Advisories ยป MGASA-2026-0388

Updated thunderbird packages fix security vulnerabilities

Publication date: 09 Sep 2026
Modification date: 09 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-84637 , CVE-2026-84639 , CVE-2026-84640 , CVE-2026-84641 , CVE-2026-84642 , CVE-2026-75874 , CVE-2026-16365 , CVE-2026-84118 , CVE-2026-84119 , CVE-2026-84120 , CVE-2026-84121 , CVE-2026-84122 , CVE-2026-84123 , CVE-2026-84124 , CVE-2026-84125 , CVE-2026-74952 , CVE-2026-84129 , CVE-2026-16371 , CVE-2026-84130 , CVE-2026-84131 , CVE-2026-84132 , CVE-2026-84133 , CVE-2026-84134 , CVE-2026-84136 , CVE-2026-84137 , CVE-2026-84139 , CVE-2026-84140 , CVE-2026-84141 , CVE-2026-84143 , CVE-2026-84144 , CVE-2026-84145

Description

Uninitialized memory in MIME parsing. (CVE-2026-84639)
One byte overflow read in mail parser. (CVE-2026-84640)
Information disclosure due to malicious IMAP server response.
(CVE-2026-84641)
Calendar invitation attachments could launch local executables.
(CVE-2026-84637)
Allowed UNC hostnames for attachments interpreted as a regular
expression. (CVE-2026-84642)
Sandbox escape in the Remote Settings Client component. (CVE-2026-75874)
Privilege escalation in the DOM: Workers component. (CVE-2026-16365)
Use-after-free in the JavaScript: GC component. (CVE-2026-84118)
Sandbox escape due to use-after-free in the DOM: Navigation component.
(CVE-2026-84119)
Use-after-free in the Audio/Video component. (CVE-2026-84120)
Sandbox escape due to use-after-free in the DOM: Security component.
(CVE-2026-84121)
Use-after-free in the Audio/Video component. (CVE-2026-84122)
Privilege escalation due to use-after-free in the Graphics: WebGPU
component. (CVE-2026-84123)
Use-after-free in the DOM: Core & HTML component. (CVE-2026-84124)
Use-after-free in the DOM: Core & HTML component. (CVE-2026-84125)
Privilege escalation in the DOM: Navigation component. (CVE-2026-16371)
Privilege escalation in the Application Update component.
(CVE-2026-74952)
Site isolation issue in the DOM: Navigation component. (CVE-2026-84129)
Information disclosure in the Graphics: WebGPU component.
(CVE-2026-84130)
Privilege escalation due to invalid pointer in the Graphics component.
(CVE-2026-84131)
Information disclosure in the Networking: HTTP component.
(CVE-2026-84132)
Site isolation issue in the DOM: Push Subscriptions component.
(CVE-2026-84133)
Other issue in the Profile Backup component. (CVE-2026-84134)
Other issue in the DOM: Navigation component. (CVE-2026-84136)
Spoofing issue in the DOM: Core & HTML component. (CVE-2026-84137)
Clickjacking issue in the DOM: Events component. (CVE-2026-84139)
Site isolation issue in the DOM: Navigation component. (CVE-2026-84140)
Integer overflow in the Graphics: ImageLib component. (CVE-2026-84141)
Internally found bugs fixed in Thunderbird 155, Thunderbird ESR 153.2
and Thunderbird ESR 140.15. (CVE-2026-84143)
Internally found bugs fixed in Thunderbird 155 and Thunderbird ESR
153.2. (CVE-2026-84144)
Internally found bugs fixed in Thunderbird 155, Thunderbird ESR 153.2
and Thunderbird ESR 140.15. (CVE-2026-84145)
                

References

SRPMS

10/core

9/core