- What: Security update for Thunderbird
- Impact: Red Hat Enterprise Linux 8.6 systems
Red Hat Product Errata RHSA-2026:53453 - Security Advisory Issued: 2026-08-11 Updated: 2026-08-11 RHSA-2026:53453 - Security Advisory Overview Updated Packages Synopsis Important: thunderbird security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for thunderbird is now available for Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support and Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description Mozilla Thunderbird is a standalone mail and newsgroup client. Security Fix(es): firefox: thunderbird: Site isolation issue in the DOM: Navigation component (CVE-2026-15719) firefox: thunderbird: Invalid pointer in the JavaScript: WebAssembly component (CVE-2026-15718) firefox: thunderbird: Mitigation bypass in the Enterprise Policies component (CVE-2026-16390) firefox: thunderbird: Incorrect boundary conditions in the Audio/Video: cubeb component (CVE-2026-16350) firefox: thunderbird: Information disclosure in the Storage: IndexedDB component (CVE-2026-16391) firefox: thunderbird: Site isolation issue in the Networking: HTTP component (CVE-2026-16375) firefox: thunderbird: Sandbox escape due to use-after-free in the Disability Access APIs component (CVE-2026-16356) firefox: thunderbird: JIT miscompilation in the JavaScript: WebAssembly component (CVE-2026-16363) firefox: thunderbird: Memory safety bugs fixed in Firefox ESR 140.13 and Firefox 153 (CVE-2026-16412) firefox: thunderbird: Same-origin policy bypass in the Networking: DNS component (CVE-2026-16381) firefox: thunderbird: JIT miscompilation in the JavaScript Engine: JIT component (CVE-2026-16355) firefox: thunderbird: Memory safety bugs fixed in Firefox ESR 115.38 and Firefox ESR 140.13 (CVE-2026-16361) firefox: thunderbird: Sandbox escape due to use-after-free in the Disability Access APIs component (CVE-2026-16352) firefox: thunderbird: Incorrect boundary conditions in the JavaScript: WebAssembly component (CVE-2026-16368) firefox: thunderbird: Mitigation bypass in the PDF Viewer component (CVE-2026-16377) firefox: thunderbird: Memory safety bugs fixed in Firefox ESR 115.38, Firefox ESR 140.13 and Firefox 153 (CVE-2026-16360) firefox: thunderbird: Use-after-free in the WebRTC: Audio/Video component (CVE-2026-16362) firefox: thunderbird: Site isolation issue in the Graphics: WebRender component (CVE-2026-16358) firefox: thunderbird: Site isolation issue in the Networking component (CVE-2026-16387) firefox: thunderbird: Same-origin policy bypass in the DOM: Navigation component (CVE-2026-16349) firefox: thunderbird: Incorrect boundary conditions in the Graphics component (CVE-2026-16357) firefox: thunderbird: Sandbox escape due to use-after-free in the DOM: Navigation component (CVE-2026-16351) firefox: thunderbird: Privilege escalation in the DOM: Navigation component (CVE-2026-16371) firefox: thunderbird: Privilege escalation in the DOM: Content Processes component (CVE-2026-16379) firefox: thunderbird: Information disclosure in the Graphics: ImageLib component (CVE-2026-16354) firefox: thunderbird: Information disclosure in the Framework component in DevTools (CVE-2026-16374) firefox: thunderbird: Incorrect boundary conditions in the Audio/Video: GMP component (CVE-2026-16359) firefox: thunderbird: Mitigation bypass in the DOM: Networking component (CVE-2026-16383) firefox: thunderbird: Integer overflow in the JavaScript: WebAssembly component (CVE-2026-16369) firefox: thunderbird: Invalid pointer in the DOM: Bindings (WebIDL) component (CVE-2026-16353) firefox: thunderbird: Privilege escalation in WebExtensions (CVE-2026-16396) firefox: thunderbird: Information disclosure in the Networking: WebSockets component (CVE-2026-16405) thunderbird: Off-by-one out of bounds read in MIME header parser for forwarding (CVE-2026-14899) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 - Extended Life Cycle Long Life 8.6 x86_64 Red Hat Enterprise Linux Server - AUS 8.6 x86_64 Fixes BZ - 2499973 - CVE-2026-15719 firefox: thunderbird: Site isolation issue in the DOM: Navigation component BZ - 2499974 - CVE-2026-15718 firefox: thunderbird: Invalid pointer in the JavaScript: WebAssembly component BZ - 2503415 - CVE-2026-16390 firefox: thunderbird: Mitigation bypass in the Enterprise Policies component BZ - 2503416 - CVE-2026-16350 firefox: thunderbird: Incorrect boundary conditions in the Audio/Video: cubeb component BZ - 2503420 - CVE-2026-16391 firefox: thunderbird: Information disclosure in the Storage: IndexedDB component BZ - 2503423 - CVE-2026-16375 firefox: thunderbird: Site isolation issue in the Networking: HTTP component BZ - 2503425 - CVE-2026-16356 firefox: thunderbird: Sandbox escape due to use-after-free in the Disability Access APIs component BZ - 2503430 - CVE-2026-16363 firefox: thunderbird: JIT miscompilation in the JavaScript: WebAssembly component BZ - 2503432 - CVE-2026-16412 firefox: thunderbird: Memory safety bugs fixed in Firefox ESR 140.13 and Firefox 153 BZ - 2503434 - CVE-2026-16381 firefox: thunderbird: Same-origin policy bypass in the Networking: DNS component BZ - 2503439 - CVE-2026-16355 firefox: thunderbird: JIT miscompilation in the JavaScript Engine: JIT component BZ - 2503440 - CVE-2026-16361 firefox: thunderbird: Memory safety bugs fixed in Firefox ESR 115.38 and Firefox ESR 140.13 BZ - 2503444 - CVE-2026-16352 firefox: thunderbird: Sandbox escape due to use-after-free in the Disability Access APIs component BZ - 2503451 - CVE-2026-16368 firefox: thunderbird: Incorrect boundary conditions in the JavaScript: WebAssembly component BZ - 2503454 - CVE-2026-16377 firefox: thunderbird: Mitigation bypass in the PDF Viewer component BZ - 2503456 - CVE-2026-16360 firefox: thunderbird: Memory safety bugs fixed in Firefox ESR 115.38, Firefox ESR 140.13 and Firefox 153 BZ - 2503463 - CVE-2026-16362 firefox: thunderbird: Use-after-free in the WebRTC: Audio/Video component BZ - 2503472 - CVE-2026-16358 firefox: thunderbird: Site isolation issue in the Graphics: WebRender component BZ - 2503473 - CVE-2026-16387 firefox: thunderbird: Site isolation issue in the Networking component BZ - 2503485 - CVE-2026-16349 firefox: thunderbird: Same-origin policy bypass in the DOM: Navigation component BZ - 2503489 - CVE-2026-16357 firefox: thunderbird: Incorrect boundary conditions in the Graphics component BZ - 2503491 - CVE-2026-16351 firefox: thunderbird: Sandbox escape due to use-after-free in the DOM: Navigation component BZ - 2503497 - CVE-2026-16371 firefox: thunderbird: Privilege escalation in the DOM: Navigation component BZ - 2503498 - CVE-2026-16379 firefox: thunderbird: Privilege escalation in the DOM: Content Processes component BZ - 2503500 - CVE-2026-16354 firefox: thunderbird: Information disclosure in the Graphics: ImageLib component BZ - 2503501 - CVE-2026-16374 firefox: thunderbird: Information disclosure in the Framework component in DevTools BZ - 2503505 - CVE-2026-16359 firefox: thunderbird: Incorrect boundary conditions in the Audio/Video: GMP component BZ - 2503512 - CVE-2026-16383 firefox: thunderbird: Mitigation bypass in the DOM: Networking component BZ - 2503513 - CVE-2026-16369 firefox: thunderbird: Integer overflow in the JavaScript: WebAssembly component BZ - 2503517 - CVE-2026-16353 firefox: thunderbird: Invalid pointer in the DOM: Bindings (WebIDL) component BZ - 2503521 - CVE-2026-16396 firefox: thunderbird: Privilege escalation in WebExtensions BZ - 2503527 - CVE-2026-16405 firefox: thunderbird: Information disclosure in the Networking: WebSockets component BZ - 2506217 - CVE-2026-14899 thunderbird: Off-by-one out of bounds read in MIME header parser for forwarding CVEs CVE-2026-14899 CVE-2026-15718 CVE-2026-15719 CVE-2026-16349 CVE-2026-16350 CVE-2026-16351 CVE-2026-16352 CVE-2026-16353 CVE-2026-16354 CVE-2026-16355 CVE-2026-16356 CVE-2026-16357 CVE-2026-16358 CVE-2026-16359 CVE-2026-16360 CVE-2026-16361 CVE-2026-16362 CVE-2026-16363 CVE-2026-16368 CVE-2026-16369 CVE-2026-16371 CVE-2026-16374 CVE-2026-16375 CVE-2026-16377 CVE-2026-16379 CVE-2026-16381 CVE-2026-16383 CVE-2026-16387 CVE-2026-16390 CVE-2026-16391 CVE-2026-16396 CVE-2026-16405 CVE-2026-16412 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 - Extended Life Cycle Long Life 8.6 SRPM thunderbird-140.13.0-1.el8_6.src.rpm SHA-256: 04f8419b17ac3fe3946b264e07cf7e2f39655519323069ea0e95ed10b507546f x86_64 thunderbird-140.13.0-1.el8_6.x86_64.rpm SHA-256: a836fb35cfa8c03c81b96375bc9aea63cb1a37dcbcb04955a2d421054081b5bc thunderbird-debuginfo-140.13.0-1.el8_6.x86_64.rpm SHA-256: ac1880876aee70ef40810c1672bad352e38a4403074d17fc46ee76be0d732513 thunderbird-debugsource-140.13.0-1.el8_6.x86_64.rpm SHA-256: 6025f9c0245ebfad03879678001f89fb328cf25f57463214b2b7aff055dcaeff Red Hat Enterprise Linux Server - AUS 8.6 SRPM thunderbird-140.13.0-1.el8_6.src.rpm SHA-256: 04f8419b17ac3fe3946b264e07cf7e2f39655519323069ea0e95ed10b507546f x86_64 thunderbird-140.13.0-1.el8_6.x86_64.rpm SHA-256: a836fb35cfa8c03c81b96375bc9aea63cb1a37dcbcb04955a2d421054081b5bc thunderbird-debuginfo-140.13.0-1.el8_6.x86_64.rpm SHA-256: ac1880876aee70ef40810c1672bad352e38a4