RHSA-2026:70642HighCVSS 7.5

Red Hat Security Advisory: thunderbird security update

Published
September 24, 2026
Last Modified
September 27, 2026

🔗 CVE IDs covered (44)

📋 Description

CVE-2026-16365 — firefox: thunderbird: Privilege escalation in the DOM: Workers component CVE-2026-75874 — firefox: thunderbird: Sandbox escape in the Remote Settings Client component CVE-2026-84119 — firefox: Sandbox escape due to use-after-free in the DOM: Navigation component CVE-2026-84120 — firefox: Use-after-free in the Audio/Video component CVE-2026-84121 — firefox: Sandbox escape due to use-after-free in the DOM: Security component CVE-2026-84122 — firefox: Use-after-free in the Audio/Video component CVE-2026-84124 — firefox: Use-after-free in the DOM: Core & HTML component CVE-2026-84131 — firefox: Privilege escalation due to invalid pointer in the Graphics component CVE-2026-84143 — firefox: Internally found bugs fixed in Firefox 155, Firefox ESR 153.2 and Firefox ESR 140.15 CVE-2026-84145 — firefox: Internally found bugs fixed in Firefox 155, Firefox ESR 153.2, Firefox ESR 140.15 and Firefox ESR 115.40 CVE-2026-84639 — thunderbird: Uninitialized memory in MIME parsing CVE-2026-84640 — thunderbird: One byte overflow read in mail parser CVE-2026-84641 — thunderbird: Information disclosure due to malicious IMAP server response CVE-2026-92005 — firefox: thunderbird: Use-after-free in the Audio/Video: Web Codecs component CVE-2026-92006 — firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component CVE-2026-92007 — firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component CVE-2026-92008 — firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component CVE-2026-92009 — firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component CVE-2026-92010 — firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component CVE-2026-92011 — firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component CVE-2026-92012 — firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component CVE-2026-92013 — firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component CVE-2026-92014 — firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics component CVE-2026-92015 — firefox: thunderbird: Privilege escalation in the WebExtensions component CVE-2026-92016 — firefox: thunderbird: Use-after-free in the Disability Access APIs component CVE-2026-92017 — firefox: thunderbird: Privilege escalation in the DOM: Service Workers component CVE-2026-92018 — firefox: thunderbird: Sandbox escape in the DOM: Core & HTML component CVE-2026-92019 — firefox: thunderbird: Mitigation bypass in the Remote Settings Client component CVE-2026-92020 — firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: WebRender component CVE-2026-92021 — firefox: thunderbird: Use-after-free in the JavaScript Engine: JIT component CVE-2026-92022 — firefox: thunderbird: Use-after-free in the DOM: HTML Parser component CVE-2026-92023 — firefox: thunderbird: Use-after-free in the XML component CVE-2026-92024 — firefox: thunderbird: Use-after-free in the SVG component CVE-2026-92025 — firefox: thunderbird: Use-after-free in the DOM: Navigation component CVE-2026-92026 — firefox: thunderbird: Use-after-free in the Networking component CVE-2026-92027 — firefox: thunderbird: Use-after-free in the DOM: Streams component CVE-2026-92028 — firefox: thunderbird: Use-after-free in the DOM: Core & HTML component CVE-2026-92029 — firefox: thunderbird: Use-after-free in the SVG component CVE-2026-92030 — firefox: thunderbird: Mitigation bypass in the DOM: Copy & Paste and Drag & Drop component CVE-2026-92031 — firefox: thunderbird: Information disclosure in the Graphics: ImageLib component CVE-2026-92032 — firefox: thunderbird: Sandbox escape due to invalid pointer in the Graphics component CVE-2026-92238 — thunderbird: Thunderbird: Memory safety violations via maliciously crafted mail headers CVE-2026-92239 — thunderbird: Thunderbird: Out-of-bounds read via maliciously constructed IMAP line CVE-2026-92240 — thunderbird: Out-of-bounds read in IMAP response parser

🎯 Affected products14

  • Red Hat Enterprise Linux AppStream (v. 9)
  • thunderbird-0:140.16.0-1.el9_8.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • thunderbird-0:140.16.0-1.el9_8.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • thunderbird-0:140.16.0-1.el9_8.s390x as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • thunderbird-0:140.16.0-1.el9_8.src as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • thunderbird-0:140.16.0-1.el9_8.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • thunderbird-debuginfo-0:140.16.0-1.el9_8.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • thunderbird-debuginfo-0:140.16.0-1.el9_8.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • thunderbird-debuginfo-0:140.16.0-1.el9_8.s390x as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • thunderbird-debuginfo-0:140.16.0-1.el9_8.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • thunderbird-debugsource-0:140.16.0-1.el9_8.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • thunderbird-debugsource-0:140.16.0-1.el9_8.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • thunderbird-debugsource-0:140.16.0-1.el9_8.s390x as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • thunderbird-debugsource-0:140.16.0-1.el9_8.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 9)

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258

🔗 References (46)