Updated thunderbird packages fix security vulnerabilities
Publication date: 09 Sep 2026Modification date: 09 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-84637 , CVE-2026-84639 , CVE-2026-84640 , CVE-2026-84641 , CVE-2026-84642 , CVE-2026-75874 , CVE-2026-16365 , CVE-2026-84118 , CVE-2026-84119 , CVE-2026-84120 , CVE-2026-84121 , CVE-2026-84122 , CVE-2026-84123 , CVE-2026-84124 , CVE-2026-84125 , CVE-2026-74952 , CVE-2026-84129 , CVE-2026-16371 , CVE-2026-84130 , CVE-2026-84131 , CVE-2026-84132 , CVE-2026-84133 , CVE-2026-84134 , CVE-2026-84136 , CVE-2026-84137 , CVE-2026-84139 , CVE-2026-84140 , CVE-2026-84141 , CVE-2026-84143 , CVE-2026-84144 , CVE-2026-84145
Description
Uninitialized memory in MIME parsing. (CVE-2026-84639)
One byte overflow read in mail parser. (CVE-2026-84640)
Information disclosure due to malicious IMAP server response.
(CVE-2026-84641)
Calendar invitation attachments could launch local executables.
(CVE-2026-84637)
Allowed UNC hostnames for attachments interpreted as a regular
expression. (CVE-2026-84642)
Sandbox escape in the Remote Settings Client component. (CVE-2026-75874)
Privilege escalation in the DOM: Workers component. (CVE-2026-16365)
Use-after-free in the JavaScript: GC component. (CVE-2026-84118)
Sandbox escape due to use-after-free in the DOM: Navigation component.
(CVE-2026-84119)
Use-after-free in the Audio/Video component. (CVE-2026-84120)
Sandbox escape due to use-after-free in the DOM: Security component.
(CVE-2026-84121)
Use-after-free in the Audio/Video component. (CVE-2026-84122)
Privilege escalation due to use-after-free in the Graphics: WebGPU
component. (CVE-2026-84123)
Use-after-free in the DOM: Core & HTML component. (CVE-2026-84124)
Use-after-free in the DOM: Core & HTML component. (CVE-2026-84125)
Privilege escalation in the DOM: Navigation component. (CVE-2026-16371)
Privilege escalation in the Application Update component.
(CVE-2026-74952)
Site isolation issue in the DOM: Navigation component. (CVE-2026-84129)
Information disclosure in the Graphics: WebGPU component.
(CVE-2026-84130)
Privilege escalation due to invalid pointer in the Graphics component.
(CVE-2026-84131)
Information disclosure in the Networking: HTTP component.
(CVE-2026-84132)
Site isolation issue in the DOM: Push Subscriptions component.
(CVE-2026-84133)
Other issue in the Profile Backup component. (CVE-2026-84134)
Other issue in the DOM: Navigation component. (CVE-2026-84136)
Spoofing issue in the DOM: Core & HTML component. (CVE-2026-84137)
Clickjacking issue in the DOM: Events component. (CVE-2026-84139)
Site isolation issue in the DOM: Navigation component. (CVE-2026-84140)
Integer overflow in the Graphics: ImageLib component. (CVE-2026-84141)
Internally found bugs fixed in Thunderbird 155, Thunderbird ESR 153.2
and Thunderbird ESR 140.15. (CVE-2026-84143)
Internally found bugs fixed in Thunderbird 155 and Thunderbird ESR
153.2. (CVE-2026-84144)
Internally found bugs fixed in Thunderbird 155, Thunderbird ESR 153.2
and Thunderbird ESR 140.15. (CVE-2026-84145)
References
- https://bugs.mageia.org/show_bug.cgi?id=36245
- https://www.thunderbird.net/en-US/thunderbird/140.14.1esr/releasenotes/
- https://www.thunderbird.net/en-US/thunderbird/153.1.1esr/releasenotes/
- https://www.thunderbird.net/en-US/thunderbird/140.15.0esr/releasenotes/
- https://www.thunderbird.net/en-US/thunderbird/153.2.0esr/releasenotes/
- https://www.mozilla.org/en-US/security/advisories/mfsa2026-87/
- https://www.mozilla.org/en-US/security/advisories/mfsa2026-88/
- https://www.cve.org/CVERecord?id=CVE-2026-84637
- https://www.cve.org/CVERecord?id=CVE-2026-84639
- https://www.cve.org/CVERecord?id=CVE-2026-84640
- https://www.cve.org/CVERecord?id=CVE-2026-84641
- https://www.cve.org/CVERecord?id=CVE-2026-84642
- https://www.cve.org/CVERecord?id=CVE-2026-75874
- https://www.cve.org/CVERecord?id=CVE-2026-16365
- https://www.cve.org/CVERecord?id=CVE-2026-84118
- https://www.cve.org/CVERecord?id=CVE-2026-84119
- https://www.cve.org/CVERecord?id=CVE-2026-84120
- https://www.cve.org/CVERecord?id=CVE-2026-84121
- https://www.cve.org/CVERecord?id=CVE-2026-84122
- https://www.cve.org/CVERecord?id=CVE-2026-84123
- https://www.cve.org/CVERecord?id=CVE-2026-84124
- https://www.cve.org/CVERecord?id=CVE-2026-84125
- https://www.cve.org/CVERecord?id=CVE-2026-74952
- https://www.cve.org/CVERecord?id=CVE-2026-84129
- https://www.cve.org/CVERecord?id=CVE-2026-16371
- https://www.cve.org/CVERecord?id=CVE-2026-84130
- https://www.cve.org/CVERecord?id=CVE-2026-84131
- https://www.cve.org/CVERecord?id=CVE-2026-84132
- https://www.cve.org/CVERecord?id=CVE-2026-84133
- https://www.cve.org/CVERecord?id=CVE-2026-84134
- https://www.cve.org/CVERecord?id=CVE-2026-84136
- https://www.cve.org/CVERecord?id=CVE-2026-84137
- https://www.cve.org/CVERecord?id=CVE-2026-84139
- https://www.cve.org/CVERecord?id=CVE-2026-84140
- https://www.cve.org/CVERecord?id=CVE-2026-84141
- https://www.cve.org/CVERecord?id=CVE-2026-84143
- https://www.cve.org/CVERecord?id=CVE-2026-84144
- https://www.cve.org/CVERecord?id=CVE-2026-84145
SRPMS
10/core
- thunderbird-153.2.0-1.mga10
- thunderbird-l10n-153.2.0-1.mga10
9/core
- thunderbird-140.15.0-1.mga9
- thunderbird-l10n-140.15.0-1.mga9