SUSE-SU-2026:2271-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-20262271-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2271-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2026:2271-1
Upstream
CVE (23)
  • CVE-2026-8090
  • CVE-2026-8092
  • CVE-2026-8094
  • CVE-2026-8388
  • CVE-2026-8391
  • CVE-2026-8401
  • CVE-2026-8946
  • CVE-2026-8947
  • CVE-2026-8949
  • CVE-2026-8950
  • CVE-2026-8953
  • CVE-2026-8954
  • CVE-2026-8955
  • CVE-2026-8956
  • CVE-2026-8957
  • CVE-2026-8958
  • CVE-2026-8959
  • CVE-2026-8961
  • CVE-2026-8962
  • CVE-2026-8968
  • CVE-2026-8970
  • CVE-2026-8974
  • CVE-2026-8975
Related
Published
2026-06-05T06:37:07Z
Modified
2026-06-06T07:30:23Z
Summary
Security update for MozillaThunderbird
Details

This update for MozillaThunderbird fixes the following issues

  • Updated to Mozilla Thunderbird 140.11 (bsc#1265212)

MFSA 2026-44:

  • CVE-2026-8090: Use-after-free in the DOM: Networking component.
  • CVE-2026-8092: Memory safety bugs fixed in Thunderbird ESR 140.10.2 and Thunderbird 150.0.2.
  • CVE-2026-8094: Other issue in the WebRTC component.

MFSA 2026-51:

  • CVE-2026-8388: Incorrect boundary conditions in the JavaScript Engine: JIT component.
  • CVE-2026-8391: Other issue in the JavaScript Engine component.
  • CVE-2026-8401: Sandbox escape in the Profile Backup component.
  • CVE-2026-8946: Incorrect boundary conditions in the Audio/Video: Web Codecs component.
  • CVE-2026-8947: Use-after-free in the DOM: Bindings (WebIDL) component.
  • CVE-2026-8949: Integer overflow in the Widget: Win32 component.
  • CVE-2026-8950: Same-origin policy bypass in the Networking: HTTP component.
  • CVE-2026-8953: Sandbox escape due to use-after-free in the Disability Access APIs component.
  • CVE-2026-8954: Incorrect boundary conditions, integer overflow in the Audio/Video component.
  • CVE-2026-8955: Privilege escalation in the DOM: Workers component.
  • CVE-2026-8956: Integer overflow in the Networking: JAR component.
  • CVE-2026-8957: Privilege escalation in the Enterprise Policies component.
  • CVE-2026-8958: Information disclosure, sandbox escape in the Security: Process Sandboxing component.
  • CVE-2026-8959: Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component.
  • CVE-2026-8961: Spoofing issue in the Form Autofill component.
  • CVE-2026-8962: Mitigation bypass in the DOM: Security component.
  • CVE-2026-8968: Denial-of-service due to invalid pointer in the Audio/Video: Web Codecs component.
  • CVE-2026-8970: Privilege escalation in the Security component.
  • CVE-2026-8974: Memory safety bugs fixed in Thunderbird 140.11 and Thunderbird 151.
  • CVE-2026-8975: Memory safety bugs fixed in Thunderbird 140.11 and Thunderbird 151.
References

Affected packages