Release date:
2026-08-04 10:36:04 UTC
Description:
- update to 140.13.0 ESR (MFSA 2026-72; includes MFSA 2026-64 / 140.12.1 fixes)
- CVE-2026-14899: The code to parse MIME headers for display when forwarding
a message (if the setting to view all headers was enabled) had an
off-by-one error, allowing a single byte to be read from the memory after
the buffer for the headers, and potentially crashing Thunderbird
- CVE-2026-15718: Invalid pointer in the JavaScript: WebAssembly component.
Exploit code for this issue is public
- CVE-2026-15719: Site isolation issue in the DOM: Navigation component.
Exploit code for this issue is public
- CVE-2026-16349: Same-origin policy bypass in the DOM: Navigation component
- CVE-2026-16350: Incorrect boundary conditions in the Audio/Video: cubeb
component
- CVE-2026-16351: Sandbox escape due to use-after-free in the DOM: Navigation
component
- CVE-2026-16352: Sandbox escape due to use-after-free in the Disability
Access APIs component
- CVE-2026-16353: Invalid pointer in the DOM: Bindings (WebIDL) component
- CVE-2026-16354: Information disclosure in the Graphics: ImageLib component
- CVE-2026-16355: JIT miscompilation in the JavaScript Engine: JIT component
- CVE-2026-16356: Sandbox escape due to use-after-free in the Disability
Access APIs component
- CVE-2026-16357: Incorrect boundary conditions in the Graphics component
- CVE-2026-16358: Site isolation issue in the Graphics: WebRender component
- CVE-2026-16359: Incorrect boundary conditions in the Audio/Video: GMP
component
- CVE-2026-16360: Memory safety bugs present in Thunderbird ESR 140.12 and
Thunderbird 152. Some of these bugs showed evidence of memory corruption
and we presume that with enough effort some of these could have been
exploited to run arbitrary code
- CVE-2026-16361: Memory safety bugs present in Thunderbird ESR 140.12. Some
of these bugs showed evidence of memory corruption and we presume that with
enough effort some of these could have been exploited to run arbitrary code
- CVE-2026-16362: Use-after-free in the WebRTC: Audio/Video component
- CVE-2026-16363: JIT miscompilation in the JavaScript: WebAssembly component
- CVE-2026-16368: Incorrect boundary conditions in the JavaScript:
WebAssembly component
- CVE-2026-16369: Integer overflow in the JavaScript: WebAssembly component
- CVE-2026-16371: Privilege escalation in the DOM: Navigation component
- CVE-2026-16374: Information disclosure in the Framework component in
DevTools
- CVE-2026-16375: Site isolation issue in the Networking: HTTP component
- CVE-2026-16377: Mitigation bypass in the PDF Viewer component
- CVE-2026-16379: Privilege escalation in the DOM: Content Processes
component
- CVE-2026-16381: Same-origin policy bypass in the Networking: DNS component
- CVE-2026-16383: Mitigation bypass in the DOM: Networking component
- CVE-2026-16387: Site isolation issue in the Networking component
- CVE-2026-16390: Mitigation bypass in the Enterprise Policies component
- CVE-2026-16391: Information disclosure in the Storage: IndexedDB component
- CVE-2026-16396: Privilege escalation in WebExtensions
- CVE-2026-16405: Information disclosure in the Networking: WebSockets
component
- CVE-2026-16412: Memory safety bugs present in Thunderbird ESR 140.12 and
Thunderbird 152. Some of these bugs showed evidence of memory corruption
and we presume that with enough effort some of these could have been
exploited to run arbitrary code
- CVE-2026-57962: Memory exhaustion via a malicious LDAP address-book server
- CVE-2026-57963: Content injection via HTML chat messages (Matrix/XMPP)
Updated packages:
-
thunderbird-140.13.0-1.el9_2.alma.1.tuxcare.els1.x86_64.rpm
sha:092c7e98cda74a5c8e52e9ca804be7c9b44346bebc3a970d20d5c7ec97bd5c91
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.