[BLFS Trac] #23634: thunderbird-140.13.0esr

BLFS Trac ([email protected] via blfs-book Mailing List) <[email protected]> Wed, 22 Jul 2026 20:21:09 -0000
Newsgroups gmane.linux.lfs.beyond.book
Message-ID <[email protected]>
#23634: thunderbird-140.13.0esr
-------------------------+------------------------
 Reporter:  Joe Locash   |      Owner:  Joe Locash
     Type:  enhancement  |     Status:  assigned
 Priority:  high         |  Milestone:  13.1
Component:  BOOK         |    Version:  git
 Severity:  critical     |   Keywords:
-------------------------+------------------------
 Security fixes:
  - CVE-2026-14899: Off-by-one out of bounds read in MIME header parser for
 forwarding (moderate)
  - CVE-2026-15718: Invalid pointer in the JavaScript: WebAssembly
 component (critial)
  - CVE-2026-15719: Site isolation issue in the DOM: Navigation component
 (critial)
  - CVE-2026-16349: Same-origin policy bypass in the DOM: Navigation
 component (high)
  - CVE-2026-16350: Incorrect boundary conditions in the Audio/Video: cubeb
 component (high)
  - CVE-2026-16362: Use-after-free in the WebRTC: Audio/Video component
 (high)
  - CVE-2026-16351: Sandbox escape due to use-after-free in the DOM:
 Navigation component (high)
  - CVE-2026-16352: Sandbox escape due to use-after-free in the Disability
 Access APIs component (high)
  - CVE-2026-16363: JIT miscompilation in the JavaScript: WebAssembly
 component (high)
  - CVE-2026-16353: Invalid pointer in the DOM: Bindings (WebIDL) component
 (high)
  - CVE-2026-16354: Information disclosure in the Graphics: ImageLib
 component (high)
  - CVE-2026-16368: Incorrect boundary conditions in the JavaScript:
 WebAssembly component (high)
  - CVE-2026-16369: Integer overflow in the JavaScript: WebAssembly
 component (high)
  - CVE-2026-16355: JIT miscompilation in the JavaScript Engine: JIT
 component (high)
  - CVE-2026-16356: Sandbox escape due to use-after-free in the Disability
 Access APIs component (high)
  - CVE-2026-16357: Incorrect boundary conditions in the Graphics component
 (high)
  - CVE-2026-16371: Privilege escalation in the DOM: Navigation component
 (moderate)
  - CVE-2026-16374: Information disclosure in the Framework component in
 DevTools (moderate)
  - CVE-2026-16375: Site isolation issue in the Networking: HTTP component
 (moderate)
  - CVE-2026-16377: Mitigation bypass in the PDF Viewer component
 (moderate)
  - CVE-2026-16379: Privilege escalation in the DOM: Content Processes
 component (moderate)
  - CVE-2026-16358: Site isolation issue in the Graphics: WebRender
 component (moderate)
  - CVE-2026-16381: Same-origin policy bypass in the Networking: DNS
 component (moderate)
  - CVE-2026-16383: Mitigation bypass in the DOM: Networking component
 (moderate)
  - CVE-2026-16387: Site isolation issue in the Networking component
 (moderate)
  - CVE-2026-16390: Mitigation bypass in the Enterprise Policies component
 (moderate)
  - CVE-2026-16391: Information disclosure in the Storage: IndexedDB
 component (moderate)
  - CVE-2026-16359: Incorrect boundary conditions in the Audio/Video: GMP
 component (moderate)
  - CVE-2026-16396: Privilege escalation in WebExtensions (moderate)
  - CVE-2026-16405: Information disclosure in the Networking: WebSockets
 component (low)
  - CVE-2026-16412: Memory safety bugs fixed in Thunderbird ESR 140.13 and
 Thunderbird 153 (high)
  - CVE-2026-16360: Memory safety bugs fixed in Thunderbird ESR 140.13 and
 Thunderbird 153 (high)
  - CVE-2026-16361: Memory safety bugs fixed in Thunderbird ESR 140.13
 (high)

 https://www.mozilla.org/en-US/security/advisories/mfsa2026-72/
-- 
Ticket URL: <https://wiki.linuxfromscratch.org/blfs/ticket/23634>
BLFS Trac <https://wiki.linuxfromscratch.org/blfs/>
Beyond Linux From Scratch

-- 
http://lists.linuxfromscratch.org/sympa/info/blfs-book
Unsubscribe: See the above information page