|
|
Log in / Subscribe / Register

Mageia alert MGASA-2026-0346 (thunderbird)

From:  Mageia Updates <updates-announce@ml.mageia.org>
To:  updates-announce@ml.mageia.org
Subject:  [updates-announce] MGASA-2026-0346: Updated thunderbird packages fix security vulnerabilities
Date:  Mon, 31 Aug 2026 18:22:57 +0200
Message-ID:  <20260831162257.CA3579FEB0@duvel.mageia.org>
Archive-link:  Article

MGASA-2026-0346 - Updated thunderbird packages fix security vulnerabilities Publication date: 31 Aug 2026 URL: https://advisories.mageia.org/MGASA-2026-0346.html Type: security Affected Mageia releases: 10, 9 CVE: CVE-2026-74934, CVE-2026-74935, CVE-2026-74936, CVE-2026-74937, CVE-2026-74938, CVE-2026-74939, CVE-2026-74940, CVE-2026-74941, CVE-2026-74942, CVE-2026-74943, CVE-2026-74944, CVE-2026-74945, CVE-2026-74946, CVE-2026-74947, CVE-2026-74948, CVE-2026-74950, CVE-2026-74953, CVE-2026-74954, CVE-2026-74955, CVE-2026-74956, CVE-2026-74957, CVE-2026-74958, CVE-2026-74959, CVE-2026-74960, CVE-2026-74961, CVE-2026-74962, CVE-2026-74963, CVE-2026-74964, CVE-2026-74965, CVE-2026-74966, CVE-2026-74967, CVE-2026-74968, CVE-2026-74969, CVE-2026-74970, CVE-2026-74971, CVE-2026-74972, CVE-2026-74949, CVE-2026-74973, CVE-2026-74974, CVE-2026-74976, CVE-2026-74977, CVE-2026-74978, CVE-2026-74979, CVE-2026-74981, CVE-2026-74982, CVE-2026-74983, CVE-2026-74984, CVE-2026-74985, CVE-2026-74986, CVE-2026-74987, CVE-2026-74988, CVE-2026-74990 Description: Site isolation issue in the Graphics: CanvasWebGL component. (CVE-2026-74934) Privilege escalation in the DOM: Networking component. (CVE-2026-74935) Use-after-free in the JavaScript: WebAssembly component. (CVE-2026-74936) Use-after-free in the JavaScript: GC component. (CVE-2026-74937) Mitigation bypass in the JavaScript: GC component. (CVE-2026-74938) Privilege escalation in the DOM: Navigation component. (CVE-2026-74939) Use-after-free in the Graphics: Text component. (CVE-2026-74940) Privilege escalation in the Graphics: CanvasWebGL component. (CVE-2026-74941) Privilege escalation in the Remote Settings Client component. (CVE-2026-74942) Use-after-free in the Graphics: ImageLib component. (CVE-2026-74943) Use-after-free in the DOM: Core & HTML component. (CVE-2026-74944) Information disclosure in the Graphics: Text component. (CVE-2026-74945) Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. (CVE-2026-74946) Privilege escalation due to invalid pointer in the Graphics component. (CVE-2026-74947) Information disclosure in the Graphics component. (CVE-2026-74948) Privilege escalation in the Downloads API component. (CVE-2026-74950) Privilege escalation in the Networking: Cookies component. (CVE-2026-74953) Information disclosure due to side-channel in the Storage: Cache API component. (CVE-2026-74954) Privilege escalation in the Request Handling component. (CVE-2026-74955) Same-origin policy bypass in the DOM: Service Workers component. (CVE-2026-74956) Mitigation bypass in the Safe Browsing component. (CVE-2026-74957) Information disclosure in the WebRTC component. (CVE-2026-74958) Mitigation bypass in the Storage: Cache API component. (CVE-2026-74959) Site isolation issue in the WebExtensions component. (CVE-2026-74960) Side-channel in the Web Audio component. (CVE-2026-74961) Site isolation issue in the Networking: Cookies component. (CVE-2026-74962) Same-origin policy bypass in the Networking: Cookies component. (CVE-2026-74963) Integer overflow in the Graphics component. (CVE-2026-74964) Privilege escalation in the Shell Integration component. (CVE-2026-74965) Information disclosure in the Form Autofill component. (CVE-2026-74966) Same-origin policy bypass in the Audio/Video: Playback component. (CVE-2026-74967) Site isolation issue in the Graphics: WebRender component. (CVE-2026-74968) Use-after-free in the Layout: Text and Fonts component. (CVE-2026-74969) Site isolation issue in the Graphics component. (CVE-2026-74970) Information disclosure in the DOM: UI Events & Focus Handling component. (CVE-2026-74971) Information disclosure in the DOM: Push Subscriptions component. (CVE-2026-74972) Use-after-free in the Graphics: Canvas2D component. (CVE-2026-74949) Race condition, use-after-free in the Graphics component. (CVE-2026-74973) Same-origin policy bypass in the Graphics: ImageLib component. (CVE-2026-74974) JIT miscompilation in the JavaScript Engine: JIT component. (CVE-2026-74976) Integer overflow in the Graphics component. (CVE-2026-74977) Clickjacking issue in the Widget component. (CVE-2026-74978) Mitigation bypass in the Add-ons Manager component. (CVE-2026-74979) Site isolation issue in the Audio/Video: Web Codecs component. (CVE-2026-74981) Denial-of-service in the Widget component. (CVE-2026-74982) Mitigation bypass in the Data Loss Prevention component. (CVE-2026-74983) Race condition in the JavaScript Engine component. (CVE-2026-74984) Privilege escalation in the Enterprise Policies component. (CVE-2026-74985) Site isolation issue in the CSS Parsing and Computation component. (CVE-2026-74986) Internally found bugs fixed in Thunderbird ESR 140.14, Thunderbird ESR 153.1 and Thunderbird 154. (CVE-2026-74987) Internally found bugs fixed in Thunderbird ESR 153.1 and Thunderbird 154 (CVE-2026-74988) Internally found bugs fixed in Thunderbird ESR 140.14, Thunderbird ESR 153.1 and Thunderbird 154. (CVE-2026-74990) References: - https://bugs.mageia.org/show_bug.cgi?id=36124 - https://www.thunderbird.net/en-US/thunderbird/140.14.0esr... - https://www.thunderbird.net/en-US/thunderbird/153.1.0esr/... - https://www.mozilla.org/en-US/security/advisories/mfsa202... - https://www.mozilla.org/en-US/security/advisories/mfsa202... - https://www.cve.org/CVERecord?id=CVE-2026-74934 - https://www.cve.org/CVERecord?id=CVE-2026-74935 - https://www.cve.org/CVERecord?id=CVE-2026-74936 - https://www.cve.org/CVERecord?id=CVE-2026-74937 - https://www.cve.org/CVERecord?id=CVE-2026-74938 - https://www.cve.org/CVERecord?id=CVE-2026-74939 - https://www.cve.org/CVERecord?id=CVE-2026-74940 - https://www.cve.org/CVERecord?id=CVE-2026-74941 - https://www.cve.org/CVERecord?id=CVE-2026-74942 - https://www.cve.org/CVERecord?id=CVE-2026-74943 - https://www.cve.org/CVERecord?id=CVE-2026-74944 - https://www.cve.org/CVERecord?id=CVE-2026-74945 - https://www.cve.org/CVERecord?id=CVE-2026-74946 - https://www.cve.org/CVERecord?id=CVE-2026-74947 - https://www.cve.org/CVERecord?id=CVE-2026-74948 - https://www.cve.org/CVERecord?id=CVE-2026-74950 - https://www.cve.org/CVERecord?id=CVE-2026-74953 - https://www.cve.org/CVERecord?id=CVE-2026-74954 - https://www.cve.org/CVERecord?id=CVE-2026-74955 - https://www.cve.org/CVERecord?id=CVE-2026-74956 - https://www.cve.org/CVERecord?id=CVE-2026-74957 - https://www.cve.org/CVERecord?id=CVE-2026-74958 - https://www.cve.org/CVERecord?id=CVE-2026-74959 - https://www.cve.org/CVERecord?id=CVE-2026-74960 - https://www.cve.org/CVERecord?id=CVE-2026-74961 - https://www.cve.org/CVERecord?id=CVE-2026-74962 - https://www.cve.org/CVERecord?id=CVE-2026-74963 - https://www.cve.org/CVERecord?id=CVE-2026-74964 - https://www.cve.org/CVERecord?id=CVE-2026-74965 - https://www.cve.org/CVERecord?id=CVE-2026-74966 - https://www.cve.org/CVERecord?id=CVE-2026-74967 - https://www.cve.org/CVERecord?id=CVE-2026-74968 - https://www.cve.org/CVERecord?id=CVE-2026-74969 - https://www.cve.org/CVERecord?id=CVE-2026-74970 - https://www.cve.org/CVERecord?id=CVE-2026-74971 - https://www.cve.org/CVERecord?id=CVE-2026-74972 - https://www.cve.org/CVERecord?id=CVE-2026-74949 - https://www.cve.org/CVERecord?id=CVE-2026-74973 - https://www.cve.org/CVERecord?id=CVE-2026-74974 - https://www.cve.org/CVERecord?id=CVE-2026-74976 - https://www.cve.org/CVERecord?id=CVE-2026-74977 - https://www.cve.org/CVERecord?id=CVE-2026-74978 - https://www.cve.org/CVERecord?id=CVE-2026-74979 - https://www.cve.org/CVERecord?id=CVE-2026-74981 - https://www.cve.org/CVERecord?id=CVE-2026-74982 - https://www.cve.org/CVERecord?id=CVE-2026-74983 - https://www.cve.org/CVERecord?id=CVE-2026-74984 - https://www.cve.org/CVERecord?id=CVE-2026-74985 - https://www.cve.org/CVERecord?id=CVE-2026-74986 - https://www.cve.org/CVERecord?id=CVE-2026-74987 - https://www.cve.org/CVERecord?id=CVE-2026-74988 - https://www.cve.org/CVERecord?id=CVE-2026-74990 SRPMS: - 10/core/thunderbird-153.1.0-1.mga10 - 10/core/thunderbird-l10n-153.1.0-1.mga10 - 9/core/thunderbird-140.14.0-1.mga9 - 9/core/thunderbird-l10n-140.14.0-1.mga9


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds