{"id":"MGASA-2026-0346","summary":"Updated thunderbird packages fix security vulnerabilities","details":"Site isolation issue in the Graphics: CanvasWebGL component.\n(CVE-2026-74934)\nPrivilege escalation in the DOM: Networking component. (CVE-2026-74935)\nUse-after-free in the JavaScript: WebAssembly component.\n(CVE-2026-74936)\nUse-after-free in the JavaScript: GC component. (CVE-2026-74937)\nMitigation bypass in the JavaScript: GC component. (CVE-2026-74938)\nPrivilege escalation in the DOM: Navigation component. (CVE-2026-74939)\nUse-after-free in the Graphics: Text component. (CVE-2026-74940)\nPrivilege escalation in the Graphics: CanvasWebGL component.\n(CVE-2026-74941)\nPrivilege escalation in the Remote Settings Client component.\n(CVE-2026-74942)\nUse-after-free in the Graphics: ImageLib component. (CVE-2026-74943)\nUse-after-free in the DOM: Core & HTML component. (CVE-2026-74944)\nInformation disclosure in the Graphics: Text component. (CVE-2026-74945)\nPrivilege escalation due to incorrect boundary conditions in the\nGraphics: CanvasWebGL component. (CVE-2026-74946)\nPrivilege escalation due to invalid pointer in the Graphics component.\n(CVE-2026-74947)\nInformation disclosure in the Graphics component. (CVE-2026-74948)\nPrivilege escalation in the Downloads API component. (CVE-2026-74950)\nPrivilege escalation in the Networking: Cookies component.\n(CVE-2026-74953)\nInformation disclosure due to side-channel in the Storage: Cache API\ncomponent. (CVE-2026-74954)\nPrivilege escalation in the Request Handling component. (CVE-2026-74955)\nSame-origin policy bypass in the DOM: Service Workers component.\n(CVE-2026-74956)\nMitigation bypass in the Safe Browsing component. (CVE-2026-74957)\nInformation disclosure in the WebRTC component. (CVE-2026-74958)\nMitigation bypass in the Storage: Cache API component. (CVE-2026-74959)\nSite isolation issue in the WebExtensions component. (CVE-2026-74960)\nSide-channel in the Web Audio component. (CVE-2026-74961)\nSite isolation issue in the Networking: Cookies component.\n(CVE-2026-74962)\nSame-origin policy bypass in the Networking: Cookies component.\n(CVE-2026-74963)\nInteger overflow in the Graphics component. (CVE-2026-74964)\nPrivilege escalation in the Shell Integration component.\n(CVE-2026-74965)\nInformation disclosure in the Form Autofill component. (CVE-2026-74966)\nSame-origin policy bypass in the Audio/Video: Playback component.\n(CVE-2026-74967)\nSite isolation issue in the Graphics: WebRender component.\n(CVE-2026-74968)\nUse-after-free in the Layout: Text and Fonts component. (CVE-2026-74969)\nSite isolation issue in the Graphics component. (CVE-2026-74970)\nInformation disclosure in the DOM: UI Events & Focus Handling component.\n(CVE-2026-74971)\nInformation disclosure in the DOM: Push Subscriptions component.\n(CVE-2026-74972)\nUse-after-free in the Graphics: Canvas2D component. (CVE-2026-74949)\nRace condition, use-after-free in the Graphics component.\n(CVE-2026-74973)\nSame-origin policy bypass in the Graphics: ImageLib component.\n(CVE-2026-74974)\nJIT miscompilation in the JavaScript Engine: JIT component.\n(CVE-2026-74976)\nInteger overflow in the Graphics component. (CVE-2026-74977)\nClickjacking issue in the Widget component. (CVE-2026-74978)\nMitigation bypass in the Add-ons Manager component. (CVE-2026-74979)\nSite isolation issue in the Audio/Video: Web Codecs component.\n(CVE-2026-74981)\nDenial-of-service in the Widget component. (CVE-2026-74982)\nMitigation bypass in the Data Loss Prevention component.\n(CVE-2026-74983)\nRace condition in the JavaScript Engine component. (CVE-2026-74984)\nPrivilege escalation in the Enterprise Policies component.\n(CVE-2026-74985)\nSite isolation issue in the CSS Parsing and Computation component.\n(CVE-2026-74986)\nInternally found bugs fixed in Thunderbird ESR 140.14, \nThunderbird ESR 153.1 and Thunderbird 154. (CVE-2026-74987)\nInternally found bugs fixed in Thunderbird ESR 153.1 and Thunderbird 154 \n(CVE-2026-74988)\nInternally found bugs fixed in Thunderbird ESR 140.14, \nThunderbird ESR 153.1 and Thunderbird 154. (CVE-2026-74990)\n","modified":"2026-08-31T16:41:22.606714171Z","published":"2026-08-31T16:22:02Z","upstream":["CVE-2026-74934","CVE-2026-74935","CVE-2026-74936","CVE-2026-74937","CVE-2026-74938","CVE-2026-74939","CVE-2026-74940","CVE-2026-74941","CVE-2026-74942","CVE-2026-74943","CVE-2026-74944","CVE-2026-74945","CVE-2026-74946","CVE-2026-74947","CVE-2026-74948","CVE-2026-74949","CVE-2026-74950","CVE-2026-74953","CVE-2026-74954","CVE-2026-74955","CVE-2026-74956","CVE-2026-74957","CVE-2026-74958","CVE-2026-74959","CVE-2026-74960","CVE-2026-74961","CVE-2026-74962","CVE-2026-74963","CVE-2026-74964","CVE-2026-74965","CVE-2026-74966","CVE-2026-74967","CVE-2026-74968","CVE-2026-74969","CVE-2026-74970","CVE-2026-74971","CVE-2026-74972","CVE-2026-74973","CVE-2026-74974","CVE-2026-74976","CVE-2026-74977","CVE-2026-74978","CVE-2026-74979","CVE-2026-74981","CVE-2026-74982","CVE-2026-74983","CVE-2026-74984","CVE-2026-74985","CVE-2026-74986","CVE-2026-74987","CVE-2026-74988","CVE-2026-74990"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2026-0346.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=36124"},{"type":"WEB","url":"https://www.thunderbird.net/en-US/thunderbird/140.14.0esr/releasenotes/"},{"type":"WEB","url":"https://www.thunderbird.net/en-US/thunderbird/153.1.0esr/releasenotes/"},{"type":"ADVISORY","url":"https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/"},{"type":"ADVISORY","url":"https://www.mozilla.org/en-US/security/advisories/mfsa2026-80/"}],"affected":[{"package":{"name":"thunderbird","ecosystem":"Mageia:10","purl":"pkg:rpm/mageia/thunderbird?arch=source&distro=mageia-10"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"153.1.0-1.mga10"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2026-0346.json"}},{"package":{"name":"thunderbird-l10n","ecosystem":"Mageia:10","purl":"pkg:rpm/mageia/thunderbird-l10n?arch=source&distro=mageia-10"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"153.1.0-1.mga10"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2026-0346.json"}},{"package":{"name":"thunderbird","ecosystem":"Mageia:9","purl":"pkg:rpm/mageia/thunderbird?arch=source&distro=mageia-9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"140.14.0-1.mga9"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2026-0346.json"}},{"package":{"name":"thunderbird-l10n","ecosystem":"Mageia:9","purl":"pkg:rpm/mageia/thunderbird-l10n?arch=source&distro=mageia-9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"140.14.0-1.mga9"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2026-0346.json"}}],"schema_version":"1.9.0","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}