- What: Security update for Thunderbird in Red Hat Enterprise Linux 8
- Impact: Users of Thunderbird may be vulnerable if not updated
Red Hat Product Errata RHSA-2026:65160 - Security Advisory Issued: 2026-09-08 Updated: 2026-09-08 RHSA-2026:65160 - Security Advisory Overview Updated Packages Synopsis Important: thunderbird security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for thunderbird is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description Mozilla Thunderbird is a standalone mail and newsgroup client. Security Fix(es): firefox: thunderbird: Site isolation issue in the Graphics: CanvasWebGL component (CVE-2026-74934) firefox: thunderbird: Privilege escalation in the Networking: Cookies component (CVE-2026-74953) firefox: thunderbird: Internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 (CVE-2026-74987) firefox: thunderbird: Information disclosure in the Graphics component (CVE-2026-74948) firefox: thunderbird: Information disclosure in the DOM: UI Events & Focus Handling component (CVE-2026-74971) firefox: thunderbird: Privilege escalation in the Graphics: CanvasWebGL component (CVE-2026-74941) firefox: Privilege escalation in the Shell Integration component (CVE-2026-74965) firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component (CVE-2026-74946) firefox: Race condition, use-after-free in the Graphics component (CVE-2026-74973) firefox: thunderbird: Internally found bugs fixed in Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 (CVE-2026-74990) firefox: thunderbird: Use-after-free in the Graphics: Text component (CVE-2026-74940) firefox: thunderbird: Site isolation issue in the WebExtensions component (CVE-2026-74960) firefox: thunderbird: Mitigation bypass in the Storage: Cache API component (CVE-2026-74959) firefox: thunderbird: JIT miscompilation in the JavaScript Engine: JIT component (CVE-2026-74976) firefox: thunderbird: Same-origin policy bypass in the Graphics: ImageLib component (CVE-2026-74974) firefox: thunderbird: Mitigation bypass in the Safe Browsing component (CVE-2026-74957) firefox: thunderbird: Same-origin policy bypass in the Audio/Video: Playback component (CVE-2026-74967) firefox: Privilege escalation in the Remote Settings Client component (CVE-2026-74942) firefox: thunderbird: Privilege escalation in the DOM: Navigation component (CVE-2026-74939) firefox: thunderbird: Information disclosure in the DOM: Push Subscriptions component (CVE-2026-74972) firefox: thunderbird: Information disclosure in the Graphics: Text component (CVE-2026-74945) firefox: thunderbird: Same-origin policy bypass in the Networking: Cookies component (CVE-2026-74963) firefox: Integer overflow in the Graphics component (CVE-2026-74964) firefox: Site isolation issue in the Networking: Cookies component (CVE-2026-74962) firefox: thunderbird: Privilege escalation in the DOM: Networking component (CVE-2026-74935) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 8 x86_64 Red Hat Enterprise Linux for IBM z Systems 8 s390x Red Hat Enterprise Linux for Power, little endian 8 ppc64le Red Hat Enterprise Linux for ARM 64 8 aarch64 Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 8.10 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 8.10 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 8.10 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 8.10 s390x Fixes BZ - 2517820 - CVE-2026-74934 firefox: thunderbird: Site isolation issue in the Graphics: CanvasWebGL component BZ - 2517822 - CVE-2026-74953 firefox: thunderbird: Privilege escalation in the Networking: Cookies component BZ - 2517823 - CVE-2026-74987 firefox: thunderbird: Internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 BZ - 2517825 - CVE-2026-74948 firefox: thunderbird: Information disclosure in the Graphics component BZ - 2517831 - CVE-2026-74971 firefox: thunderbird: Information disclosure in the DOM: UI Events & Focus Handling component BZ - 2517833 - CVE-2026-74941 firefox: thunderbird: Privilege escalation in the Graphics: CanvasWebGL component BZ - 2517834 - CVE-2026-74965 firefox: Privilege escalation in the Shell Integration component BZ - 2517835 - CVE-2026-74946 firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component BZ - 2517836 - CVE-2026-74973 firefox: Race condition, use-after-free in the Graphics component BZ - 2517839 - CVE-2026-74990 firefox: thunderbird: Internally found bugs fixed in Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 BZ - 2517841 - CVE-2026-74940 firefox: thunderbird: Use-after-free in the Graphics: Text component BZ - 2517845 - CVE-2026-74960 firefox: thunderbird: Site isolation issue in the WebExtensions component BZ - 2517849 - CVE-2026-74959 firefox: thunderbird: Mitigation bypass in the Storage: Cache API component BZ - 2517851 - CVE-2026-74976 firefox: thunderbird: JIT miscompilation in the JavaScript Engine: JIT component BZ - 2517853 - CVE-2026-74974 firefox: thunderbird: Same-origin policy bypass in the Graphics: ImageLib component BZ - 2517856 - CVE-2026-74957 firefox: thunderbird: Mitigation bypass in the Safe Browsing component BZ - 2517858 - CVE-2026-74967 firefox: thunderbird: Same-origin policy bypass in the Audio/Video: Playback component BZ - 2517859 - CVE-2026-74942 firefox: Privilege escalation in the Remote Settings Client component BZ - 2517860 - CVE-2026-74939 firefox: thunderbird: Privilege escalation in the DOM: Navigation component BZ - 2517862 - CVE-2026-74972 firefox: thunderbird: Information disclosure in the DOM: Push Subscriptions component BZ - 2517863 - CVE-2026-74945 firefox: thunderbird: Information disclosure in the Graphics: Text component BZ - 2517866 - CVE-2026-74963 firefox: thunderbird: Same-origin policy bypass in the Networking: Cookies component BZ - 2517870 - CVE-2026-74964 firefox: Integer overflow in the Graphics component BZ - 2517872 - CVE-2026-74962 firefox: Site isolation issue in the Networking: Cookies component BZ - 2517874 - CVE-2026-74935 firefox: thunderbird: Privilege escalation in the DOM: Networking component CVEs CVE-2026-74934 CVE-2026-74935 CVE-2026-74939 CVE-2026-74940 CVE-2026-74941 CVE-2026-74942 CVE-2026-74945 CVE-2026-74946 CVE-2026-74948 CVE-2026-74953 CVE-2026-74957 CVE-2026-74959 CVE-2026-74960 CVE-2026-74962 CVE-2026-74963 CVE-2026-74964 CVE-2026-74965 CVE-2026-74967 CVE-2026-74971 CVE-2026-74972 CVE-2026-74973 CVE-2026-74974 CVE-2026-74976 CVE-2026-74987 CVE-2026-74990 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 8 SRPM thunderbird-140.14.0-1.el8_10.src.rpm SHA-256: 584c28833bab2d6159492842be3f87560fa06425263c4c6117be46b981088e6a x86_64 thunderbird-140.14.0-1.el8_10.x86_64.rpm SHA-256: 0ff26384e1e201e248caca6eb9b0cd2f75e1c78eef7830d720034ba47d779a76 thunderbird-debuginfo-140.14.0-1.el8_10.x86_64.rpm SHA-256: b0f00d0a8ca849689617577f842e91f879cf7c0df94d342b8bd82bc3389a5080 thunderbird-debugsource-140.14.0-1.el8_10.x86_64.rpm SHA-256: ffa34ff784c8b02e6e50ba2c3994fae28f411300af8cdbcf20284aa90827f1a1 Red Hat Enterprise Linux for IBM z Systems 8 SRPM thunderbird-140.14.0-1.el8_10.src.rpm SHA-256: 584c28833bab2d6159492842be3f87560fa06425263c4c6117be46b981088e6a s390x thunderbird-140.14.0-1.el8_10.s390x.rpm SHA-256: 91a39950d60fa5c2ba557a4cf4c5000c358f1582343be2107af0a4d95a1067fa thunderbird-debuginfo-140.14.0-1.el8_10.s390x.rpm SHA-256: 45e04f7fd78de9739c50472e19118710728f156b67718c35f2166cb907bb81f4 thunderbird-debugsource-140.14.0-1.el8_10.s390x.rpm SHA-256: f3fc758f9c2e051dc5748925a48c701134a86fca80f5d8ddf939b2917a871283 Red Hat Enterprise Linux for Power, little endian 8 SRPM thunderbird-140.14.0-1.el8_10.src.rpm SHA-256: 584c28833bab2d6159492842be3f87560fa06425263c4c6117be46b981088e6a ppc64le thunderbird-140.14.0-1.el8_10.ppc64le.rpm SHA-256: 3357c8c02427f159220099a8c3b58d01a346d5af630e4d10b6d58d5eceec29f8 thunderbird-debuginfo-140.14.0-1.el8_10.ppc64le.rpm SHA-256: 63d35fd6e150e5056c35ec2d4b915f8eefbf4a39fcef04efb82ef059ce866db4 thunderbird-debugsource-140.14.0-1.el8_10.ppc64le.rpm SHA-256: d28fc6e81e9cda0bc62562b30d48eac2c47bac82465c4c688bad09e81dd05233 Red Hat Enterprise Linux for ARM 64 8 SRPM thunderbird-140.14.0-1.el8_10.src.rpm SHA-256: 584c28833bab2d6159492842be3f87560fa06425263c4c6117be46b981088e6a aarch64 thunderbird-140.14.0-1.el8_10.aarch64.rpm SHA-256: bad70c69e4801adadf86fa3ca287f36c1bb9da04d950eb23723ccef1f4268322 thunderbird-debuginfo-140.14.0-1.el8_10.aarch64.rpm SHA-256: 9755c0f814ca3ae2b82003e222360c37c0372f6e9c66bde42314d10a184cf056 thunderbird-debugsource-140.14.0-1.el8_10.aarch64.rpm SHA-256: e4199a79cb7b39679a7ca0ae4e8972b1639ca9e2a02290ac8f7604096f79f070 Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 8.10 SRPM thunderbird-140.14.0-1.el8_10.src.rpm SHA-256: 584c28833bab2d6159492842be3f87560fa06425263c4c6117be46b981088e6a x86_64 thunderbird-140.14.0-1.el8_10.x86_64.rpm SHA-256: 0ff26384e1e201e248caca6eb9b0cd2f75e1c78eef7830d720034ba47d779a76 thunderbird-debuginfo-140.14.0-1.el8_10.x86_64.rpm SHA-256: b0f00d0a8ca849689617577f842e91