SUSE-SU-2026:3897-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-20263897-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3897-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2026:3897-1
Upstream
  • CVE-2026-74934
  • CVE-2026-74935
  • CVE-2026-74936
  • CVE-2026-74939
  • CVE-2026-74940
  • CVE-2026-74941
  • CVE-2026-74942
  • CVE-2026-74943
  • CVE-2026-74944
  • CVE-2026-74945
  • CVE-2026-74946
  • CVE-2026-74948
  • CVE-2026-74949
  • CVE-2026-74953
  • CVE-2026-74957
  • CVE-2026-74959
  • CVE-2026-74960
  • CVE-2026-74962
  • CVE-2026-74963
  • CVE-2026-74964
  • CVE-2026-74965
  • CVE-2026-74967
  • CVE-2026-74969
  • CVE-2026-74971
  • CVE-2026-74972
  • CVE-2026-74973
  • CVE-2026-74974
  • CVE-2026-74976
  • CVE-2026-74983
  • CVE-2026-74987
  • CVE-2026-74990
Related
  • CVE-2026-74934
  • CVE-2026-74935
  • CVE-2026-74936
  • CVE-2026-74939
  • CVE-2026-74940
  • CVE-2026-74941
  • CVE-2026-74942
  • CVE-2026-74943
  • CVE-2026-74944
  • CVE-2026-74945
  • CVE-2026-74946
  • CVE-2026-74948
  • CVE-2026-74949
  • CVE-2026-74953
  • CVE-2026-74957
  • CVE-2026-74959
  • CVE-2026-74960
  • CVE-2026-74962
  • CVE-2026-74963
  • CVE-2026-74964
  • CVE-2026-74965
  • CVE-2026-74967
  • CVE-2026-74969
  • CVE-2026-74971
  • CVE-2026-74972
  • CVE-2026-74973
  • CVE-2026-74974
  • CVE-2026-74976
  • CVE-2026-74983
  • CVE-2026-74987
  • CVE-2026-74990
Published
2026-08-31T15:01:13Z
Modified
2026-09-10T18:23:20Z
Summary
Security update for MozillaThunderbird
Details

This update for MozillaThunderbird fixes the following issue:

Update to Mozilla Thunderbird 140.14.

  • MFSA 2026-79 (bsc#1274867)
    • CVE-2026-74934: Site isolation issue in the Graphics: CanvasWebGL component
    • CVE-2026-74935: Privilege escalation in the DOM: Networking component
    • CVE-2026-74936: Use-after-free in the JavaScript: WebAssembly component
    • CVE-2026-74939: Privilege escalation in the DOM: Navigation component
    • CVE-2026-74940: Use-after-free in the Graphics: Text component
    • CVE-2026-74941: Privilege escalation in the Graphics: CanvasWebGL component
    • CVE-2026-74942: Privilege escalation in the Remote Settings Client component
    • CVE-2026-74943: Use-after-free in the Graphics: ImageLib component
    • CVE-2026-74944: Use-after-free in the DOM: Core & HTML component
    • CVE-2026-74945: Information disclosure in the Graphics: Text component
    • CVE-2026-74946: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component
    • CVE-2026-74948: Information disclosure in the Graphics component
    • CVE-2026-74949: Privilege escalation due to use-after-free in the Graphics: Canvas2D component
    • CVE-2026-74953: Privilege escalation in the Networking: Cookies component
    • CVE-2026-74957: Mitigation bypass in the Safe Browsing component
    • CVE-2026-74959: Mitigation bypass in the Storage: Cache API component
    • CVE-2026-74960: Site isolation issue in the WebExtensions component
    • CVE-2026-74962: Site isolation issue in the Networking: Cookies component
    • CVE-2026-74963: Same-origin policy bypass in the Networking: Cookies component
    • CVE-2026-74964: Integer overflow in the Graphics component
    • CVE-2026-74965: Privilege escalation in the Shell Integration component
    • CVE-2026-74967: Same-origin policy bypass in the Audio/Video: Playback component
    • CVE-2026-74969: Use-after-free in the Layout: Text and Fonts component
    • CVE-2026-74971: Information disclosure in the DOM: UI Events & Focus Handling component
    • CVE-2026-74972: Information disclosure in the DOM: Push Subscriptions component
    • CVE-2026-74973: Race condition, use-after-free in the Graphics component
    • CVE-2026-74974: Same-origin policy bypass in the Graphics: ImageLib component
    • CVE-2026-74976: JIT miscompilation in the JavaScript Engine: JIT component
    • CVE-2026-74983: Mitigation bypass in the Data Loss Prevention component
    • CVE-2026-74987: Internally found bugs fixed in Thunderbird ESR 140.14, Thunderbird ESR 153.1 and Thunderbird 154
    • CVE-2026-74990: Internally found bugs fixed in Thunderbird ESR 140.14, Thunderbird ESR 153.1 and Thunderbird 154
References

Affected packages

SUSE:Linux Enterprise Module for Package Hub 15 SP7
MozillaThunderbird

Package

Name
MozillaThunderbird
Purl
pkg:rpm/suse/MozillaThunderbird&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
140.14.0-150200.8.283.1

Ecosystem specific

{
    "binaries": [
        {
            "MozillaThunderbird": "140.14.0-150200.8.283.1",
            "MozillaThunderbird-translations-common": "140.14.0-150200.8.283.1",
            "MozillaThunderbird-translations-other": "140.14.0-150200.8.283.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3897-1.json"
SUSE:Linux Enterprise Workstation Extension 15 SP7
MozillaThunderbird

Package

Name
MozillaThunderbird
Purl
pkg:rpm/suse/MozillaThunderbird&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2015%20SP7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
140.14.0-150200.8.283.1

Ecosystem specific

{
    "binaries": [
        {
            "MozillaThunderbird": "140.14.0-150200.8.283.1",
            "MozillaThunderbird-translations-common": "140.14.0-150200.8.283.1",
            "MozillaThunderbird-translations-other": "140.14.0-150200.8.283.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3897-1.json"