{"id":"SUSE-SU-2026:3897-1","summary":"Security update for MozillaThunderbird","details":"This update for MozillaThunderbird fixes the following issue:\n\nUpdate to Mozilla Thunderbird 140.14.\n\n- MFSA 2026-79 (bsc#1274867)\n  * CVE-2026-74934: Site isolation issue in the Graphics: CanvasWebGL component\n  * CVE-2026-74935: Privilege escalation in the DOM: Networking component\n  * CVE-2026-74936: Use-after-free in the JavaScript: WebAssembly component\n  * CVE-2026-74939: Privilege escalation in the DOM: Navigation component\n  * CVE-2026-74940: Use-after-free in the Graphics: Text component\n  * CVE-2026-74941: Privilege escalation in the Graphics: CanvasWebGL component\n  * CVE-2026-74942: Privilege escalation in the Remote Settings Client component\n  * CVE-2026-74943: Use-after-free in the Graphics: ImageLib component\n  * CVE-2026-74944: Use-after-free in the DOM: Core & HTML component\n  * CVE-2026-74945: Information disclosure in the Graphics: Text component\n  * CVE-2026-74946: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component\n  * CVE-2026-74948: Information disclosure in the Graphics component\n  * CVE-2026-74949: Privilege escalation due to use-after-free in the Graphics: Canvas2D component\n  * CVE-2026-74953: Privilege escalation in the Networking: Cookies component\n  * CVE-2026-74957: Mitigation bypass in the Safe Browsing component\n  * CVE-2026-74959: Mitigation bypass in the Storage: Cache API component\n  * CVE-2026-74960: Site isolation issue in the WebExtensions component\n  * CVE-2026-74962: Site isolation issue in the Networking: Cookies component\n  * CVE-2026-74963: Same-origin policy bypass in the Networking: Cookies component\n  * CVE-2026-74964: Integer overflow in the Graphics component\n  * CVE-2026-74965: Privilege escalation in the Shell Integration component\n  * CVE-2026-74967: Same-origin policy bypass in the Audio/Video: Playback component\n  * CVE-2026-74969: Use-after-free in the Layout: Text and Fonts component\n  * CVE-2026-74971: Information disclosure in the DOM: UI Events & Focus Handling component \n  * CVE-2026-74972: Information disclosure in the DOM: Push Subscriptions component\n  * CVE-2026-74973: Race condition, use-after-free in the Graphics component\n  * CVE-2026-74974: Same-origin policy bypass in the Graphics: ImageLib component\n  * CVE-2026-74976: JIT miscompilation in the JavaScript Engine: JIT component\n  * CVE-2026-74983: Mitigation bypass in the Data Loss Prevention component\n  * CVE-2026-74987: Internally found bugs fixed in Thunderbird ESR 140.14, Thunderbird ESR 153.1 and Thunderbird 154\n  * CVE-2026-74990: Internally found bugs fixed in Thunderbird ESR 140.14, Thunderbird ESR 153.1 and Thunderbird 154\n","modified":"2026-09-10T18:23:20.621326539Z","published":"2026-08-31T15:01:13Z","related":["CVE-2026-74934","CVE-2026-74935","CVE-2026-74936","CVE-2026-74939","CVE-2026-74940","CVE-2026-74941","CVE-2026-74942","CVE-2026-74943","CVE-2026-74944","CVE-2026-74945","CVE-2026-74946","CVE-2026-74948","CVE-2026-74949","CVE-2026-74953","CVE-2026-74957","CVE-2026-74959","CVE-2026-74960","CVE-2026-74962","CVE-2026-74963","CVE-2026-74964","CVE-2026-74965","CVE-2026-74967","CVE-2026-74969","CVE-2026-74971","CVE-2026-74972","CVE-2026-74973","CVE-2026-74974","CVE-2026-74976","CVE-2026-74983","CVE-2026-74987","CVE-2026-74990"],"upstream":["CVE-2026-74934","CVE-2026-74935","CVE-2026-74936","CVE-2026-74939","CVE-2026-74940","CVE-2026-74941","CVE-2026-74942","CVE-2026-74943","CVE-2026-74944","CVE-2026-74945","CVE-2026-74946","CVE-2026-74948","CVE-2026-74949","CVE-2026-74953","CVE-2026-74957","CVE-2026-74959","CVE-2026-74960","CVE-2026-74962","CVE-2026-74963","CVE-2026-74964","CVE-2026-74965","CVE-2026-74967","CVE-2026-74969","CVE-2026-74971","CVE-2026-74972","CVE-2026-74973","CVE-2026-74974","CVE-2026-74976","CVE-2026-74983","CVE-2026-74987","CVE-2026-74990"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20263897-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1274867"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74934"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74935"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74936"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74939"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74940"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74941"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74942"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74943"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74944"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74945"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74946"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74948"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74949"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74953"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74957"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74959"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74960"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74962"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74963"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74964"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74965"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74967"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74969"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74971"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74972"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74973"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74974"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74976"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74983"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74987"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74990"}],"affected":[{"package":{"name":"MozillaThunderbird","ecosystem":"SUSE:Linux Enterprise Module for Package Hub 15 SP7","purl":"pkg:rpm/suse/MozillaThunderbird&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"140.14.0-150200.8.283.1"}]}],"ecosystem_specific":{"binaries":[{"MozillaThunderbird-translations-common":"140.14.0-150200.8.283.1","MozillaThunderbird-translations-other":"140.14.0-150200.8.283.1","MozillaThunderbird":"140.14.0-150200.8.283.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3897-1.json"}},{"package":{"name":"MozillaThunderbird","ecosystem":"SUSE:Linux Enterprise Workstation Extension 15 SP7","purl":"pkg:rpm/suse/MozillaThunderbird&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2015%20SP7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"140.14.0-150200.8.283.1"}]}],"ecosystem_specific":{"binaries":[{"MozillaThunderbird-translations-common":"140.14.0-150200.8.283.1","MozillaThunderbird-translations-other":"140.14.0-150200.8.283.1","MozillaThunderbird":"140.14.0-150200.8.283.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3897-1.json"}}],"schema_version":"1.9.0"}