{"id":"SUSE-SU-2026:2271-1","summary":"Security update for MozillaThunderbird","details":"This update for MozillaThunderbird fixes the following issues\n\n- Updated to Mozilla Thunderbird 140.11 (bsc#1265212)\n\nMFSA 2026-44:\n\n- CVE-2026-8090: Use-after-free in the DOM: Networking component.\n- CVE-2026-8092: Memory safety bugs fixed in Thunderbird ESR 140.10.2 and Thunderbird 150.0.2.\n- CVE-2026-8094: Other issue in the WebRTC component.\n\nMFSA 2026-51:\n\n- CVE-2026-8388: Incorrect boundary conditions in the JavaScript Engine: JIT component.\n- CVE-2026-8391: Other issue in the JavaScript Engine component.\n- CVE-2026-8401: Sandbox escape in the Profile Backup component.\n- CVE-2026-8946: Incorrect boundary conditions in the Audio/Video: Web Codecs component.\n- CVE-2026-8947: Use-after-free in the DOM: Bindings (WebIDL) component.\n- CVE-2026-8949: Integer overflow in the Widget: Win32 component.\n- CVE-2026-8950: Same-origin policy bypass in the Networking: HTTP component.\n- CVE-2026-8953: Sandbox escape due to use-after-free in the Disability Access APIs component.\n- CVE-2026-8954: Incorrect boundary conditions, integer overflow in the Audio/Video component.\n- CVE-2026-8955: Privilege escalation in the DOM: Workers component.\n- CVE-2026-8956: Integer overflow in the Networking: JAR component.\n- CVE-2026-8957: Privilege escalation in the Enterprise Policies component.\n- CVE-2026-8958: Information disclosure, sandbox escape in the Security: Process Sandboxing component.\n- CVE-2026-8959: Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component.\n- CVE-2026-8961: Spoofing issue in the Form Autofill component.\n- CVE-2026-8962: Mitigation bypass in the DOM: Security component.\n- CVE-2026-8968: Denial-of-service due to invalid pointer in the Audio/Video: Web Codecs component.\n- CVE-2026-8970: Privilege escalation in the Security component.\n- CVE-2026-8974: Memory safety bugs fixed in Thunderbird 140.11 and Thunderbird 151.\n- CVE-2026-8975: Memory safety bugs fixed in Thunderbird 140.11 and Thunderbird 151.\n","modified":"2026-06-06T07:30:23.488755642Z","published":"2026-06-05T06:37:07Z","related":["CVE-2026-8090","CVE-2026-8092","CVE-2026-8094","CVE-2026-8388","CVE-2026-8391","CVE-2026-8401","CVE-2026-8946","CVE-2026-8947","CVE-2026-8949","CVE-2026-8950","CVE-2026-8953","CVE-2026-8954","CVE-2026-8955","CVE-2026-8956","CVE-2026-8957","CVE-2026-8958","CVE-2026-8959","CVE-2026-8961","CVE-2026-8962","CVE-2026-8968","CVE-2026-8970","CVE-2026-8974","CVE-2026-8975"],"upstream":["CVE-2026-8090","CVE-2026-8092","CVE-2026-8094","CVE-2026-8388","CVE-2026-8391","CVE-2026-8401","CVE-2026-8946","CVE-2026-8947","CVE-2026-8949","CVE-2026-8950","CVE-2026-8953","CVE-2026-8954","CVE-2026-8955","CVE-2026-8956","CVE-2026-8957","CVE-2026-8958","CVE-2026-8959","CVE-2026-8961","CVE-2026-8962","CVE-2026-8968","CVE-2026-8970","CVE-2026-8974","CVE-2026-8975"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20262271-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265212"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-8090"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-8092"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-8094"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-8388"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-8391"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-8401"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-8946"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-8947"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-8949"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-8950"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-8953"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-8954"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-8955"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-8956"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-8957"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-8958"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-8959"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-8961"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-8962"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-8968"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-8970"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-8974"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-8975"}],"schema_version":"1.7.5"}