Issued at: 2026-09-25
Updated at: 2026-09-25
Advisory content derived from Red Hat RHSA-2026:70642, © Red Hat, Inc., used under CC BY 4.0, with modifications.
Synopsis
Important: thunderbird security update
Description
Mozilla Thunderbird is a standalone mail and newsgroup client.
Security Fix(es):
* firefox: thunderbird: Privilege escalation in the DOM: Workers component (CVE-2026-16365)
* firefox: thunderbird: Sandbox escape in the Remote Settings Client component (CVE-2026-75874)
* firefox: Sandbox escape due to use-after-free in the DOM: Security component (CVE-2026-84121)
* firefox: Internally found bugs fixed in Firefox 155, Firefox ESR 153.2, Firefox ESR 140.15 and Firefox ESR 115.40 (CVE-2026-84145)
* firefox: Sandbox escape due to use-after-free in the DOM: Navigation component (CVE-2026-84119)
* firefox: Use-after-free in the Audio/Video component (CVE-2026-84120)
* firefox: Privilege escalation due to invalid pointer in the Graphics component (CVE-2026-84131)
* firefox: Use-after-free in the DOM: Core & HTML component (CVE-2026-84124)
* firefox: Use-after-free in the Audio/Video component (CVE-2026-84122)
* firefox: Internally found bugs fixed in Firefox 155, Firefox ESR 153.2 and Firefox ESR 140.15 (CVE-2026-84143)
* thunderbird: Uninitialized memory in MIME parsing (CVE-2026-84639)
* thunderbird: Information disclosure due to malicious IMAP server response (CVE-2026-84641)
* thunderbird: One byte overflow read in mail parser (CVE-2026-84640)
* firefox: thunderbird: Use-after-free in the SVG component (CVE-2026-92024)
* firefox: thunderbird: Mitigation bypass in the Remote Settings Client component (CVE-2026-92019)
* firefox: thunderbird: Use-after-free in the Networking component (CVE-2026-92026)
* firefox: thunderbird: Information disclosure in the Graphics: ImageLib component (CVE-2026-92031)
* firefox: thunderbird: Sandbox escape due to invalid pointer in the Graphics component (CVE-2026-92032)
* firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component (CVE-2026-92010)
* firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component (CVE-2026-92006)
* firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component (CVE-2026-92011)
* firefox: thunderbird: Use-after-free in the DOM: Streams component (CVE-2026-92027)
* firefox: thunderbird: Use-after-free in the DOM: Core & HTML component (CVE-2026-92028)
* firefox: thunderbird: Privilege escalation in the WebExtensions component (CVE-2026-92015)
* firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component (CVE-2026-92013)
* firefox: thunderbird: Use-after-free in the Disability Access APIs component (CVE-2026-92016)
* firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component (CVE-2026-92012)
* firefox: thunderbird: Use-after-free in the DOM: HTML Parser component (CVE-2026-92022)
* firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics component (CVE-2026-92014)
* firefox: thunderbird: Sandbox escape in the DOM: Core & HTML component (CVE-2026-92018)
* firefox: thunderbird: Use-after-free in the JavaScript Engine: JIT component (CVE-2026-92021)
* firefox: thunderbird: Use-after-free in the Audio/Video: Web Codecs component (CVE-2026-92005)
* firefox: thunderbird: Privilege escalation in the DOM: Service Workers component (CVE-2026-92017)
* firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component (CVE-2026-92009)
* firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: WebRender component (CVE-2026-92020)
* firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component (CVE-2026-92008)
* firefox: thunderbird: Mitigation bypass in the DOM: Copy & Paste and Drag & Drop component (CVE-2026-92030)
* firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component (CVE-2026-92007)
* firefox: thunderbird: Use-after-free in the DOM: Navigation component (CVE-2026-92025)
* firefox: thunderbird: Use-after-free in the SVG component (CVE-2026-92029)
* firefox: thunderbird: Use-after-free in the XML component (CVE-2026-92023)
* thunderbird: Out-of-bounds read in IMAP response parser (CVE-2026-92240)
* thunderbird: Thunderbird: Out-of-bounds read via maliciously constructed IMAP line (CVE-2026-92239)
* thunderbird: Thunderbird: Memory safety violations via maliciously crafted mail headers (CVE-2026-92238)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.