RHSA-2026:14223HighCVSS 8.8
Red Hat Security Advisory: thunderbird security update
🔗 CVE IDs covered (5)
📋 Description
CVE-2026-5731 — thunderbird: firefox: Memory safety bugs fixed in Firefox ESR 115.34.1, Firefox ESR 140.9.1, Thunderbird ESR 140.9.1, Firefox 149.0.2 and Thunderbird 149.0.2 CVE-2026-5732 — firefox: thunderbird: Incorrect boundary conditions, integer overflow in the Graphics: Text component CVE-2026-5734 — thunderbird: firefox: Memory safety bugs fixed in Firefox ESR 140.9.1, Thunderbird ESR 140.9.1, Firefox 149.0.2 and Thunderbird 149.0.2 CVE-2026-33416 — libpng: libpng: Arbitrary code execution due to use-after-free vulnerability CVE-2026-33636 — libpng: libpng: Information disclosure and denial of service via out-of-bounds read/write in Neon palette expansion
🔗 References (8)
- selfhttps://access.redhat.com/errata/RHSA-2026:14223
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2451805
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2451819
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2455897
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2455901
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2455908
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_14223.json