Heap buffer overflow in libvpx. Debian's firefox-esr links against the system
libvpx (libvpx9), not the bundled copy in the source tree. The system libvpx in
trixie (1.15.0-2.1+deb13u1) already includes the fix via DSA-6143-1.
The Debian security tracker even notes: "Firefox, Firefox ESR and Thunderbird
use the system libvpx library".
https://security-tracker.debian.org/tracker/CVE-2026-2447