{
  "schema_version": "1.7.0",
  "id": "MGASA-2026-0388",
  "published": "2026-09-09T18:01:33Z",
  "modified": "2026-09-09T16:54:44Z",
  "summary": "Updated thunderbird packages fix security vulnerabilities",
  "details": "Uninitialized memory in MIME parsing. (CVE-2026-84639)\nOne byte overflow read in mail parser. (CVE-2026-84640)\nInformation disclosure due to malicious IMAP server response.\n(CVE-2026-84641)\nCalendar invitation attachments could launch local executables.\n(CVE-2026-84637)\nAllowed UNC hostnames for attachments interpreted as a regular\nexpression. (CVE-2026-84642)\nSandbox escape in the Remote Settings Client component. (CVE-2026-75874)\nPrivilege escalation in the DOM: Workers component. (CVE-2026-16365)\nUse-after-free in the JavaScript: GC component. (CVE-2026-84118)\nSandbox escape due to use-after-free in the DOM: Navigation component.\n(CVE-2026-84119)\nUse-after-free in the Audio/Video component. (CVE-2026-84120)\nSandbox escape due to use-after-free in the DOM: Security component.\n(CVE-2026-84121)\nUse-after-free in the Audio/Video component. (CVE-2026-84122)\nPrivilege escalation due to use-after-free in the Graphics: WebGPU\ncomponent. (CVE-2026-84123)\nUse-after-free in the DOM: Core & HTML component. (CVE-2026-84124)\nUse-after-free in the DOM: Core & HTML component. (CVE-2026-84125)\nPrivilege escalation in the DOM: Navigation component. (CVE-2026-16371)\nPrivilege escalation in the Application Update component.\n(CVE-2026-74952)\nSite isolation issue in the DOM: Navigation component. (CVE-2026-84129)\nInformation disclosure in the Graphics: WebGPU component.\n(CVE-2026-84130)\nPrivilege escalation due to invalid pointer in the Graphics component.\n(CVE-2026-84131)\nInformation disclosure in the Networking: HTTP component.\n(CVE-2026-84132)\nSite isolation issue in the DOM: Push Subscriptions component.\n(CVE-2026-84133)\nOther issue in the Profile Backup component. (CVE-2026-84134)\nOther issue in the DOM: Navigation component. (CVE-2026-84136)\nSpoofing issue in the DOM: Core & HTML component. (CVE-2026-84137)\nClickjacking issue in the DOM: Events component. (CVE-2026-84139)\nSite isolation issue in the DOM: Navigation component. (CVE-2026-84140)\nInteger overflow in the Graphics: ImageLib component. (CVE-2026-84141)\nInternally found bugs fixed in Thunderbird 155, Thunderbird ESR 153.2\nand Thunderbird ESR 140.15. (CVE-2026-84143)\nInternally found bugs fixed in Thunderbird 155 and Thunderbird ESR\n153.2. (CVE-2026-84144)\nInternally found bugs fixed in Thunderbird 155, Thunderbird ESR 153.2\nand Thunderbird ESR 140.15. (CVE-2026-84145)\n",
  "upstream": [
    "CVE-2026-84637",
    "CVE-2026-84639",
    "CVE-2026-84640",
    "CVE-2026-84641",
    "CVE-2026-84642",
    "CVE-2026-75874",
    "CVE-2026-16365",
    "CVE-2026-84118",
    "CVE-2026-84119",
    "CVE-2026-84120",
    "CVE-2026-84121",
    "CVE-2026-84122",
    "CVE-2026-84123",
    "CVE-2026-84124",
    "CVE-2026-84125",
    "CVE-2026-74952",
    "CVE-2026-84129",
    "CVE-2026-16371",
    "CVE-2026-84130",
    "CVE-2026-84131",
    "CVE-2026-84132",
    "CVE-2026-84133",
    "CVE-2026-84134",
    "CVE-2026-84136",
    "CVE-2026-84137",
    "CVE-2026-84139",
    "CVE-2026-84140",
    "CVE-2026-84141",
    "CVE-2026-84143",
    "CVE-2026-84144",
    "CVE-2026-84145"
  ],
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://advisories.mageia.org/MGASA-2026-0388.html"
    },
    {
      "type": "REPORT",
      "url": "https://bugs.mageia.org/show_bug.cgi?id=36245"
    },
    {
      "type": "WEB",
      "url": "https://www.thunderbird.net/en-US/thunderbird/140.14.1esr/releasenotes/"
    },
    {
      "type": "WEB",
      "url": "https://www.thunderbird.net/en-US/thunderbird/153.1.1esr/releasenotes/"
    },
    {
      "type": "WEB",
      "url": "https://www.thunderbird.net/en-US/thunderbird/140.15.0esr/releasenotes/"
    },
    {
      "type": "WEB",
      "url": "https://www.thunderbird.net/en-US/thunderbird/153.2.0esr/releasenotes/"
    },
    {
      "type": "ADVISORY",
      "url": "https://www.mozilla.org/en-US/security/advisories/mfsa2026-87/"
    },
    {
      "type": "ADVISORY",
      "url": "https://www.mozilla.org/en-US/security/advisories/mfsa2026-88/"
    }
  ],
  "affected": [
    {
      "package": {
        "ecosystem": "Mageia:10",
        "name": "thunderbird",
        "purl": "pkg:rpm/mageia/thunderbird?arch=source&distro=mageia-10"
      },
      "ranges": [
        {
          "type": "ECOSYSTEM",
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "153.2.0-1.mga10"
            }
          ]
        }
      ],
      "ecosystem_specific": {
        "section": "core"
      }
    },
    {
      "package": {
        "ecosystem": "Mageia:10",
        "name": "thunderbird-l10n",
        "purl": "pkg:rpm/mageia/thunderbird-l10n?arch=source&distro=mageia-10"
      },
      "ranges": [
        {
          "type": "ECOSYSTEM",
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "153.2.0-1.mga10"
            }
          ]
        }
      ],
      "ecosystem_specific": {
        "section": "core"
      }
    },
    {
      "package": {
        "ecosystem": "Mageia:9",
        "name": "thunderbird",
        "purl": "pkg:rpm/mageia/thunderbird?arch=source&distro=mageia-9"
      },
      "ranges": [
        {
          "type": "ECOSYSTEM",
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "140.15.0-1.mga9"
            }
          ]
        }
      ],
      "ecosystem_specific": {
        "section": "core"
      }
    },
    {
      "package": {
        "ecosystem": "Mageia:9",
        "name": "thunderbird-l10n",
        "purl": "pkg:rpm/mageia/thunderbird-l10n?arch=source&distro=mageia-9"
      },
      "ranges": [
        {
          "type": "ECOSYSTEM",
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "140.15.0-1.mga9"
            }
          ]
        }
      ],
      "ecosystem_specific": {
        "section": "core"
      }
    }
  ],
  "credits": [
    {
      "name": "Mageia",
      "type": "COORDINATOR",
      "contact": [
        "https://wiki.mageia.org/en/Packages_Security_Team"
      ]
    }
  ]
}
