|
|
Log in / Subscribe / Register

AlmaLinux alert ALSA-2026:49922 (thunderbird)

From:  AlmaLinux Errata Notifications via Announce <announce@lists.almalinux.org>
To:  announce@lists.almalinux.org
Subject:  [Announce] [Security Advisory] ALSA-2026:49922: thunderbird security update (Important)
Date:  Tue, 04 Aug 2026 19:01:50 +0000
Message-ID:  <0100019fce275090-9bbf2e78-32db-4a36-9057-93a226046de1-000000@email.amazonses.com>
Archive-link:  Article

Hi, You are receiving an AlmaLinux Security update email because you subscribed to receive errata notifications from AlmaLinux. AlmaLinux: 8 Type: Security Severity: Important Release date: 2026-08-04 Summary: Mozilla Thunderbird is a standalone mail and newsgroup client. Security Fix(es): * firefox: thunderbird: Site isolation issue in the DOM: Navigation component (CVE-2026-15719) * firefox: thunderbird: Invalid pointer in the JavaScript: WebAssembly component (CVE-2026-15718) * firefox: thunderbird: Mitigation bypass in the Enterprise Policies component (CVE-2026-16390) * firefox: thunderbird: Incorrect boundary conditions in the Audio/Video: cubeb component (CVE-2026-16350) * firefox: thunderbird: Information disclosure in the Storage: IndexedDB component (CVE-2026-16391) * firefox: thunderbird: Site isolation issue in the Networking: HTTP component (CVE-2026-16375) * firefox: thunderbird: Sandbox escape due to use-after-free in the Disability Access APIs component (CVE-2026-16356) * firefox: thunderbird: JIT miscompilation in the JavaScript: WebAssembly component (CVE-2026-16363) * firefox: thunderbird: Memory safety bugs fixed in Firefox ESR 140.13 and Firefox 153 (CVE-2026-16412) * firefox: thunderbird: Same-origin policy bypass in the Networking: DNS component (CVE-2026-16381) * firefox: thunderbird: JIT miscompilation in the JavaScript Engine: JIT component (CVE-2026-16355) * firefox: thunderbird: Memory safety bugs fixed in Firefox ESR 115.38 and Firefox ESR 140.13 (CVE-2026-16361) * firefox: thunderbird: Sandbox escape due to use-after-free in the Disability Access APIs component (CVE-2026-16352) * firefox: thunderbird: Incorrect boundary conditions in the JavaScript: WebAssembly component (CVE-2026-16368) * firefox: thunderbird: Mitigation bypass in the PDF Viewer component (CVE-2026-16377) * firefox: thunderbird: Memory safety bugs fixed in Firefox ESR 115.38, Firefox ESR 140.13 and Firefox 153 (CVE-2026-16360) * firefox: thunderbird: Use-after-free in the WebRTC: Audio/Video component (CVE-2026-16362) * firefox: thunderbird: Site isolation issue in the Graphics: WebRender component (CVE-2026-16358) * firefox: thunderbird: Site isolation issue in the Networking component (CVE-2026-16387) * firefox: thunderbird: Same-origin policy bypass in the DOM: Navigation component (CVE-2026-16349) * firefox: thunderbird: Incorrect boundary conditions in the Graphics component (CVE-2026-16357) * firefox: thunderbird: Sandbox escape due to use-after-free in the DOM: Navigation component (CVE-2026-16351) * firefox: thunderbird: Privilege escalation in the DOM: Navigation component (CVE-2026-16371) * firefox: thunderbird: Privilege escalation in the DOM: Content Processes component (CVE-2026-16379) * firefox: thunderbird: Information disclosure in the Graphics: ImageLib component (CVE-2026-16354) * firefox: thunderbird: Information disclosure in the Framework component in DevTools (CVE-2026-16374) * firefox: thunderbird: Incorrect boundary conditions in the Audio/Video: GMP component (CVE-2026-16359) * firefox: thunderbird: Mitigation bypass in the DOM: Networking component (CVE-2026-16383) * firefox: thunderbird: Integer overflow in the JavaScript: WebAssembly component (CVE-2026-16369) * firefox: thunderbird: Invalid pointer in the DOM: Bindings (WebIDL) component (CVE-2026-16353) * firefox: thunderbird: Privilege escalation in WebExtensions (CVE-2026-16396) * firefox: thunderbird: Information disclosure in the Networking: WebSockets component (CVE-2026-16405) * thunderbird: Off-by-one out of bounds read in MIME header parser for forwarding (CVE-2026-14899) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Full details, updated packages, references, and other related information: https://errata.almalinux.org/8/ALSA-2026-49922.html This message is automatically generated, please don’t reply. For further questions, please, contact us via the AlmaLinux community chat: https://chat.almalinux.org/. Want to change your notification settings? Sign in and manage mailing lists on https://lists.almalinux.org. Kind regards, AlmaLinux Team _______________________________________________ Announce mailing list -- announce@lists.almalinux.org To unsubscribe send an email to announce-leave@lists.almalinux.org


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds