Accepted thunderbird 1:140.13.0esr-1 (source) into unstable

Debian FTP Masters <[email protected]> Tue, 04 Aug 2026 19:20:47 +0000
Newsgroups gmane.linux.debian.devel.changes.unstable
Message-ID <[email protected]>
--===============6241147169521553094==
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: quoted-printable

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Tue, 04 Aug 2026 17:36:13 +0200
Source: thunderbird
Architecture: source
Version: 1:140.13.0esr-1
Distribution: unstable
Urgency: medium
Maintainer: Carsten Schoenert <[email protected]>
Changed-By: Carsten Schoenert <[email protected]>
Changes:
 thunderbird (1:140.13.0esr-1) unstable; urgency=3Dmedium
 .
   * [41e5476] New upstream version 140.13.0esr
     Fixed CVE issues in upstream version 140.13 (MFSA 2026-72):
     CVE-2026-14899: Off-by-one out of bounds read in MIME header parser
                     for forwarding
     CVE-2026-15718: Invalid pointer in the JavaScript: WebAssembly component
     CVE-2026-15719: Site isolation issue in the DOM: Navigation component
     CVE-2026-16349: Same-origin policy bypass in the DOM: Navigation
                     component
     CVE-2026-16350: Incorrect boundary conditions in the Audio/Video: cubeb
                     component
     CVE-2026-16362: Use-after-free in the WebRTC: Audio/Video component
     CVE-2026-16351: Sandbox escape due to use-after-free in the DOM:
                     Navigation component
     CVE-2026-16352: Sandbox escape due to use-after-free in the Disability
                     Access APIs component
     CVE-2026-16363: JIT miscompilation in the JavaScript: WebAssembly
                     component
     CVE-2026-16353: Invalid pointer in the DOM: Bindings (WebIDL) component
     CVE-2026-16354: Information disclosure in the Graphics: ImageLib
                     component
     CVE-2026-16368: Incorrect boundary conditions in the JavaScript:
                     WebAssembly component
     CVE-2026-16369: Integer overflow in the JavaScript: WebAssembly component
     CVE-2026-16355: JIT miscompilation in the JavaScript Engine: JIT
                     component
     CVE-2026-16356: Sandbox escape due to use-after-free in the Disability
                     Access APIs component
     CVE-2026-16357: Incorrect boundary conditions in the Graphics component
     CVE-2026-16371: Privilege escalation in the DOM: Navigation component
     CVE-2026-16374: Information disclosure in the Framework component in
                     DevTools
     CVE-2026-16375: Site isolation issue in the Networking: HTTP component
     CVE-2026-16377: Mitigation bypass in the PDF Viewer component
     CVE-2026-16379: Privilege escalation in the DOM: Content Processes
                     component
     CVE-2026-16358: Site isolation issue in the Graphics: WebRender component
     CVE-2026-16381: Same-origin policy bypass in the Networking: DNS
                     component
     CVE-2026-16383: Mitigation bypass in the DOM: Networking component
     CVE-2026-16387: Site isolation issue in the Networking component
     CVE-2026-16390: Mitigation bypass in the Enterprise Policies component
     CVE-2026-16391: Information disclosure in the Storage: IndexedDB
                     component
     CVE-2026-16359: Incorrect boundary conditions in the Audio/Video: GMP
                     component
     CVE-2026-16396: Privilege escalation in WebExtensions
     CVE-2026-16405: Information disclosure in the Networking: WebSockets
                     component
     CVE-2026-16412: Memory safety bugs fixed in Thunderbird ESR 140.13 and
                     Thunderbird 153
     CVE-2026-16360: Memory safety bugs fixed in Thunderbird ESR 140.13 and
                     Thunderbird 153
     CVE-2026-16361: Memory safety bugs fixed in Thunderbird ESR 140.13
   * [fe5c7e7] Rebuild patch queue from patch-queue branch
     Added patches (picked from firefox-esr):
     fixes/Bug-1969769-Change-uses-of-ast.Str-with-ast.Constant.-r-f.patch
     fixes/Bug-1983713-Use-non-deprecated-ast-value.-r-firefox-build.patch
     fixes/Bug-1983736-Patch-jsonschema-to-work-with-Python-3.14-r-m.patch
 .
     Adjusted patches (removed wrong used metadata field 'Forwared'):
     fixes/Add-missing-.gitmodules-files-which-are-needed-to-build-t.patch
     fixes/Fix-conflicting-types-for-once_flag-and-call_once-with-gl.patch
     fixes/Fix-sandbox-to-build-with-glibc-2.43.patch
     fixes/Install-vaapitest-v4l2test-only-when-build.patch
   * [79acc18] d/control: Increase Standards-Version to 4.7.4
     No further changes needed.
   * [d6c0a0f] d/rules: Move/rename third party Python modul temporarly
Checksums-Sha1:
 54c4c00af5ba19be481c48417c8bddf290c3fb7f 8478 thunderbird_140.13.0esr-1.dsc
 de103d0c924e407fe5f2186976c1dd8dad9ca464 12267700 thunderbird_140.13.0esr.or=
ig-thunderbird-l10n.tar.xz
 09d7fba6b0f1c83004aac5d0d1de11f9101e8b9d 790026404 thunderbird_140.13.0esr.o=
rig.tar.xz
 0ca8e8806ca4b2c4d06c4f5391b1eed1ea8779a0 571900 thunderbird_140.13.0esr-1.de=
bian.tar.xz
 cb3b6d015e89ee3bfb9548f223304fed1dd1719e 41448 thunderbird_140.13.0esr-1_amd=
64.buildinfo
Checksums-Sha256:
 d79a5b312589cfab3f329c299d0308ee8008fef0c34b7706e772fed8953b09e3 8478 thunde=
rbird_140.13.0esr-1.dsc
 3b56a1f24e2797d14b2fcc79904fbed70f3fc82dd85f9dffc1ac12c65c0f3d45 12267700 th=
underbird_140.13.0esr.orig-thunderbird-l10n.tar.xz
 eefa02949bd02f85827313f36b24a613570a9dd2d93df3286ca62f3b5bf7d75a 790026404 t=
hunderbird_140.13.0esr.orig.tar.xz
 4d737023b561182ab0fe9ec9dea41b65db9527eaf36bb8578cd8a2a4994e0d5f 571900 thun=
derbird_140.13.0esr-1.debian.tar.xz
 2b265fdf2c738a5db94a001ee17f66b1fdd2698877d2387d1cc3897a7eb577fb 41448 thund=
erbird_140.13.0esr-1_amd64.buildinfo
Files:
 498bf6270cb870f8f6cfc2a9049650c2 8478 mail optional thunderbird_140.13.0esr-=
1.dsc
 7cf47970c17189bfb0a3d78e8bb2c134 12267700 mail optional thunderbird_140.13.0=
esr.orig-thunderbird-l10n.tar.xz
 27912317063b8e6103e477611169b8ba 790026404 mail optional thunderbird_140.13.=
0esr.orig.tar.xz
 f98cdc06c69b2c51f472a842b9e61f23 571900 mail optional thunderbird_140.13.0es=
r-1.debian.tar.xz
 cc0f781e4077afd53d84663f952f4811 41448 mail optional thunderbird_140.13.0esr=
-1_amd64.buildinfo

-----BEGIN PGP SIGNATURE-----

iQJMBAEBCgA2FiEEtw38bxNP7PwBHmKqgwFgFCUdHbAFAmpyNxUYHGMuc2Nob2Vu
ZXJ0QHQtb25saW5lLmRlAAoJEIMBYBQlHR2wmjMQAIJk0FXbkJTwjZx8Em7S8Ntb
LqRbcC8Qqs0nAoD9ALsDmkPxBa6OO+buvWjDm+6ldW3AOZZhZCKfydqVLf9fvWyz
xXnhpIbys9hk7jK1eXFt9gpdllJg9vBF8juxSD2Rqe315l8DCSeTeKmjunG7BCyx
J2myVP3N1yM4ur7OsD3RxhqM/nPpqBULOsyMokyQVhbRMLHbfoElr91NyoaRl05L
jYEk94iAIFK9x+GZFHFh1yfinjlg38DlGundIxRI262QDYRq6YOpFUqqyuEdQFyS
C4RSlp6bIAXD0O3x6Y+cIblMYvfg0f6IrJM9iV+M37Zigi8+qh8ISwjo4Apb+uzp
Nyzh0cc+imEEqUWexsJaKGVzMS484RU2JstuZ0ssmxUnoduNcW4T1J9sZJYUlXEc
SyzI72TJy7JxbhdIfQqhI9P9nw3Nv2LCeZckRIDARvYQk6W7mbbI5rrw30aCQykp
i9JluJIz1vbDKDO5Rcvwd5h88XtPuLX6NV3j9EqYbZPAo87+A8Zu8rSRaNpLQjoU
YK3eRSaMxrQk3w0LR+xEGu2sgmiOGgjldW2x9CMZuKeEsjguu38PxxJnmEeSUbiv
HIm0oFHa1e+8l7Oc/3TmrAriU9dB0Vimb/mBh5IqRc4vkB3m23MIvWH2kC7gVqVK
kAH2y7xwXgDdTbypSuSs
=3DOiwd
-----END PGP SIGNATURE-----


--===============6241147169521553094==
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----

iHUEABYIAB0WIQTziqJOuF8J+ZI8pJSb9qggYcy5IQUCanI7jwAKCRCb9qggYcy5
IRslAP0dvCFFN9wUffP+1IZ9TWsUxFoyCjOG3PinDI/urRFa5wD8CygMt0HJeI0s
DR6tZqFxKYwKjYwsAR1p3w/WwjUp0gs=
=AOsC
-----END PGP SIGNATURE-----

--===============6241147169521553094==--