles created by an incompetent upstream for Firefox, which is getting worse by the hour.



Debian tries to produce a stable OS that doesn’t change very much (although you can use backports and Flatpaks to strategically update packages), and this is very important for people who are happy with the way their computer works and don’t want to be on a bug treadmill, like Fedora.



However, you may have noticed that Firefox 78 ESR hasn’t been supported upstream now for over a week and has missed the latest round of security updates from Mozilla, and that Firefox 91.3 ESR is still stuck in the pipes, being packaged only in Experimental and Debian Unstable.



When I went to look at the reasons why, it appears that there are new problems related to Rust, build failures on various supported CPU architectures, and it also demands a newer version of Mesa3d than Debian 11 has, even though the entire OS is barely over a month old (and will be supported for five years).



Mozilla decided to migrate away from GLX and make EGL mandatory, _and_ blacklist the version of Mesa (20.3.5) which ships with Debian 11, demanding at least Mesa 21.



Mesa 21 would otherwise be fine as a Backport package, but now Debian has to choose between backporting a critical component of the OS directly into “Stable” updates (the OpenGL/Vulkan stack and Direct Rendering Interface drivers and libdrm), as well as newer Nvidia proprietary drivers in non-Free for the people who haven’t disembarked that clown car yet in favor of Intel and AMD cards that are truly supported on GNU/Linux, or forcing Firefox ESR 91 to use GLX again by overriding a default preference, which kicks the can down the road 1 year and creates the same problem again later, at which time Mozilla may have removed the GLX code anyway.



And reverting to GLX makes it impossible for users to enable Wayland and WebRender Compositing without knowing that they also need to set Firefox back to EGL and bring in a Backported Mesa package when one arrives.



In the mean time, there are 6 CVEs that are unpatched in Firefox 78.15, and one of those CVE numbers contains bugs (the details of which are still hidden by Mozilla) corresponding to four memory safety issues (which are often crash with potential arbitrary code execution). So really, at least 10 unpatched security issues, and maybe more (because not all patched issues get a CVE even though they may have security implications).



However Debian solves this problem will set more bad precedents and probably the least incorrect way to solve for it, assuming it’s even worth anything to keep Mozilla’s lawyers happy and use the official “branding”, which Mozilla is pissing down the drain these days anyway, is to bring in newer Mesa builds, which undermines the “feature freeze” that keeps Debian Stable running so well.



It’s definitely well past time to “IceWeasel” Firefox again and do whatever they need to do to keep it running securely without compromising the rest of the operating system.

Recent Techrights' Posts

24/7 Wall St. Editor-In-Chief and CEO Calls IBM Is "America’s Worst Big Tech Company", Talent is Leaving, Supposedly Strategic Units Culled
21 hours ago by Douglas A. McIntyre
IBM's Debt Increased Over $5 Billion in 3 Months While IBM Laid Off Many in Europe, US, Confluent, HashiCorp, and Red Hat
An increase of $5,000,000,000+ in debt in just 3 months!
Drama at the European Patent Office (EPO) This Week
We'll be covering the EPO quite a lot this weekend and next week
EPO Cocainegate Escalates - Part VI - The Strikes Go On and On (Major Strike Today)
We'll be covering this later today in relation to what the Office dubs "ethics"
Huge Microsoft Layoffs Coming Shortly (With Financial Report)
There will be lots of slop layoffs. Be ready. It's a bubble.
 
Links 24/04/2026: Zelenskyy Says Ukraine's War Position "Most Stable", Samsung Workers on Strike Due to Pay
Links for the day
Dr. Andy Farnell on Why Calling Slop or Chaff "Hey Hi" (AI) Harm Us All, Except for "Ten or Twenty Rich Industrialists"
"words to avoid"
Recent Happenings at IBM Reaffirm Rumours About the CEO; He Might be Resigning (or Pushed Out) Soon
If the rumours are true (no, we did not check those tax records for ourselves), it's not unthinkable that IBM is already doing what Apple did months ago
Gemini Links 24/04/2026: Public Reticulum Gateway Node, Smol Computers, and Old E-mail
Links for the day
Links 24/04/2026: Intel Abandoning Computer Freedom (Even Further), Iran Reports That American Software and Hardware Remotely Sabotaged/Hijacked During War
Links for the day
The Great Wonders of Slop "Efficiency"
Thankfully nothing was lost in the transmission and lots of work (datacentre emissions) got "done"
IBMers Expect Another Giant Wave of Layoffs, Talk (and Sing) About the PIPs
The media won't be covering the key facts
As We Predicted, Francophonie Countries in the EU and Outside the EU Dumping Microsoft for National Security Reasons
We expected Belgium or some other Francophonie place to do so next
Even to Microsoft Insiders It Seems Like XBox Has Already Died or Surrendered to the Japanese Companies
Now the Microsoft layoffs are evident for people to see
Absolutely Terrible Journalism About Microsoft Layoffs This Week
7 hours ago by Leila Sheridan
SLAPP Censorship - Part 56 Out of 200: 5RB and Brett Wilson LLP's Copy-Paste Machination for Garrett and Graveley
Here is another straightforward example of their junior barrister overusing copy-paste on his Mac
Getting Aggressive Suggestive of Loss - Part II - Lawyers Are Not "Hired Guns" (and Should Never Act Like Ones)
The matter is being investigated
Nadella is Killing Microsoft. Slop Kills It Even Faster.
A decade from now we'll look back at slop like we look back at skateboards
Gemini Links 24/04/2026: Data Breaches and Unofficial Gemini Protocol Specification Archive
Links for the day
Microsoft Offers About 10,000 of Its Senior American (Read: Expensive) Workers to be Laid Off
How many slopfarms and media parrots play along?
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Thursday, April 23, 2026
IRC logs for Thursday, April 23, 2026
SLAPP Censorship - Part 55 Out of 200: Strangled Women, Charged for Strangulation, Cannot Find a Job Now (After Microsoft)
merits public awareness and wider scrutiny
Gemini Links 23/04/2026: Spirituality and Detachment, Shoplifting in the UK, and "Introducing Scout, an iOS Native Gemini Client"
Links for the day
Links 23/04/2026: YouTube Age Limits Expanded and 'Secret' Model With Bug-Finding Hype Campaign 'Leaks'
Links for the day
Media Operatives of Microsoft Paint Microsoft Layoffs as Buyouts (Intentionally False Narrative)
Those are mass layoffs disguised as something else
IBM's Stock Has Collapsed Over 10% in One Day, Insiders Explain What's Happening
Today, due to a lack of time, we mostly present an outline of what people say (not IBM-sponsored media hacks with LLM slop)
Getting Aggressive Suggestive of Loss - Part I - Threats Sent From Burner Accounts Since February, Belatedly Reported to British Police
Threats connected to Graveley or Garrett or 5RB or Brett Wilson LLP [...] We're not dealing with a law firm here; we're dealing with the underworld
EPO Cocainegate Escalates - Part V - Where Does the António Campinos 'Family Affair' Go From Here?
Do cocaine in public, get caught, take paid "sick leave", come back to lead Europe's second-largest organisation
Links 23/04/2026: Legal Trouble for Microsoft, Chronic Fatigue Syndrome, and DMCA Whac-a-Mole
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Wednesday, April 22, 2026
IRC logs for Wednesday, April 22, 2026
Gemini Links 23/04/2026: Sunrise Chasing Season, Going Back to Older Software, New Gemini Client for Mobile Devices
Links for the day
Upcoming Mass Layoffs at Microsoft Not Limited to Gaming/XBox
from Microsoft staff
What Could Run the World Instead of "Linux"
Had it not been for GNU (the software, the licence, the compiler GCC), we'd probably not have Linux and perhaps BSD would be more widespread (no copyleft, so expect proprietary derivatives)
IBM's Shares Have Just Collapsed Again as a Result of the Phony 'Results'
Of course all the so-called news is shallow parroting of IBM or "churnalism" void of real analysis
EPO President to Meet the Union, But He Needs to Resign
Colleagues or workers of the EPO have only just been told that the boyfriend of the sister of "Cocaine Communication Manager" will be talking to the union (SUEPO) tomorrow mornin
Gemini Links 22/04/2026: Movies, Vim, and Bash
Links for the day
International Business Machines Corporation: Paying Peanuts, Getting Monkeys
they don't pay enough to retain key people
No, Finding Security Bugs Takes Time and Care (Human Touch, Real Grasp of Real Code)
This too shall pass
Move to GNU/Linux, Save This Planet
If you are an environmentalist, it's hard to justify still using stuff from Apple or Microsoft
SLAPP Censorship - Part 54 Out of 200: Alex-Matt/Automate Twin Cases, Separated at Birth, Drafted by Brett Wilson LLP and 5RB
Perhaps their solicitor K.C. (not the legal title) sought actual redemption and followed the Cross, not the dagger
When Peak Oil Isn't Just "Alarmist Propaganda"
the current conditions favour less consumption
Combatting Racist Abuse
Take racism seriously
They've Failed to Ruin Our Community, But They Still Try
The cost of liberty is not zero. The cost of it can be supremely high.
IBM "Results" as a Smokescreen to Distract From Mass Layoffs at IBM Every Month in 2026
How can we as a society function if we do not get properly informed and educated about what goes on around us?
'Nuclear Winter' at Microsoft This Summer?
At Microsoft so far this year there have been many layoffs, but the company tries to keep them secret
Links 22/04/2026: LLM Slop "Damaging Users’ Cognitive Abilities", UK-based Publishers Urge CMA to Curb Slop-Wielding Plagiarists Like GAFAM
Links for the day
EPO Cocainegate Escalates - Part IV - António Campinos Allegedly Sleeping With Sister of "Cocaine Communication Manager" Luis Berenguer to Secure Third Mandate
Based on our understanding, "the f---ing president" Campinos - to quote rather than merely paraphrase his description of himself - is dating Ana Berenguer, sister of "Cocaine Communication Manager" (Luis Berenguer) and daughter of another Luis Berenguer, a friend of the late Jorge Campinos (António's father)
Clownflare (Cloudflare) and the 'Ecosystem' It Wants to Replace
Vercel & Next.JS Hacked - Nothing New to Report
Today, or Tonight, Look for What IBM is Hiding, Not What It's Telling Shareholders
It shapes the narrative while cooking the books
Brett Wilson LLP Working for Racists and Losing (at the Same Time It Works for Men Who Assault Women in America)
Brett Wilson LLP is basically attacking whistleblowers
The Corrupt Lecture the Non-Corrupt - Part IV - Demanding Respect From Those You Are Attacking and Robbing
"literature" aimed at staff looks increasingly comical, hypocritical, one might say inappropriate
What It Will Take for More Nations in Europe to Move Fully to GNU/Linux
It would be false to say that France is hostile towards the US
Gemini Links 22/04/2026: Voyage into Cheapness, Heat and Pressure in a Contained Ideal Gas, Tidepools
Links for the day
Links 22/04/2026: YouTube Deletes Channels to Promote US Hegemony, "Kash Patel’s Defamation Suit Against The Atlantic Is Designed To Generate Headlines, Not Win In Court"
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Tuesday, April 21, 2026
IRC logs for Tuesday, April 21, 2026