Security News

Cybersecurity news aggregator

🔄
INFO Updates Red Hat Errata

RHSA-2026:65159: Important: thunderbird security update

  • What: Security update for Thunderbird in Red Hat Enterprise Linux 10
  • Impact: Users of Thunderbird may be vulnerable if not updated
Read Full Article →

Red Hat Product Errata RHSA-2026:65159 - Security Advisory Issued: 2026-09-08 Updated: 2026-09-08 RHSA-2026:65159 - Security Advisory Overview Updated Packages Synopsis Important: thunderbird security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for thunderbird is now available for Red Hat Enterprise Linux 10. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description Mozilla Thunderbird is a standalone mail and newsgroup client. Security Fix(es): firefox: thunderbird: Site isolation issue in the Graphics: CanvasWebGL component (CVE-2026-74934) firefox: thunderbird: Privilege escalation in the Networking: Cookies component (CVE-2026-74953) firefox: thunderbird: Internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 (CVE-2026-74987) firefox: thunderbird: Information disclosure in the Graphics component (CVE-2026-74948) firefox: thunderbird: Information disclosure in the DOM: UI Events & Focus Handling component (CVE-2026-74971) firefox: Race condition, use-after-free in the Graphics component (CVE-2026-74973) firefox: thunderbird: Internally found bugs fixed in Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 (CVE-2026-74990) firefox: thunderbird: Use-after-free in the JavaScript: WebAssembly component (CVE-2026-74936) firefox: thunderbird: Site isolation issue in the WebExtensions component (CVE-2026-74960) firefox: thunderbird: Mitigation bypass in the Storage: Cache API component (CVE-2026-74959) firefox: thunderbird: JIT miscompilation in the JavaScript Engine: JIT component (CVE-2026-74976) firefox: thunderbird: Same-origin policy bypass in the Graphics: ImageLib component (CVE-2026-74974) firefox: thunderbird: Mitigation bypass in the Safe Browsing component (CVE-2026-74957) firefox: Privilege escalation in the Remote Settings Client component (CVE-2026-74942) firefox: thunderbird: Privilege escalation in the DOM: Navigation component (CVE-2026-74939) firefox: thunderbird: Information disclosure in the DOM: Push Subscriptions component (CVE-2026-74972) firefox: thunderbird: Information disclosure in the Graphics: Text component (CVE-2026-74945) firefox: thunderbird: Same-origin policy bypass in the Networking: Cookies component (CVE-2026-74963) firefox: Integer overflow in the Graphics component (CVE-2026-74964) firefox: Site isolation issue in the Networking: Cookies component (CVE-2026-74962) firefox: thunderbird: Privilege escalation in the DOM: Networking component (CVE-2026-74935) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 10 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.2 x86_64 Red Hat Enterprise Linux for IBM z Systems 10 s390x Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.2 s390x Red Hat Enterprise Linux for Power, little endian 10 ppc64le Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.2 ppc64le Red Hat Enterprise Linux for ARM 64 10 aarch64 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.2 aarch64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 10.2 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 10.2 s390x Red Hat Enterprise Linux for Power, little endian - 4 years of support 10.2 ppc64le Red Hat Enterprise Linux for x86_64 - 4 years of updates 10.2 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 10.2 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 10.2 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 10.2 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 10.2 s390x Fixes BZ - 2517820 - CVE-2026-74934 firefox: thunderbird: Site isolation issue in the Graphics: CanvasWebGL component BZ - 2517822 - CVE-2026-74953 firefox: thunderbird: Privilege escalation in the Networking: Cookies component BZ - 2517823 - CVE-2026-74987 firefox: thunderbird: Internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 BZ - 2517825 - CVE-2026-74948 firefox: thunderbird: Information disclosure in the Graphics component BZ - 2517831 - CVE-2026-74971 firefox: thunderbird: Information disclosure in the DOM: UI Events & Focus Handling component BZ - 2517836 - CVE-2026-74973 firefox: Race condition, use-after-free in the Graphics component BZ - 2517839 - CVE-2026-74990 firefox: thunderbird: Internally found bugs fixed in Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 BZ - 2517840 - CVE-2026-74936 firefox: thunderbird: Use-after-free in the JavaScript: WebAssembly component BZ - 2517845 - CVE-2026-74960 firefox: thunderbird: Site isolation issue in the WebExtensions component BZ - 2517849 - CVE-2026-74959 firefox: thunderbird: Mitigation bypass in the Storage: Cache API component BZ - 2517851 - CVE-2026-74976 firefox: thunderbird: JIT miscompilation in the JavaScript Engine: JIT component BZ - 2517853 - CVE-2026-74974 firefox: thunderbird: Same-origin policy bypass in the Graphics: ImageLib component BZ - 2517856 - CVE-2026-74957 firefox: thunderbird: Mitigation bypass in the Safe Browsing component BZ - 2517859 - CVE-2026-74942 firefox: Privilege escalation in the Remote Settings Client component BZ - 2517860 - CVE-2026-74939 firefox: thunderbird: Privilege escalation in the DOM: Navigation component BZ - 2517862 - CVE-2026-74972 firefox: thunderbird: Information disclosure in the DOM: Push Subscriptions component BZ - 2517863 - CVE-2026-74945 firefox: thunderbird: Information disclosure in the Graphics: Text component BZ - 2517866 - CVE-2026-74963 firefox: thunderbird: Same-origin policy bypass in the Networking: Cookies component BZ - 2517870 - CVE-2026-74964 firefox: Integer overflow in the Graphics component BZ - 2517872 - CVE-2026-74962 firefox: Site isolation issue in the Networking: Cookies component BZ - 2517874 - CVE-2026-74935 firefox: thunderbird: Privilege escalation in the DOM: Networking component CVEs CVE-2026-74934 CVE-2026-74935 CVE-2026-74936 CVE-2026-74939 CVE-2026-74942 CVE-2026-74945 CVE-2026-74948 CVE-2026-74953 CVE-2026-74957 CVE-2026-74959 CVE-2026-74960 CVE-2026-74962 CVE-2026-74963 CVE-2026-74964 CVE-2026-74971 CVE-2026-74972 CVE-2026-74973 CVE-2026-74974 CVE-2026-74976 CVE-2026-74987 CVE-2026-74990 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 10 SRPM thunderbird-140.14.0-1.el10_2.src.rpm SHA-256: 80ef5602a320f4c42c9e4ac308d11220686d28e3d614eaf93ffbb0195d167cab x86_64 thunderbird-140.14.0-1.el10_2.x86_64.rpm SHA-256: 7467c40a7d83ae28c6b7636ef17f1cb4dc873e16d9b7203de83751b334542a4e thunderbird-debuginfo-140.14.0-1.el10_2.x86_64.rpm SHA-256: 1f604c87b0e3309778c56e9e932a8c519fa7ebe6a04a609433a18cdf517b06fe thunderbird-debugsource-140.14.0-1.el10_2.x86_64.rpm SHA-256: c85ca940885f4f47fdde0db03757de9f60f7e35887ce9330caef10f74eea393c Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.2 SRPM thunderbird-140.14.0-1.el10_2.src.rpm SHA-256: 80ef5602a320f4c42c9e4ac308d11220686d28e3d614eaf93ffbb0195d167cab x86_64 thunderbird-140.14.0-1.el10_2.x86_64.rpm SHA-256: 7467c40a7d83ae28c6b7636ef17f1cb4dc873e16d9b7203de83751b334542a4e thunderbird-debuginfo-140.14.0-1.el10_2.x86_64.rpm SHA-256: 1f604c87b0e3309778c56e9e932a8c519fa7ebe6a04a609433a18cdf517b06fe thunderbird-debugsource-140.14.0-1.el10_2.x86_64.rpm SHA-256: c85ca940885f4f47fdde0db03757de9f60f7e35887ce9330caef10f74eea393c Red Hat Enterprise Linux for IBM z Systems 10 SRPM thunderbird-140.14.0-1.el10_2.src.rpm SHA-256: 80ef5602a320f4c42c9e4ac308d11220686d28e3d614eaf93ffbb0195d167cab s390x thunderbird-140.14.0-1.el10_2.s390x.rpm SHA-256: 5d529ac981b6ea38eb0d17939e3f80fd84cab258756fec6cd6a4b17bc9dc6eee thunderbird-debuginfo-140.14.0-1.el10_2.s390x.rpm SHA-256: d194b96f55ce43b2f9d1c61667042b8f9eced30b9a77cef6390bd73d90428d71 thunderbird-debugsource-140.14.0-1.el10_2.s390x.rpm SHA-256: 024f8ee740d3edb5c9cb688db792926cd98b431f1bc0af21a8143b00ab66b901 Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.2 SRPM thunderbird-140.14.0-1.el10_2.src.rpm SHA-256: 80ef5602a320f4c42c9e4ac308d11220686d28e3d614eaf93ffbb0195d167cab s390x thunderbird-140.14.0-1.el10_2.s390x.rpm SHA-256: 5d529ac981b6ea38eb0d17939e3f80fd84cab258756fec6cd6a4b17bc9dc6eee thunderbird-debuginfo-140.14.0-1.el10_2.s390x.rpm SHA-256: d194b96f55ce43b2f9d1c61667042b8f9eced30b9a77cef6390bd73d90428d71 thunderbird-debugsource-140.14.0-1.el10_2.s390x.rpm SHA-256: 024f8ee740d3edb5c9cb688db792926cd98b431f1bc0af21a8143b00ab66b901 Red Hat Enterprise Linux for Power, little endian 10 SRPM thunderbird-140.14.0-1.el10_2.src.rpm SHA-256: 80ef5602a320f4c42c9e4ac308d11220686d28e3d614eaf93ffbb0195d167cab ppc64le thunderbird-140.14.0-1.el10_2.ppc64le.rpm SHA-256: bb25d1a37e9c57f9da0277d250c2a12fd0d29b634e039add272d49239c094432 thunderbird-debuginfo-140.14.0-1.el10_2.ppc64le.rpm SHA-256: eb24800e94a61dad5820e787093afee9833bf1cee2b92dc8c9ab7d36f0f125b6 thunderbird-debugsource-140.14.0-1.el10_2.ppc64le.rpm SHA-256: 55afe3f352ed0beb0303777af0ab1aaece2330be6a6e05a97bae314bfe7cff2e Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.2 SRPM thunderbird-140.14.0-1.el10_2.sr

Share this article