MGASA-2026-0346

Source
https://advisories.mageia.org/MGASA-2026-0346.html
Import Source
https://advisories.mageia.org/MGASA-2026-0346.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2026-0346
Upstream
  • CVE-2026-74934
  • CVE-2026-74935
  • CVE-2026-74936
  • CVE-2026-74937
  • CVE-2026-74938
  • CVE-2026-74939
  • CVE-2026-74940
  • CVE-2026-74941
  • CVE-2026-74942
  • CVE-2026-74943
  • CVE-2026-74944
  • CVE-2026-74945
  • CVE-2026-74946
  • CVE-2026-74947
  • CVE-2026-74948
  • CVE-2026-74949
  • CVE-2026-74950
  • CVE-2026-74953
  • CVE-2026-74954
  • CVE-2026-74955
  • CVE-2026-74956
  • CVE-2026-74957
  • CVE-2026-74958
  • CVE-2026-74959
  • CVE-2026-74960
  • CVE-2026-74961
  • CVE-2026-74962
  • CVE-2026-74963
  • CVE-2026-74964
  • CVE-2026-74965
  • CVE-2026-74966
  • CVE-2026-74967
  • CVE-2026-74968
  • CVE-2026-74969
  • CVE-2026-74970
  • CVE-2026-74971
  • CVE-2026-74972
  • CVE-2026-74973
  • CVE-2026-74974
  • CVE-2026-74976
  • CVE-2026-74977
  • CVE-2026-74978
  • CVE-2026-74979
  • CVE-2026-74981
  • CVE-2026-74982
  • CVE-2026-74983
  • CVE-2026-74984
  • CVE-2026-74985
  • CVE-2026-74986
  • CVE-2026-74987
  • CVE-2026-74988
  • CVE-2026-74990
Published
2026-08-31T16:22:02Z
Modified
2026-08-31T16:41:22.606714171Z
Summary
Updated thunderbird packages fix security vulnerabilities
Details

Site isolation issue in the Graphics: CanvasWebGL component. (CVE-2026-74934) Privilege escalation in the DOM: Networking component. (CVE-2026-74935) Use-after-free in the JavaScript: WebAssembly component. (CVE-2026-74936) Use-after-free in the JavaScript: GC component. (CVE-2026-74937) Mitigation bypass in the JavaScript: GC component. (CVE-2026-74938) Privilege escalation in the DOM: Navigation component. (CVE-2026-74939) Use-after-free in the Graphics: Text component. (CVE-2026-74940) Privilege escalation in the Graphics: CanvasWebGL component. (CVE-2026-74941) Privilege escalation in the Remote Settings Client component. (CVE-2026-74942) Use-after-free in the Graphics: ImageLib component. (CVE-2026-74943) Use-after-free in the DOM: Core & HTML component. (CVE-2026-74944) Information disclosure in the Graphics: Text component. (CVE-2026-74945) Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. (CVE-2026-74946) Privilege escalation due to invalid pointer in the Graphics component. (CVE-2026-74947) Information disclosure in the Graphics component. (CVE-2026-74948) Privilege escalation in the Downloads API component. (CVE-2026-74950) Privilege escalation in the Networking: Cookies component. (CVE-2026-74953) Information disclosure due to side-channel in the Storage: Cache API component. (CVE-2026-74954) Privilege escalation in the Request Handling component. (CVE-2026-74955) Same-origin policy bypass in the DOM: Service Workers component. (CVE-2026-74956) Mitigation bypass in the Safe Browsing component. (CVE-2026-74957) Information disclosure in the WebRTC component. (CVE-2026-74958) Mitigation bypass in the Storage: Cache API component. (CVE-2026-74959) Site isolation issue in the WebExtensions component. (CVE-2026-74960) Side-channel in the Web Audio component. (CVE-2026-74961) Site isolation issue in the Networking: Cookies component. (CVE-2026-74962) Same-origin policy bypass in the Networking: Cookies component. (CVE-2026-74963) Integer overflow in the Graphics component. (CVE-2026-74964) Privilege escalation in the Shell Integration component. (CVE-2026-74965) Information disclosure in the Form Autofill component. (CVE-2026-74966) Same-origin policy bypass in the Audio/Video: Playback component. (CVE-2026-74967) Site isolation issue in the Graphics: WebRender component. (CVE-2026-74968) Use-after-free in the Layout: Text and Fonts component. (CVE-2026-74969) Site isolation issue in the Graphics component. (CVE-2026-74970) Information disclosure in the DOM: UI Events & Focus Handling component. (CVE-2026-74971) Information disclosure in the DOM: Push Subscriptions component. (CVE-2026-74972) Use-after-free in the Graphics: Canvas2D component. (CVE-2026-74949) Race condition, use-after-free in the Graphics component. (CVE-2026-74973) Same-origin policy bypass in the Graphics: ImageLib component. (CVE-2026-74974) JIT miscompilation in the JavaScript Engine: JIT component. (CVE-2026-74976) Integer overflow in the Graphics component. (CVE-2026-74977) Clickjacking issue in the Widget component. (CVE-2026-74978) Mitigation bypass in the Add-ons Manager component. (CVE-2026-74979) Site isolation issue in the Audio/Video: Web Codecs component. (CVE-2026-74981) Denial-of-service in the Widget component. (CVE-2026-74982) Mitigation bypass in the Data Loss Prevention component. (CVE-2026-74983) Race condition in the JavaScript Engine component. (CVE-2026-74984) Privilege escalation in the Enterprise Policies component. (CVE-2026-74985) Site isolation issue in the CSS Parsing and Computation component. (CVE-2026-74986) Internally found bugs fixed in Thunderbird ESR 140.14, Thunderbird ESR 153.1 and Thunderbird 154. (CVE-2026-74987) Internally found bugs fixed in Thunderbird ESR 153.1 and Thunderbird 154 (CVE-2026-74988) Internally found bugs fixed in Thunderbird ESR 140.14, Thunderbird ESR 153.1 and Thunderbird 154. (CVE-2026-74990)

References
Credits

Affected packages

Mageia:10 / thunderbird

Package

Name
thunderbird
Purl
pkg:rpm/mageia/thunderbird?arch=source&distro=mageia-10

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
153.1.0-1.mga10

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2026-0346.json"

Mageia:10 / thunderbird-l10n

Package

Name
thunderbird-l10n
Purl
pkg:rpm/mageia/thunderbird-l10n?arch=source&distro=mageia-10

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
153.1.0-1.mga10

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2026-0346.json"

Mageia:9 / thunderbird

Package

Name
thunderbird
Purl
pkg:rpm/mageia/thunderbird?arch=source&distro=mageia-9

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
140.14.0-1.mga9

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2026-0346.json"

Mageia:9 / thunderbird-l10n

Package

Name
thunderbird-l10n
Purl
pkg:rpm/mageia/thunderbird-l10n?arch=source&distro=mageia-9

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
140.14.0-1.mga9

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2026-0346.json"