openSUSE-SU-2026:20664-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:20664-1.json
JSON Data
https://api.osv.dev/v1/vulns/openSUSE-SU-2026:20664-1
Upstream
  • CVE-2026-3889
  • CVE-2026-4371
  • CVE-2026-4684
  • CVE-2026-4685
  • CVE-2026-4686
  • CVE-2026-4687
  • CVE-2026-4688
  • CVE-2026-4689
  • CVE-2026-4690
  • CVE-2026-4691
  • CVE-2026-4692
  • CVE-2026-4693
  • CVE-2026-4694
  • CVE-2026-4695
  • CVE-2026-4696
  • CVE-2026-4697
  • CVE-2026-4698
  • CVE-2026-4699
  • CVE-2026-4700
  • CVE-2026-4701
  • CVE-2026-4702
  • CVE-2026-4704
  • CVE-2026-4705
  • CVE-2026-4706
  • CVE-2026-4707
  • CVE-2026-4708
  • CVE-2026-4709
  • CVE-2026-4710
  • CVE-2026-4711
  • CVE-2026-4712
  • CVE-2026-4713
  • CVE-2026-4714
  • CVE-2026-4715
  • CVE-2026-4716
  • CVE-2026-4717
  • CVE-2026-4718
  • CVE-2026-4719
  • CVE-2026-4720
  • CVE-2026-4721
  • CVE-2026-5731
  • CVE-2026-5732
  • CVE-2026-5734
  • CVE-2026-6746
  • CVE-2026-6747
  • CVE-2026-6748
  • CVE-2026-6749
  • CVE-2026-6750
  • CVE-2026-6751
  • CVE-2026-6752
  • CVE-2026-6753
  • CVE-2026-6754
  • CVE-2026-6757
  • CVE-2026-6759
  • CVE-2026-6761
  • CVE-2026-6762
  • CVE-2026-6763
  • CVE-2026-6764
  • CVE-2026-6765
  • CVE-2026-6766
  • CVE-2026-6767
  • CVE-2026-6769
  • CVE-2026-6770
  • CVE-2026-6771
  • CVE-2026-6772
  • CVE-2026-6776
  • CVE-2026-6785
  • CVE-2026-6786
Related
  • CVE-2025-59375
  • CVE-2026-3889
  • CVE-2026-4371
  • CVE-2026-4684
  • CVE-2026-4685
  • CVE-2026-4686
  • CVE-2026-4687
  • CVE-2026-4688
  • CVE-2026-4689
  • CVE-2026-4690
  • CVE-2026-4691
  • CVE-2026-4692
  • CVE-2026-4693
  • CVE-2026-4694
  • CVE-2026-4695
  • CVE-2026-4696
  • CVE-2026-4697
  • CVE-2026-4698
  • CVE-2026-4699
  • CVE-2026-4700
  • CVE-2026-4701
  • CVE-2026-4702
  • CVE-2026-4704
  • CVE-2026-4705
  • CVE-2026-4706
  • CVE-2026-4707
  • CVE-2026-4708
  • CVE-2026-4709
  • CVE-2026-4710
  • CVE-2026-4711
  • CVE-2026-4712
  • CVE-2026-4713
  • CVE-2026-4714
  • CVE-2026-4715
  • CVE-2026-4716
  • CVE-2026-4717
  • CVE-2026-4718
  • CVE-2026-4719
  • CVE-2026-4720
  • CVE-2026-4721
  • CVE-2026-5731
  • CVE-2026-5732
  • CVE-2026-5734
  • CVE-2026-6746
  • CVE-2026-6747
  • CVE-2026-6748
  • CVE-2026-6749
  • CVE-2026-6750
  • CVE-2026-6751
  • CVE-2026-6752
  • CVE-2026-6753
  • CVE-2026-6754
  • CVE-2026-6757
  • CVE-2026-6759
  • CVE-2026-6761
  • CVE-2026-6762
  • CVE-2026-6763
  • CVE-2026-6764
  • CVE-2026-6765
  • CVE-2026-6766
  • CVE-2026-6767
  • CVE-2026-6769
  • CVE-2026-6770
  • CVE-2026-6771
  • CVE-2026-6772
  • CVE-2026-6776
  • CVE-2026-6785
  • CVE-2026-6786
Published
2026-05-01T17:00:28Z
Modified
2026-05-05T07:47:10.888728Z
Summary
Security update for MozillaThunderbird
Details

This update for MozillaThunderbird fixes the following issues:

Changes in MozillaThunderbird:

  • Mozilla Thunderbird 140.10.0 ESR

    • Newly translated strings were not available in Thunderbird MFSA 2026-34 (bsc#1262230)
    • CVE-2026-6746 Use-after-free in the DOM: Core & HTML component
    • CVE-2026-6747 Use-after-free in the WebRTC component
    • CVE-2026-6748 Uninitialized memory in the Audio/Video: Web Codecs component
    • CVE-2026-6749 Information disclosure due to uninitialized memory in the Graphics: Canvas2D component
    • CVE-2026-6750 Privilege escalation in the Graphics: WebRender component
    • CVE-2026-6751 Uninitialized memory in the Audio/Video: Web Codecs component
    • CVE-2026-6752 Incorrect boundary conditions in the WebRTC component
    • CVE-2026-6753 Incorrect boundary conditions in the WebRTC component
    • CVE-2026-6754 Use-after-free in the JavaScript Engine component
    • CVE-2026-6757 Invalid pointer in the JavaScript: WebAssembly component
    • CVE-2026-6759 Use-after-free in the Widget: Cocoa component
    • CVE-2026-6761 Privilege escalation in the Networking component
    • CVE-2026-6762 Spoofing issue in the DOM: Core & HTML component
    • CVE-2026-6763 Mitigation bypass in the File Handling component
    • CVE-2026-6764 Incorrect boundary conditions in the DOM: Device Interfaces component
    • CVE-2026-6765 Information disclosure in the Form Autofill component
    • CVE-2026-6766 Incorrect boundary conditions in the Libraries component in NSS
    • CVE-2026-6767 Other issue in the Libraries component in NSS
    • CVE-2026-6769 Privilege escalation in the Debugger component
    • CVE-2026-6770 Other issue in the Storage: IndexedDB component
    • CVE-2026-6771 Mitigation bypass in the DOM: Security component
    • CVE-2026-6772 Incorrect boundary conditions in the Libraries component in NSS
    • CVE-2026-6776 Incorrect boundary conditions in the WebRTC: Networking component
    • CVE-2026-6785 Memory safety bugs fixed in Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird ESR 140.10, Firefox 150 and Thunderbird 150
    • CVE-2026-6786 Memory safety bugs fixed in Firefox ESR 140.10, Thunderbird ESR 140.10, Firefox 150 and Thunderbird 150
  • Mozilla Thunderbird 140.9.1 ESR MFSA 2026-29

    • CVE-2026-5732 Incorrect boundary conditions, integer overflow in the Graphics: Text component
    • CVE-2026-5731 Memory safety bugs fixed in Firefox ESR 115.34.1, Firefox ESR 140.9.1, Thunderbird ESR 140.9.1, Firefox 149.0.2 and Thunderbird 149.0.2
    • CVE-2026-5734 Memory safety bugs fixed in Firefox ESR 140.9.1, Thunderbird ESR 140.9.1, Firefox 149.0.2 and Thunderbird 149.0.2
  • Mozilla Thunderbird 140.9.0 ESR MFSA 2026-24 (bsc#1260083)

    • CVE-2026-3889 Spoofing issue in Thunderbird
    • CVE-2026-4371 Out of bounds read in IMAP parsing
    • CVE-2026-4684 Race condition, use-after-free in the Graphics: WebRender component
    • CVE-2026-4685 Incorrect boundary conditions in the Graphics: Canvas2D component
    • CVE-2026-4686 Incorrect boundary conditions in the Graphics: Canvas2D component
    • CVE-2026-4687 Sandbox escape due to incorrect boundary conditions in the Telemetry component
    • CVE-2026-4688 Sandbox escape due to use-after-free in the Disability Access APIs component
    • CVE-2026-4689 Sandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM component
    • CVE-2026-4690 Sandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM component
    • CVE-2026-4691 Use-after-free in the CSS Parsing and Computation component
    • CVE-2026-4692 Sandbox escape in the Responsive Design Mode component
    • CVE-2026-4693 Incorrect boundary conditions in the Audio/Video: Playback component
    • CVE-2026-4694 Incorrect boundary conditions, integer overflow in the Graphics component
    • CVE-2026-4695 Incorrect boundary conditions in the Audio/Video: Web Codecs component
    • CVE-2026-4696 Use-after-free in the Layout: Text and Fonts component
    • CVE-2026-4697 Incorrect boundary conditions in the Audio/Video: Web Codecs component
    • CVE-2026-4698 JIT miscompilation in the JavaScript Engine: JIT component
    • CVE-2026-4699 Incorrect boundary conditions in the Layout: Text and Fonts component
    • CVE-2026-4700 Mitigation bypass in the Networking: HTTP component
    • CVE-2026-4701 Use-after-free in the JavaScript Engine component
    • CVE-2026-4702 JIT miscompilation in the JavaScript Engine component
    • CVE-2026-4704 Denial-of-service in the WebRTC: Signaling component
    • CVE-2026-4705 Undefined behavior in the WebRTC: Signaling component
    • CVE-2026-4706 Incorrect boundary conditions in the Graphics: Canvas2D component
    • CVE-2026-4707 Incorrect boundary conditions in the Graphics: Canvas2D component
    • CVE-2026-4708 Incorrect boundary conditions in the Graphics component
    • CVE-2026-4709 Incorrect boundary conditions in the Audio/Video: GMP component
    • CVE-2026-4710 Incorrect boundary conditions in the Audio/Video component
    • CVE-2026-4711 Use-after-free in the Widget: Cocoa component
    • CVE-2026-4712 Information disclosure in the Widget: Cocoa component
    • CVE-2026-4713 Incorrect boundary conditions in the Graphics component
    • CVE-2026-4714 Incorrect boundary conditions in the Audio/Video component
    • CVE-2026-4715 Uninitialized memory in the Graphics: Canvas2D component
    • CVE-2026-4716 Incorrect boundary conditions, uninitialized memory in the JavaScript Engine component
    • CVE-2026-4717 Privilege escalation in the Netmonitor component
    • CVE-2025-59375 Denial-of-service in the XML component
    • CVE-2026-4718 Undefined behavior in the WebRTC: Signaling component
    • CVE-2026-4719 Incorrect boundary conditions in the Graphics: Text component
    • CVE-2026-4720 Memory safety bugs fixed in Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149
    • CVE-2026-4721 Memory safety bugs fixed in Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149
References

Affected packages