{"id":"openSUSE-SU-2026:21168-1","summary":"Security update for MozillaThunderbird","details":"This update for MozillaThunderbird fixes the following issues:\n\nChanges in MozillaThunderbird:\n\n- Mozilla Thunderbird 140.12.0 ESR\n  MFSA 2026-61 (bsc#1268071)\n  * CVE-2026-12289 (bmo#2023443)\n    Privilege escalation in the Graphics: WebRender component\n  * CVE-2026-12290 (bmo#2024852)\n    Memory safety bug fixed in Thunderbird ESR 140.12\n  * CVE-2026-12291 (bmo#2036929)\n    Use-after-free in the Networking: HTTP component\n  * CVE-2026-12292 (bmo#2038465)\n    Incorrect boundary conditions in the Web Audio component\n  * CVE-2026-12294 (bmo#2039873)\n    Sandbox escape in the DOM: Workers component\n  * CVE-2026-12295 (bmo#2040160)\n    Sandbox escape in the DOM: Navigation component\n  * CVE-2026-12298 (bmo#2041981)\n    Memory safety bug fixed in Thunderbird ESR 140.12\n  * CVE-2026-12296 (bmo#2040515)\n    Sandbox escape in the Security: Process Sandboxing component\n  * CVE-2026-12297 (bmo#2041610)\n    Sandbox escape due to incorrect boundary conditions in the\n    Networking component\n  * CVE-2026-12299 (bmo#2043139)\n    JIT miscompilation in the DOM: Core & HTML component\n  * CVE-2026-12329 (bmo#2044738)\n    Memory safety bug fixed in Thunderbird ESR 140.12\n  * CVE-2026-12302 (bmo#2034489)\n    Mitigation bypass in the DOM: Security component\n  * CVE-2026-12304 (bmo#2034944)\n    Same-origin policy bypass in the Networking: Cookies component\n  * CVE-2026-12305 (bmo#2037290)\n    Memory safety bug fixed in Thunderbird ESR 140.12\n  * CVE-2026-12306 (bmo#2037323)\n    Memory safety bug fixed in Thunderbird ESR 140.12\n  * CVE-2026-12307 (bmo#2038133)\n    Memory safety bug fixed in Thunderbird ESR 140.12\n  * CVE-2026-12308 (bmo#2038302)\n    Memory safety bug fixed in Thunderbird ESR 140.12\n  * CVE-2026-12309 (bmo#2038476)\n    Memory safety bug fixed in Thunderbird ESR 140.12\n  * CVE-2026-12310 (bmo#2039707)\n    Memory safety bug fixed in Thunderbird ESR 140.12\n  * CVE-2026-12311 (bmo#2040177)\n    Information disclosure, sandbox escape in the Security:\n    Process Sandboxing component\n  * CVE-2026-12312 (bmo#2040383)\n    Memory safety bug fixed in Thunderbird ESR 140.12\n  * CVE-2026-12313 (bmo#2040477)\n    Information disclosure, sandbox escape in the Security:\n    Process Sandboxing component\n  * CVE-2026-12314 (bmo#2041856)\n    Memory safety bug fixed in Thunderbird ESR 140.12\n  * CVE-2026-12315 (bmo#2042058)\n    Mitigation bypass in the DOM: Security component\n  * CVE-2026-12330 (bmo#2029326)\n    Incorrect boundary conditions in the Internationalization\n    component\n  * CVE-2026-12324 (bmo#2038444)\n    Incorrect boundary conditions in the Graphics: CanvasWebGL\n    component\n  * CVE-2026-12325 (bmo#2039443)\n    Denial-of-service in the Graphics: ImageLib component\n  * CVE-2026-12327 (bmo#2011842, bmo#2023902, bmo#2025512, bmo#2027312,\n    bmo#2029444, bmo#2036571, bmo#2036900, bmo#2036936, bmo#2037995,\n    bmo#2038551, bmo#2040717, bmo#2042724)\n    Memory safety bugs fixed in Firefox ESR 140.12, Thunderbird\n    ESR 140.12, Firefox 152 and Thunderbird 152\n  * CVE-2026-12328 (bmo#2029402, bmo#2038477, bmo#2039726, bmo#2041373,\n    bmo#2042268, bmo#2042451, bmo#2042782, bmo#2042858, bmo#2042929,\n    bmo#2042965, bmo#2043213)\n    Memory safety bugs fixed in Firefox ESR 115.37, Firefox ESR\n    140.12, Thunderbird ESR 140.12, Firefox 152 and Thunderbird 152\n\n- Mozilla Thunderbird 140.11.0 ESR\n  MFSA 2026-51 (bsc#1265212)\n  * CVE-2026-8946 (bmo#2029070)\n    Incorrect boundary conditions in the Audio/Video: Web Codecs\n    component\n  * CVE-2026-8388 (bmo#2036978)\n    Incorrect boundary conditions in the JavaScript Engine: JIT\n    component\n  * CVE-2026-8947 (bmo#2038439)\n    Use-after-free in the DOM: Bindings (WebIDL) component\n  * CVE-2026-8391 (bmo#2038575)\n    Other issue in the JavaScript Engine component\n  * CVE-2026-8401 (bmo#2038679)\n    Sandbox escape in the Profile Backup component\n  * CVE-2026-8949 (bmo#1355639)\n    Integer overflow in the Widget: Win32 component\n  * CVE-2026-8950 (bmo#1965430)\n    Same-origin policy bypass in the Networking: HTTP component\n  * CVE-2026-8953 (bmo#2029511)\n    Sandbox escape due to use-after-free in the Disability Access\n    APIs component\n  * CVE-2026-8954 (bmo#2030747)\n    Incorrect boundary conditions, integer overflow in the\n    Audio/Video component\n  * CVE-2026-8955 (bmo#2031064)\n    Privilege escalation in the DOM: Workers component\n  * CVE-2026-8956 (bmo#2032427)\n    Integer overflow in the Networking: JAR component\n  * CVE-2026-8957 (bmo#2033850)\n    Privilege escalation in the Enterprise Policies component\n  * CVE-2026-8958 (bmo#2034713)\n    Information disclosure, sandbox escape in the Security:\n    Process Sandboxing component\n  * CVE-2026-8959 (bmo#2034754)\n    Sandbox escape due to incorrect boundary conditions in the\n    Widget: Win32 component\n  * CVE-2026-8961 (bmo#1962625)\n    Spoofing issue in the Form Autofill component\n  * CVE-2026-8962 (bmo#2004804)\n    Mitigation bypass in the DOM: Security component\n  * CVE-2026-8968 (bmo#2030467)\n    Denial-of-service due to invalid pointer in the Audio/Video:\n    Web Codecs component\n  * CVE-2026-8970 (bmo#2032174)\n    Privilege escalation in the Security component\n  * CVE-2026-8974 (bmo#1784128, bmo#1883230, bmo#1983677, bmo#2022390,\n    bmo#2023116, bmo#2023657, bmo#2024255, bmo#2024418, bmo#2024441,\n    bmo#2024447, bmo#2024966, bmo#2025412, bmo#2025467, bmo#2025940,\n    bmo#2025950, bmo#2025956, bmo#2026284, bmo#2027247, bmo#2027255,\n    bmo#2027288, bmo#2027306, bmo#2027322, bmo#2027332, bmo#2027333,\n    bmo#2028266, bmo#2028292, bmo#2028319, bmo#2028526, bmo#2028870,\n    bmo#2028876, bmo#2028882, bmo#2029062, bmo#2029309, bmo#2029414,\n    bmo#2029422, bmo#2029428, bmo#2029447, bmo#2029732, bmo#2029785,\n    bmo#2029793, bmo#2029813, bmo#2029899, bmo#2031028, bmo#2031457,\n    bmo#2032039, bmo#2033610, bmo#2033854, bmo#2034498, bmo#2034628,\n    bmo#2034978, bmo#2035966, bmo#2036668, bmo#2036905, bmo#2036930)\n    Memory safety bugs fixed in Thunderbird 140.11 and Thunderbird 151\n  * CVE-2026-8975 (bmo#1860195, bmo#2029325, bmo#2029429, bmo#2029910,\n    bmo#2035915, bmo#2038669, bmo#2038678)\n    Memory safety bugs fixed in Thunderbird 140.11 and Thunderbird 151\n\n- Mozilla Thunderbird 140.10.2\n  MFSA 2026-44 (bsc#1264378)\n  * CVE-2026-8090 (bmo#2034352)\n    Use-after-free in the DOM: Networking component\n  * CVE-2026-8094 (bmo#2035939)\n    Other issue in the WebRTC component\n  * CVE-2026-8092 (bmo#1806249, bmo#2021977, bmo#2022576, bmo#2022722,\n    bmo#2024439, bmo#2027883, bmo#2029463, bmo#2030323, bmo#2032042,\n    bmo#2032043, bmo#2033270, bmo#2033637, bmo#2034422, bmo#2034496,\n    bmo#2035879, bmo#2036516)\n    Memory safety bugs fixed in Thunderbird ESR 140.10.2 and\n    Thunderbird 150.0.2\n\n- Mozilla Thunderbird 140.10.1 ESR\n  MFSA 2026-39 (bsc#1263110)\n  * CVE-2026-7320 (bmo#2027433)\n    Information disclosure due to incorrect boundary conditions\n    in the Audio/Video component\n  * CVE-2026-7321 (bmo#2029461)\n    Sandbox escape due to incorrect boundary conditions in the\n    WebRTC: Networking component\n  * CVE-2026-7322 (bmo#2021904, bmo#2022731, bmo#2027158,\n    bmo#2027733, bmo#2027973, bmo#2027976, bmo#2028231,\n    bmo#2028731, bmo#2028886, bmo#2029067, bmo#2029700,\n    bmo#2029724, bmo#2029806, bmo#2029814, bmo#2030108,\n    bmo#2030111, bmo#2031524, bmo#2031921, bmo#2032040)\n    Memory safety bugs fixed in Thunderbird ESR 140.10.1 and\n    Thunderbird 150.0.1\n  * CVE-2026-7323 (bmo#2028537, bmo#2029911, bmo#2031121,\n    bmo#2033602)\n    Memory safety bugs fixed in Thunderbird ESR 140.10.1 and\n    Thunderbird 150.0.1\n","modified":"2026-06-30T09:15:07.725612415Z","published":"2026-06-29T11:13:35Z","related":["CVE-2026-12289","CVE-2026-12290","CVE-2026-12291","CVE-2026-12292","CVE-2026-12294","CVE-2026-12295","CVE-2026-12296","CVE-2026-12297","CVE-2026-12298","CVE-2026-12299","CVE-2026-12302","CVE-2026-12304","CVE-2026-12305","CVE-2026-12306","CVE-2026-12307","CVE-2026-12308","CVE-2026-12309","CVE-2026-12310","CVE-2026-12311","CVE-2026-12312","CVE-2026-12313","CVE-2026-12314","CVE-2026-12315","CVE-2026-12324","CVE-2026-12325","CVE-2026-12327","CVE-2026-12328","CVE-2026-12329","CVE-2026-12330","CVE-2026-7320","CVE-2026-7321","CVE-2026-7322","CVE-2026-7323","CVE-2026-8090","CVE-2026-8092","CVE-2026-8094","CVE-2026-8388","CVE-2026-8391","CVE-2026-8401","CVE-2026-8946","CVE-2026-8947","CVE-2026-8949","CVE-2026-8950","CVE-2026-8953","CVE-2026-8954","CVE-2026-8955","CVE-2026-8956","CVE-2026-8957","CVE-2026-8958","CVE-2026-8959","CVE-2026-8961","CVE-2026-8962","CVE-2026-8968","CVE-2026-8970","CVE-2026-8974","CVE-2026-8975"],"upstream":["CVE-2026-12289","CVE-2026-12290","CVE-2026-12291","CVE-2026-12292","CVE-2026-12294","CVE-2026-12295","CVE-2026-12296","CVE-2026-12297","CVE-2026-12298","CVE-2026-12299","CVE-2026-12302","CVE-2026-12304","CVE-2026-12305","CVE-2026-12306","CVE-2026-12307","CVE-2026-12308","CVE-2026-12309","CVE-2026-12310","CVE-2026-12311","CVE-2026-12312","CVE-2026-12313","CVE-2026-12314","CVE-2026-12315","CVE-2026-12324","CVE-2026-12325","CVE-2026-12327","CVE-2026-12328","CVE-2026-12329","CVE-2026-12330","CVE-2026-7320","CVE-2026-7321","CVE-2026-7322","CVE-2026-7323","CVE-2026-8090","CVE-2026-8092","CVE-2026-8094","CVE-2026-8388","CVE-2026-8391","CVE-2026-8401","CVE-2026-8946","CVE-2026-8947","CVE-2026-8949","CVE-2026-8950","CVE-2026-8953","CVE-2026-8954","CVE-2026-8955","CVE-2026-8956","CVE-2026-8957","CVE-2026-8958","CVE-2026-8959","CVE-2026-8961","CVE-2026-8962","CVE-2026-8968","CVE-2026-8970","CVE-2026-8974","CVE-2026-8975"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1158957"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263110"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264378"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265212"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268071"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-12289"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-12290"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-12291"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-12292"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-12294"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-12295"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-12296"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-12297"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-12298"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-12299"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-12302"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-12304"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-12305"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-12306"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-12307"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-12308"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-12309"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-12310"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-12311"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-12312"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-12313"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-12314"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-12315"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-12324"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-12325"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-12327"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-12328"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-12329"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-12330"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-7320"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-7321"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-7322"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-7323"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-8090"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-8092"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-8094"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-8388"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-8391"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-8401"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-8946"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-8947"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-8949"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-8950"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-8953"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-8954"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-8955"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-8956"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-8957"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-8958"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-8959"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-8961"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-8962"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-8968"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-8970"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-8974"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-8975"}],"affected":[{"package":{"name":"MozillaThunderbird","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/MozillaThunderbird&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"140.12.0-bp160.1.1"}]}],"ecosystem_specific":{"binaries":[{"MozillaThunderbird-translations-common":"140.12.0-bp160.1.1","MozillaThunderbird-translations-other":"140.12.0-bp160.1.1","MozillaThunderbird":"140.12.0-bp160.1.1","MozillaThunderbird-openpgp-librnp":"140.12.0-bp160.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21168-1.json"}}],"schema_version":"1.7.5"}