{
  "schema_version": "1.7.0",
  "id": "MGASA-2026-0449",
  "published": "2026-09-24T16:06:15Z",
  "modified": "2026-09-24T15:01:05Z",
  "summary": "Updated thunderbird & thunderbird-l10n packages fix security vulnerabilities",
  "details": "Ambiguous parsing of mail headers. (CVE-2026-92238)\nBuffer overrun in IMAP. (CVE-2026-92239)\nOut-of-bounds read in IMAP response parser. (CVE-2026-92240)\nUse-after-free in the Audio/Video: Web Codecs component.\n(CVE-2026-92005)\nPrivilege escalation due to incorrect boundary conditions in the\nGraphics: CanvasWebGL component. (CVE-2026-92006)\nPrivilege escalation due to incorrect boundary conditions in the\nGraphics: CanvasWebGL component. (CVE-2026-92007)\nPrivilege escalation due to incorrect boundary conditions in the\nGraphics: CanvasWebGL component. (CVE-2026-92008)\nPrivilege escalation due to incorrect boundary conditions in the\nGraphics: CanvasWebGL component. (CVE-2026-92009)\nPrivilege escalation due to incorrect boundary conditions in the\nGraphics: CanvasWebGL component. (CVE-2026-92010)\nPrivilege escalation due to incorrect boundary conditions in the\nGraphics: CanvasWebGL component. (CVE-2026-92011)\nPrivilege escalation due to incorrect boundary conditions in the\nGraphics: CanvasWebGL component. (CVE-2026-92012)\nPrivilege escalation due to incorrect boundary conditions in the\nGraphics: CanvasWebGL component. (CVE-2026-92013)\nPrivilege escalation due to incorrect boundary conditions in the\nGraphics component. (CVE-2026-92014)\nPrivilege escalation in the WebExtensions component. (CVE-2026-92015)\nUse-after-free in the Disability Access APIs component. (CVE-2026-92016)\nPrivilege escalation in the DOM: Service Workers component.\n(CVE-2026-92017)\nSandbox escape in the DOM: Core & HTML component. (CVE-2026-92018)\nMitigation bypass in the Remote Settings Client component.\n(CVE-2026-92019)\nPrivilege escalation due to incorrect boundary conditions in the\nGraphics: WebRender component. (CVE-2026-92020)\nUse-after-free in the JavaScript Engine: JIT component. (CVE-2026-92021)\nUse-after-free in the DOM: HTML Parser component. (CVE-2026-92022)\nUse-after-free in the XML component. (CVE-2026-92023)\nUse-after-free in the SVG component. (CVE-2026-92024)\nUse-after-free in the DOM: Navigation component. (CVE-2026-92025)\nUse-after-free in the Networking component. (CVE-2026-92026)\nUse-after-free in the DOM: Streams component. (CVE-2026-92027)\nUse-after-free in the DOM: Core & HTML component. (CVE-2026-92028)\nUse-after-free in the SVG component. (CVE-2026-92029)\nMitigation bypass in the DOM: Copy & Paste and Drag & Drop component.\n(CVE-2026-92030)\nInformation disclosure in the Graphics: ImageLib component.\n(CVE-2026-92031)\nSandbox escape due to invalid pointer in the Graphics component.\n(CVE-2026-92032)\nMitigation bypass in the Remote Settings Client component.\n(CVE-2026-92038)\nMitigation bypass in the DOM: Notifications component. (CVE-2026-92039)\nMitigation bypass in the DOM: Networking component. (CVE-2026-92041)\nRace condition in the DOM: Content Processes component. (CVE-2026-92042)\nPrivilege escalation due to incorrect boundary conditions in the\nAudio/Video component. (CVE-2026-92043)\nInformation disclosure in the Networking: HTTP component.\n(CVE-2026-92044)\nSandbox escape due to incorrect boundary conditions in the WebRTC\ncomponent. (CVE-2026-92045)\nUse-after-free in the Graphics component. (CVE-2026-92046)\nPrivilege escalation in the Crash Reporting component. (CVE-2026-92047)\nPrivilege escalation due to uninitialized memory in the Graphics:\nCanvasWebGL component. (CVE-2026-92052)\nPrivilege escalation in the Graphics: CanvasWebGL component.\n(CVE-2026-92053)\nPrivilege escalation in the Memory component. (CVE-2026-92054)\nPrivilege escalation in the DevTools component. (CVE-2026-92055)\nUse-after-free in the Graphics: Text component. (CVE-2026-92056)\nMitigation bypass in the Enterprise Policies component. (CVE-2026-92057)\nUse-after-free in the Graphics component. (CVE-2026-92058)\nIncorrect boundary conditions in the DOM: Editor component.\n(CVE-2026-92059)\nUse-after-free in the Internationalization component. (CVE-2026-92060)\nPrivilege escalation in the Session Restore component. (CVE-2026-92062)\nUse-after-free in the Widget: Gtk component. (CVE-2026-92067)\nSite isolation issue in the Reader Mode component. (CVE-2026-92068)\nSpoofing issue in the DOM: Navigation component. (CVE-2026-92069)\nInformation disclosure in the Networking component. (CVE-2026-92070)\nIncorrect boundary conditions in the Safe Browsing component.\n(CVE-2026-92072)\nPrivilege escalation in the Enterprise Policies component.\n(CVE-2026-92073)\nMitigation bypass in the Popup Blocker component. (CVE-2026-92074)\nMitigation bypass in the Networking component. (CVE-2026-92075)\nIncorrect boundary conditions in the Networking component.\n(CVE-2026-92076)\nDenial-of-service in the SVG component. (CVE-2026-92077)\nDenial-of-service in the Security component. (CVE-2026-92078)\n",
  "upstream": [
    "CVE-2026-92238",
    "CVE-2026-92239",
    "CVE-2026-92240",
    "CVE-2026-92005",
    "CVE-2026-92006",
    "CVE-2026-92007",
    "CVE-2026-92008",
    "CVE-2026-92009",
    "CVE-2026-92010",
    "CVE-2026-92011",
    "CVE-2026-92012",
    "CVE-2026-92013",
    "CVE-2026-92014",
    "CVE-2026-92015",
    "CVE-2026-92016",
    "CVE-2026-92017",
    "CVE-2026-92018",
    "CVE-2026-92019",
    "CVE-2026-92020",
    "CVE-2026-92021",
    "CVE-2026-92022",
    "CVE-2026-92023",
    "CVE-2026-92024",
    "CVE-2026-92025",
    "CVE-2026-92026",
    "CVE-2026-92027",
    "CVE-2026-92028",
    "CVE-2026-92029",
    "CVE-2026-92030",
    "CVE-2026-92031",
    "CVE-2026-92032",
    "CVE-2026-92038",
    "CVE-2026-92039",
    "CVE-2026-92041",
    "CVE-2026-92042",
    "CVE-2026-92043",
    "CVE-2026-92044",
    "CVE-2026-92045",
    "CVE-2026-92046",
    "CVE-2026-92047",
    "CVE-2026-92052",
    "CVE-2026-92053",
    "CVE-2026-92054",
    "CVE-2026-92055",
    "CVE-2026-92056",
    "CVE-2026-92057",
    "CVE-2026-92058",
    "CVE-2026-92059",
    "CVE-2026-92060",
    "CVE-2026-92062",
    "CVE-2026-92064",
    "CVE-2026-92067",
    "CVE-2026-92068",
    "CVE-2026-92069",
    "CVE-2026-92070",
    "CVE-2026-92072",
    "CVE-2026-92073",
    "CVE-2026-92074",
    "CVE-2026-92075",
    "CVE-2026-92076",
    "CVE-2026-92077",
    "CVE-2026-92078"
  ],
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://advisories.mageia.org/MGASA-2026-0449.html"
    },
    {
      "type": "REPORT",
      "url": "https://bugs.mageia.org/show_bug.cgi?id=36318"
    },
    {
      "type": "WEB",
      "url": "https://www.thunderbird.net/en-US/thunderbird/140.16.0esr/releasenotes/"
    },
    {
      "type": "WEB",
      "url": "https://www.thunderbird.net/en-US/thunderbird/153.3.0esr/releasenotes/"
    },
    {
      "type": "ADVISORY",
      "url": "https://www.mozilla.org/en-US/security/advisories/mfsa2026-95/"
    },
    {
      "type": "ADVISORY",
      "url": "https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/"
    }
  ],
  "affected": [
    {
      "package": {
        "ecosystem": "Mageia:10",
        "name": "thunderbird",
        "purl": "pkg:rpm/mageia/thunderbird?arch=source&distro=mageia-10"
      },
      "ranges": [
        {
          "type": "ECOSYSTEM",
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "153.3.0-1.mga10"
            }
          ]
        }
      ],
      "ecosystem_specific": {
        "section": "core"
      }
    },
    {
      "package": {
        "ecosystem": "Mageia:10",
        "name": "thunderbird-l10n",
        "purl": "pkg:rpm/mageia/thunderbird-l10n?arch=source&distro=mageia-10"
      },
      "ranges": [
        {
          "type": "ECOSYSTEM",
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "153.3.0-1.mga10"
            }
          ]
        }
      ],
      "ecosystem_specific": {
        "section": "core"
      }
    },
    {
      "package": {
        "ecosystem": "Mageia:9",
        "name": "thunderbird",
        "purl": "pkg:rpm/mageia/thunderbird?arch=source&distro=mageia-9"
      },
      "ranges": [
        {
          "type": "ECOSYSTEM",
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "140.16.0-1.mga9"
            }
          ]
        }
      ],
      "ecosystem_specific": {
        "section": "core"
      }
    },
    {
      "package": {
        "ecosystem": "Mageia:9",
        "name": "thunderbird-l10n",
        "purl": "pkg:rpm/mageia/thunderbird-l10n?arch=source&distro=mageia-9"
      },
      "ranges": [
        {
          "type": "ECOSYSTEM",
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "140.16.0-1.mga9"
            }
          ]
        }
      ],
      "ecosystem_specific": {
        "section": "core"
      }
    }
  ],
  "credits": [
    {
      "name": "Mageia",
      "type": "COORDINATOR",
      "contact": [
        "https://wiki.mageia.org/en/Packages_Security_Team"
      ]
    }
  ]
}
