Red Hat Product Errata RHSA-2026:39428 - Security Advisory Issued: 2026-07-14 Updated: 2026-07-14 RHSA-2026:39428 - Security Advisory Overview Updated Packages Synopsis Important: thunderbird security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for thunderbird is now available for Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support and Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description Mozilla Thunderbird is a standalone mail and newsgroup client. Security Fix(es): firefox: thunderbird: Sandbox escape in the DOM: Workers component (CVE-2026-12294) firefox: thunderbird: Information disclosure, sandbox escape in the Security: Process Sandboxing component (CVE-2026-12313) firefox: thunderbird: Information disclosure, sandbox escape in the Security: Process Sandboxing component (CVE-2026-12311) firefox: thunderbird: Memory safety bug fixed in Thunderbird ESR 140.12 (CVE-2026-12290) firefox: thunderbird: Memory safety bugs fixed in Firefox ESR 140.12, Thunderbird ESR 140.12, Firefox 152 and Thunderbird 152 (CVE-2026-12327) firefox: thunderbird: JIT miscompilation in the DOM: Core & HTML component (CVE-2026-12299) firefox: thunderbird: Memory safety bug fixed in Thunderbird ESR 140.12 (CVE-2026-12329) firefox: thunderbird: Memory safety bug fixed in Thunderbird ESR 140.12 (CVE-2026-12312) firefox: thunderbird: Mitigation bypass in the DOM: Security component (CVE-2026-12302) firefox: thunderbird: Memory safety bugs fixed in Firefox ESR 115.37, Firefox ESR 140.12, Thunderbird ESR 140.12, Firefox 152 and Thunderbird 152 (CVE-2026-12328) firefox: thunderbird: Incorrect boundary conditions in the Internationalization component (CVE-2026-12330) firefox: thunderbird: Memory safety bug fixed in Thunderbird ESR 140.12 (CVE-2026-12314) firefox: thunderbird: Memory safety bug fixed in Thunderbird ESR 140.12 (CVE-2026-12309) firefox: thunderbird: Memory safety bug fixed in Thunderbird ESR 140.12 (CVE-2026-12310) firefox: thunderbird: Denial-of-service in the Graphics: ImageLib component (CVE-2026-12325) firefox: thunderbird: Sandbox escape in the DOM: Navigation component (CVE-2026-12295) firefox: thunderbird: Privilege escalation in the Graphics: WebRender component (CVE-2026-12289) firefox: thunderbird: Mitigation bypass in the DOM: Security component (CVE-2026-12315) firefox: thunderbird: Sandbox escape in the Security: Process Sandboxing component (CVE-2026-12296) firefox: thunderbird: Memory safety bug fixed in Thunderbird ESR 140.12 (CVE-2026-12306) firefox: thunderbird: Memory safety bug fixed in Thunderbird ESR 140.12 (CVE-2026-12307) firefox: thunderbird: Sandbox escape due to incorrect boundary conditions in the Networking component (CVE-2026-12297) firefox: thunderbird: Memory safety bug fixed in Thunderbird ESR 140.12 (CVE-2026-12305) firefox: thunderbird: Incorrect boundary conditions in the Web Audio component (CVE-2026-12292) firefox: thunderbird: Memory safety bug fixed in Thunderbird ESR 140.12 (CVE-2026-12308) firefox: thunderbird: Incorrect boundary conditions in the Graphics: CanvasWebGL component (CVE-2026-12324) firefox: thunderbird: Same-origin policy bypass in the Networking: Cookies component (CVE-2026-12304) firefox: thunderbird: Use-after-free in the Networking: HTTP component (CVE-2026-12291) firefox: thunderbird: Memory safety bug fixed in Firefox ESR 140.12 (CVE-2026-12298) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 - Extended Life Cycle Long Life 8.4 x86_64 Red Hat Enterprise Linux Server - AUS 8.4 x86_64 Fixes BZ - 2489207 - CVE-2026-12294 firefox: thunderbird: Sandbox escape in the DOM: Workers component BZ - 2489208 - CVE-2026-12313 firefox: thunderbird: Information disclosure, sandbox escape in the Security: Process Sandboxing component BZ - 2489209 - CVE-2026-12311 firefox: thunderbird: Information disclosure, sandbox escape in the Security: Process Sandboxing component BZ - 2489210 - CVE-2026-12290 firefox: thunderbird: Memory safety bug fixed in Thunderbird ESR 140.12 BZ - 2489211 - CVE-2026-12327 firefox: thunderbird: Memory safety bugs fixed in Firefox ESR 140.12, Thunderbird ESR 140.12, Firefox 152 and Thunderbird 152 BZ - 2489212 - CVE-2026-12299 firefox: thunderbird: JIT miscompilation in the DOM: Core & HTML component BZ - 2489214 - CVE-2026-12329 firefox: thunderbird: Memory safety bug fixed in Thunderbird ESR 140.12 BZ - 2489215 - CVE-2026-12312 firefox: thunderbird: Memory safety bug fixed in Thunderbird ESR 140.12 BZ - 2489217 - CVE-2026-12302 firefox: thunderbird: Mitigation bypass in the DOM: Security component BZ - 2489218 - CVE-2026-12328 firefox: thunderbird: Memory safety bugs fixed in Firefox ESR 115.37, Firefox ESR 140.12, Thunderbird ESR 140.12, Firefox 152 and Thunderbird 152 BZ - 2489220 - CVE-2026-12330 firefox: thunderbird: Incorrect boundary conditions in the Internationalization component BZ - 2489221 - CVE-2026-12314 firefox: thunderbird: Memory safety bug fixed in Thunderbird ESR 140.12 BZ - 2489223 - CVE-2026-12309 firefox: thunderbird: Memory safety bug fixed in Thunderbird ESR 140.12 BZ - 2489224 - CVE-2026-12310 firefox: thunderbird: Memory safety bug fixed in Thunderbird ESR 140.12 BZ - 2489225 - CVE-2026-12325 firefox: thunderbird: Denial-of-service in the Graphics: ImageLib component BZ - 2489226 - CVE-2026-12295 firefox: thunderbird: Sandbox escape in the DOM: Navigation component BZ - 2489229 - CVE-2026-12289 firefox: thunderbird: Privilege escalation in the Graphics: WebRender component BZ - 2489231 - CVE-2026-12315 firefox: thunderbird: Mitigation bypass in the DOM: Security component BZ - 2489232 - CVE-2026-12296 firefox: thunderbird: Sandbox escape in the Security: Process Sandboxing component BZ - 2489233 - CVE-2026-12306 firefox: thunderbird: Memory safety bug fixed in Thunderbird ESR 140.12 BZ - 2489234 - CVE-2026-12307 firefox: thunderbird: Memory safety bug fixed in Thunderbird ESR 140.12 BZ - 2489235 - CVE-2026-12297 firefox: thunderbird: Sandbox escape due to incorrect boundary conditions in the Networking component BZ - 2489236 - CVE-2026-12305 firefox: thunderbird: Memory safety bug fixed in Thunderbird ESR 140.12 BZ - 2489237 - CVE-2026-12292 firefox: thunderbird: Incorrect boundary conditions in the Web Audio component BZ - 2489239 - CVE-2026-12308 firefox: thunderbird: Memory safety bug fixed in Thunderbird ESR 140.12 BZ - 2489240 - CVE-2026-12324 firefox: thunderbird: Incorrect boundary conditions in the Graphics: CanvasWebGL component BZ - 2489243 - CVE-2026-12304 firefox: thunderbird: Same-origin policy bypass in the Networking: Cookies component BZ - 2489244 - CVE-2026-12291 firefox: thunderbird: Use-after-free in the Networking: HTTP component BZ - 2489248 - CVE-2026-12298 firefox: thunderbird: Memory safety bug fixed in Firefox ESR 140.12 CVEs CVE-2026-12289 CVE-2026-12290 CVE-2026-12291 CVE-2026-12292 CVE-2026-12294 CVE-2026-12295 CVE-2026-12296 CVE-2026-12297 CVE-2026-12298 CVE-2026-12299 CVE-2026-12302 CVE-2026-12304 CVE-2026-12305 CVE-2026-12306 CVE-2026-12307 CVE-2026-12308 CVE-2026-12309 CVE-2026-12310 CVE-2026-12311 CVE-2026-12312 CVE-2026-12313 CVE-2026-12314 CVE-2026-12315 CVE-2026-12324 CVE-2026-12325 CVE-2026-12327 CVE-2026-12328 CVE-2026-12329 CVE-2026-12330 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 - Extended Life Cycle Long Life 8.4 SRPM thunderbird-140.12.0-1.el8_4.src.rpm SHA-256: cc2f9c909dc263c2be7ab356b2c6d2bd622b35a9c2db22150b57ea634ca0fdf0 x86_64 thunderbird-140.12.0-1.el8_4.x86_64.rpm SHA-256: 59d23f5fd859ce651b1e7f6c8cf7a7037b275e8c30ca4d200fd2ed494f3772d4 thunderbird-debuginfo-140.12.0-1.el8_4.x86_64.rpm SHA-256: ab57bd82e739e6a1a8008235f82ede96f408c951a89d8208ea4ba8334465164f thunderbird-debugsource-140.12.0-1.el8_4.x86_64.rpm SHA-256: 3062d14c7acbfe697e798f6061813a2bd3906c97e408b3771df95a85c8e6e333 Red Hat Enterprise Linux Server - AUS 8.4 SRPM thunderbird-140.12.0-1.el8_4.src.rpm SHA-256: cc2f9c909dc263c2be7ab356b2c6d2bd622b35a9c2db22150b57ea634ca0fdf0 x86_64 thunderbird-140.12.0-1.el8_4.x86_64.rpm SHA-256: 59d23f5fd859ce651b1e7f6c8cf7a7037b275e8c30ca4d200fd2ed494f3772d4 thunderbird-debuginfo-140.12.0-1.el8_4.x86_64.rpm SHA-256: ab57bd82e739e6a1a8008235f82ede96f408c951a89d8208ea4ba8334465164f thunderbird-debugsource-140.12.0-1.el8_4.x86_64.rpm SHA-256: 3062d14c7acbfe697e798f6061813a2bd3906c97e408b3771df95a85c8e6e333 The Red Hat security contact is secalert@redhat.com . More contact details at https://access.redhat.com/security/team/contact/ .
This security update addresses multiple critical vulnerabilities in Thunderbird, including a critical sandbox escape in the DOM: Workers component (CVE-2026-12294, CVSS 9.6) and a privilege escalation in the Graphics: WebRender component (CVE-2026-12289). Affected versions include Thunderbird ESR prior to 140.12.0 and Thunderbird prior to 152.0.0. The remediation is to upgrade to Thunderbird ESR 140.12.0 or Thunderbird 152.0.0.