{
  "schema_version": "1.7.0",
  "id": "MGASA-2026-0346",
  "published": "2026-08-31T16:22:02Z",
  "modified": "2026-08-31T15:00:04Z",
  "summary": "Updated thunderbird packages fix security vulnerabilities",
  "details": "Site isolation issue in the Graphics: CanvasWebGL component.\n(CVE-2026-74934)\nPrivilege escalation in the DOM: Networking component. (CVE-2026-74935)\nUse-after-free in the JavaScript: WebAssembly component.\n(CVE-2026-74936)\nUse-after-free in the JavaScript: GC component. (CVE-2026-74937)\nMitigation bypass in the JavaScript: GC component. (CVE-2026-74938)\nPrivilege escalation in the DOM: Navigation component. (CVE-2026-74939)\nUse-after-free in the Graphics: Text component. (CVE-2026-74940)\nPrivilege escalation in the Graphics: CanvasWebGL component.\n(CVE-2026-74941)\nPrivilege escalation in the Remote Settings Client component.\n(CVE-2026-74942)\nUse-after-free in the Graphics: ImageLib component. (CVE-2026-74943)\nUse-after-free in the DOM: Core & HTML component. (CVE-2026-74944)\nInformation disclosure in the Graphics: Text component. (CVE-2026-74945)\nPrivilege escalation due to incorrect boundary conditions in the\nGraphics: CanvasWebGL component. (CVE-2026-74946)\nPrivilege escalation due to invalid pointer in the Graphics component.\n(CVE-2026-74947)\nInformation disclosure in the Graphics component. (CVE-2026-74948)\nPrivilege escalation in the Downloads API component. (CVE-2026-74950)\nPrivilege escalation in the Networking: Cookies component.\n(CVE-2026-74953)\nInformation disclosure due to side-channel in the Storage: Cache API\ncomponent. (CVE-2026-74954)\nPrivilege escalation in the Request Handling component. (CVE-2026-74955)\nSame-origin policy bypass in the DOM: Service Workers component.\n(CVE-2026-74956)\nMitigation bypass in the Safe Browsing component. (CVE-2026-74957)\nInformation disclosure in the WebRTC component. (CVE-2026-74958)\nMitigation bypass in the Storage: Cache API component. (CVE-2026-74959)\nSite isolation issue in the WebExtensions component. (CVE-2026-74960)\nSide-channel in the Web Audio component. (CVE-2026-74961)\nSite isolation issue in the Networking: Cookies component.\n(CVE-2026-74962)\nSame-origin policy bypass in the Networking: Cookies component.\n(CVE-2026-74963)\nInteger overflow in the Graphics component. (CVE-2026-74964)\nPrivilege escalation in the Shell Integration component.\n(CVE-2026-74965)\nInformation disclosure in the Form Autofill component. (CVE-2026-74966)\nSame-origin policy bypass in the Audio/Video: Playback component.\n(CVE-2026-74967)\nSite isolation issue in the Graphics: WebRender component.\n(CVE-2026-74968)\nUse-after-free in the Layout: Text and Fonts component. (CVE-2026-74969)\nSite isolation issue in the Graphics component. (CVE-2026-74970)\nInformation disclosure in the DOM: UI Events & Focus Handling component.\n(CVE-2026-74971)\nInformation disclosure in the DOM: Push Subscriptions component.\n(CVE-2026-74972)\nUse-after-free in the Graphics: Canvas2D component. (CVE-2026-74949)\nRace condition, use-after-free in the Graphics component.\n(CVE-2026-74973)\nSame-origin policy bypass in the Graphics: ImageLib component.\n(CVE-2026-74974)\nJIT miscompilation in the JavaScript Engine: JIT component.\n(CVE-2026-74976)\nInteger overflow in the Graphics component. (CVE-2026-74977)\nClickjacking issue in the Widget component. (CVE-2026-74978)\nMitigation bypass in the Add-ons Manager component. (CVE-2026-74979)\nSite isolation issue in the Audio/Video: Web Codecs component.\n(CVE-2026-74981)\nDenial-of-service in the Widget component. (CVE-2026-74982)\nMitigation bypass in the Data Loss Prevention component.\n(CVE-2026-74983)\nRace condition in the JavaScript Engine component. (CVE-2026-74984)\nPrivilege escalation in the Enterprise Policies component.\n(CVE-2026-74985)\nSite isolation issue in the CSS Parsing and Computation component.\n(CVE-2026-74986)\nInternally found bugs fixed in Thunderbird ESR 140.14, \nThunderbird ESR 153.1 and Thunderbird 154. (CVE-2026-74987)\nInternally found bugs fixed in Thunderbird ESR 153.1 and Thunderbird 154 \n(CVE-2026-74988)\nInternally found bugs fixed in Thunderbird ESR 140.14, \nThunderbird ESR 153.1 and Thunderbird 154. (CVE-2026-74990)\n",
  "upstream": [
    "CVE-2026-74934",
    "CVE-2026-74935",
    "CVE-2026-74936",
    "CVE-2026-74937",
    "CVE-2026-74938",
    "CVE-2026-74939",
    "CVE-2026-74940",
    "CVE-2026-74941",
    "CVE-2026-74942",
    "CVE-2026-74943",
    "CVE-2026-74944",
    "CVE-2026-74945",
    "CVE-2026-74946",
    "CVE-2026-74947",
    "CVE-2026-74948",
    "CVE-2026-74950",
    "CVE-2026-74953",
    "CVE-2026-74954",
    "CVE-2026-74955",
    "CVE-2026-74956",
    "CVE-2026-74957",
    "CVE-2026-74958",
    "CVE-2026-74959",
    "CVE-2026-74960",
    "CVE-2026-74961",
    "CVE-2026-74962",
    "CVE-2026-74963",
    "CVE-2026-74964",
    "CVE-2026-74965",
    "CVE-2026-74966",
    "CVE-2026-74967",
    "CVE-2026-74968",
    "CVE-2026-74969",
    "CVE-2026-74970",
    "CVE-2026-74971",
    "CVE-2026-74972",
    "CVE-2026-74949",
    "CVE-2026-74973",
    "CVE-2026-74974",
    "CVE-2026-74976",
    "CVE-2026-74977",
    "CVE-2026-74978",
    "CVE-2026-74979",
    "CVE-2026-74981",
    "CVE-2026-74982",
    "CVE-2026-74983",
    "CVE-2026-74984",
    "CVE-2026-74985",
    "CVE-2026-74986",
    "CVE-2026-74987",
    "CVE-2026-74988",
    "CVE-2026-74990"
  ],
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://advisories.mageia.org/MGASA-2026-0346.html"
    },
    {
      "type": "REPORT",
      "url": "https://bugs.mageia.org/show_bug.cgi?id=36124"
    },
    {
      "type": "WEB",
      "url": "https://www.thunderbird.net/en-US/thunderbird/140.14.0esr/releasenotes/"
    },
    {
      "type": "WEB",
      "url": "https://www.thunderbird.net/en-US/thunderbird/153.1.0esr/releasenotes/"
    },
    {
      "type": "ADVISORY",
      "url": "https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/"
    },
    {
      "type": "ADVISORY",
      "url": "https://www.mozilla.org/en-US/security/advisories/mfsa2026-80/"
    }
  ],
  "affected": [
    {
      "package": {
        "ecosystem": "Mageia:10",
        "name": "thunderbird",
        "purl": "pkg:rpm/mageia/thunderbird?arch=source&distro=mageia-10"
      },
      "ranges": [
        {
          "type": "ECOSYSTEM",
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "153.1.0-1.mga10"
            }
          ]
        }
      ],
      "ecosystem_specific": {
        "section": "core"
      }
    },
    {
      "package": {
        "ecosystem": "Mageia:10",
        "name": "thunderbird-l10n",
        "purl": "pkg:rpm/mageia/thunderbird-l10n?arch=source&distro=mageia-10"
      },
      "ranges": [
        {
          "type": "ECOSYSTEM",
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "153.1.0-1.mga10"
            }
          ]
        }
      ],
      "ecosystem_specific": {
        "section": "core"
      }
    },
    {
      "package": {
        "ecosystem": "Mageia:9",
        "name": "thunderbird",
        "purl": "pkg:rpm/mageia/thunderbird?arch=source&distro=mageia-9"
      },
      "ranges": [
        {
          "type": "ECOSYSTEM",
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "140.14.0-1.mga9"
            }
          ]
        }
      ],
      "ecosystem_specific": {
        "section": "core"
      }
    },
    {
      "package": {
        "ecosystem": "Mageia:9",
        "name": "thunderbird-l10n",
        "purl": "pkg:rpm/mageia/thunderbird-l10n?arch=source&distro=mageia-9"
      },
      "ranges": [
        {
          "type": "ECOSYSTEM",
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "140.14.0-1.mga9"
            }
          ]
        }
      ],
      "ecosystem_specific": {
        "section": "core"
      }
    }
  ],
  "credits": [
    {
      "name": "Mageia",
      "type": "COORDINATOR",
      "contact": [
        "https://wiki.mageia.org/en/Packages_Security_Team"
      ]
    }
  ]
}
