RHSA-2025:8756HighCVSS 8.8

Red Hat Security Advisory: thunderbird security update

Published
June 10, 2025
Last Modified
August 6, 2026

🔗 CVE IDs covered (13)

📋 Description

CVE-2025-3875 — thunderbird: Sender Spoofing via Malformed From Header in Thunderbird CVE-2025-3877 — thunderbird: Unsolicited File Download, Disk Space Exhaustion, and Credential Leakage via mailbox:/// Links CVE-2025-3909 — thunderbird: JavaScript Execution via Spoofed PDF Attachment and file:/// Link CVE-2025-3932 — thunderbird: Tracking Links in Attachments Bypassed Remote Content Blocking CVE-2025-4918 — firefox: thunderbird: Out-of-bounds access when resolving Promise objects CVE-2025-4919 — firefox: thunderbird: Out-of-bounds access when optimizing linear sums CVE-2025-5263 — firefox: thunderbird: Error handling for script execution was incorrectly isolated from web content CVE-2025-5264 — firefox: thunderbird: Potential local code execution in “Copy as cURL” command CVE-2025-5266 — firefox: thunderbird: Script element events leaked cross-origin resource status CVE-2025-5267 — firefox: thunderbird: Clickjacking vulnerability could have led to leaking saved payment card details CVE-2025-5268 — firefox: thunderbird: Memory safety bugs CVE-2025-5269 — firefox: thunderbird: Memory safety bug CVE-2025-5283 — libvpx: Double-free in libvpx encoder

🎯 Affected products14

  • Red Hat Enterprise Linux AppStream (v. 8)
  • thunderbird-0:128.11.0-1.el8_10.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • thunderbird-0:128.11.0-1.el8_10.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • thunderbird-0:128.11.0-1.el8_10.s390x as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • thunderbird-0:128.11.0-1.el8_10.src as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • thunderbird-0:128.11.0-1.el8_10.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • thunderbird-debuginfo-0:128.11.0-1.el8_10.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • thunderbird-debuginfo-0:128.11.0-1.el8_10.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • thunderbird-debuginfo-0:128.11.0-1.el8_10.s390x as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • thunderbird-debuginfo-0:128.11.0-1.el8_10.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • thunderbird-debugsource-0:128.11.0-1.el8_10.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • thunderbird-debugsource-0:128.11.0-1.el8_10.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • thunderbird-debugsource-0:128.11.0-1.el8_10.s390x as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • thunderbird-debugsource-0:128.11.0-1.el8_10.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 8)

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: No mitigation is currently available that meets Red Hat Product Security’s standards for usability, deployment, applicability, or stability. Workaround: Mitigation is either unavailable or does not meet Red Hat Product Security standards for usability, deployment, applicability, or stability.

🔗 References (15)