{"id":"openSUSE-SU-2026:20391-1","summary":"Security update for MozillaThunderbird","details":"This update for MozillaThunderbird fixes the following issues:\n\nChanges in MozillaThunderbird:\n\n- Mozilla Thunderbird 140.8.1 ESR\n  * Add mail.openpgp.load_untested_gpgme_version to load untested\n    GPGME version\n\n- Mozilla Thunderbird 140.8.0 ESR\n  MFSA 2026-17 (boo#1258568)\n  * CVE-2026-2757 (bmo#2001637)\n    Incorrect boundary conditions in the WebRTC: Audio/Video\n    component\n  * CVE-2026-2758 (bmo#2009608)\n    Use-after-free in the JavaScript: GC component\n  * CVE-2026-2759 (bmo#2010933)\n    Incorrect boundary conditions in the Graphics: ImageLib\n    component\n  * CVE-2026-2760 (bmo#2011062)\n    Sandbox escape due to incorrect boundary conditions in the\n    Graphics: WebRender component\n  * CVE-2026-2761 (bmo#2011063)\n    Sandbox escape in the Graphics: WebRender component\n  * CVE-2026-2762 (bmo#2011649)\n    Integer overflow in the JavaScript: Standard Library\n    component\n  * CVE-2026-2763 (bmo#2012018)\n    Use-after-free in the JavaScript Engine component\n  * CVE-2026-2764 (bmo#2012608)\n    JIT miscompilation, use-after-free in the JavaScript Engine:\n    JIT component\n  * CVE-2026-2765 (bmo#2013562)\n    Use-after-free in the JavaScript Engine component\n  * CVE-2026-2766 (bmo#2013583)\n    Use-after-free in the JavaScript Engine: JIT component\n  * CVE-2026-2767 (bmo#2013741)\n    Use-after-free in the JavaScript: WebAssembly component\n  * CVE-2026-2768 (bmo#2014101)\n    Sandbox escape in the Storage: IndexedDB component\n  * CVE-2026-2769 (bmo#2014550)\n    Use-after-free in the Storage: IndexedDB component\n  * CVE-2026-2770 (bmo#2014585)\n    Use-after-free in the DOM: Bindings (WebIDL) component\n  * CVE-2026-2771 (bmo#2014593)\n    Undefined behavior in the DOM: Core & HTML component\n  * CVE-2026-2772 (bmo#2014827)\n    Use-after-free in the Audio/Video: Playback component\n  * CVE-2026-2773 (bmo#2014832)\n    Incorrect boundary conditions in the Web Audio component\n  * CVE-2026-2774 (bmo#2014883)\n    Integer overflow in the Audio/Video component\n  * CVE-2026-2775 (bmo#2015199)\n    Mitigation bypass in the DOM: HTML Parser component\n  * CVE-2026-2776 (bmo#2015266)\n    Sandbox escape due to incorrect boundary conditions in the\n    Telemetry component in External Software\n  * CVE-2026-2777 (bmo#2015305)\n    Privilege escalation in the Messaging System component\n  * CVE-2026-2778 (bmo#2016358)\n    Sandbox escape due to incorrect boundary conditions in the\n    DOM: Core & HTML component\n  * CVE-2026-2779 (bmo#1164141)\n    Incorrect boundary conditions in the Networking: JAR\n    component\n  * CVE-2026-2780 (bmo#2007829)\n    Privilege escalation in the Netmonitor component\n  * CVE-2026-2781 (bmo#2009552)\n    Integer overflow in the Libraries component in NSS\n  * CVE-2026-2782 (bmo#2010743)\n    Privilege escalation in the Netmonitor component\n  * CVE-2026-2783 (bmo#2010943)\n    Information disclosure due to JIT miscompilation in the\n    JavaScript Engine: JIT component\n  * CVE-2026-2784 (bmo#2012984)\n    Mitigation bypass in the DOM: Security component\n  * CVE-2026-2785 (bmo#2013549)\n    Invalid pointer in the JavaScript Engine component\n  * CVE-2026-2786 (bmo#2013612)\n    Use-after-free in the JavaScript Engine component\n  * CVE-2026-2787 (bmo#2014560)\n    Use-after-free in the DOM: Window and Location component\n  * CVE-2026-2788 (bmo#2014824)\n    Incorrect boundary conditions in the Audio/Video: GMP\n    component\n  * CVE-2026-2789 (bmo#2015179)\n    Use-after-free in the Graphics: ImageLib component\n  * CVE-2026-2790 (bmo#2008426)\n    Same-origin policy bypass in the Networking: JAR component\n  * CVE-2026-2791 (bmo#2015220)\n    Mitigation bypass in the Networking: Cache component\n  * CVE-2026-2792 (bmo#2008912, bmo#2010050, bmo#2010275,\n    bmo#2012331)\n    Memory safety bugs fixed in Firefox ESR 140.8, Thunderbird\n    ESR 140.8, Firefox 148 and Thunderbird 148\n  * CVE-2026-2793 (bmo#2015196, bmo#2016423, bmo#2016498)\n    Memory safety bugs fixed in Firefox ESR 115.33, Firefox ESR\n    140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird 148\n\n- Mozilla Thunderbird 140.7.2 ESR\n  MFSA 2026-11 (boo#1258231)\n  * CVE-2026-2447 (bmo#2014390)\n    Heap buffer overflow in libvpx\n\n- Mozilla Thunderbird 140.7.1 ESR\n  MFSA 2026-08 (bsc#1257397)\n  * CVE-2026-0818 (bmo#1881530)\n    CSS-based exfiltration of the content from partially\n    encrypted emails when allowing remote content\n\n- Support using system GnuPG with gpgme 2, boo#1253718\n\n- Mozilla Thunderbird 140.7.0 ESR\n  MFSA 2026-05 (bsc#1256340)\n  * CVE-2026-0877 (bmo#1999257)\n    Mitigation bypass in the DOM: Security component\n  * CVE-2026-0878 (bmo#2003989)\n    Sandbox escape due to incorrect boundary conditions in the\n    Graphics: CanvasWebGL component\n  * CVE-2026-0879 (bmo#2004602)\n    Sandbox escape due to incorrect boundary conditions in the\n    Graphics component\n  * CVE-2026-0880 (bmo#2005014)\n    Sandbox escape due to integer overflow in the Graphics\n    component\n  * CVE-2026-0882 (bmo#1924125)\n    Use-after-free in the IPC component\n  * CVE-2025-14327 (bmo#1970743)\n    Spoofing issue in the Downloads Panel component\n  * CVE-2026-0883 (bmo#1989340)\n    Information disclosure in the Networking component\n  * CVE-2026-0884 (bmo#2003588)\n    Use-after-free in the JavaScript Engine component\n  * CVE-2026-0885 (bmo#2003607)\n    Use-after-free in the JavaScript: GC component\n  * CVE-2026-0886 (bmo#2005658)\n    Incorrect boundary conditions in the Graphics component\n  * CVE-2026-0887 (bmo#2006500)\n    Clickjacking issue, information disclosure in the PDF Viewer\n    component\n  * CVE-2026-0890 (bmo#2005081)\n    Spoofing issue in the DOM: Copy & Paste and Drag & Drop\n    component\n  * CVE-2026-0891 (bmo#1964722, bmo#2000981, bmo#2003100,\n    bmo#2003278)\n    Memory safety bugs fixed in Firefox ESR 140.7, Thunderbird\n    ESR 140.7, Firefox 147 and Thunderbird 147\n","modified":"2026-03-26T17:24:13.827663Z","published":"2026-03-18T13:37:38Z","related":["CVE-2025-14327","CVE-2026-0818","CVE-2026-0877","CVE-2026-0878","CVE-2026-0879","CVE-2026-0880","CVE-2026-0882","CVE-2026-0883","CVE-2026-0884","CVE-2026-0885","CVE-2026-0886","CVE-2026-0887","CVE-2026-0890","CVE-2026-0891","CVE-2026-2447","CVE-2026-2757","CVE-2026-2758","CVE-2026-2759","CVE-2026-2760","CVE-2026-2761","CVE-2026-2762","CVE-2026-2763","CVE-2026-2764","CVE-2026-2765","CVE-2026-2766","CVE-2026-2767","CVE-2026-2768","CVE-2026-2769","CVE-2026-2770","CVE-2026-2771","CVE-2026-2772","CVE-2026-2773","CVE-2026-2774","CVE-2026-2775","CVE-2026-2776","CVE-2026-2777","CVE-2026-2778","CVE-2026-2779","CVE-2026-2780","CVE-2026-2781","CVE-2026-2782","CVE-2026-2783","CVE-2026-2784","CVE-2026-2785","CVE-2026-2786","CVE-2026-2787","CVE-2026-2788","CVE-2026-2789","CVE-2026-2790","CVE-2026-2791","CVE-2026-2792","CVE-2026-2793"],"upstream":["CVE-2025-14327","CVE-2026-0818","CVE-2026-0877","CVE-2026-0878","CVE-2026-0879","CVE-2026-0880","CVE-2026-0882","CVE-2026-0883","CVE-2026-0884","CVE-2026-0885","CVE-2026-0886","CVE-2026-0887","CVE-2026-0890","CVE-2026-0891","CVE-2026-2447","CVE-2026-2757","CVE-2026-2758","CVE-2026-2759","CVE-2026-2760","CVE-2026-2761","CVE-2026-2762","CVE-2026-2763","CVE-2026-2764","CVE-2026-2765","CVE-2026-2766","CVE-2026-2767","CVE-2026-2768","CVE-2026-2769","CVE-2026-2770","CVE-2026-2771","CVE-2026-2772","CVE-2026-2773","CVE-2026-2774","CVE-2026-2775","CVE-2026-2776","CVE-2026-2777","CVE-2026-2778","CVE-2026-2779","CVE-2026-2780","CVE-2026-2781","CVE-2026-2782","CVE-2026-2783","CVE-2026-2784","CVE-2026-2785","CVE-2026-2786","CVE-2026-2787","CVE-2026-2788","CVE-2026-2789","CVE-2026-2790","CVE-2026-2791","CVE-2026-2792","CVE-2026-2793"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1253718"},{"type":"REPORT","url":"https://bugzilla.suse.com/1256340"},{"type":"REPORT","url":"https://bugzilla.suse.com/1257397"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258231"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258568"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-14327"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-0818"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-0877"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-0878"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-0879"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-0880"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-0882"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-0883"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-0884"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-0885"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-0886"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-0887"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-0890"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-0891"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-2447"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-2757"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-2758"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-2759"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-2760"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-2761"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-2762"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-2763"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-2764"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-2765"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-2766"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-2767"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-2768"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-2769"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-2770"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-2771"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-2772"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-2773"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-2774"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-2775"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-2776"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-2777"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-2778"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-2779"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-2780"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-2781"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-2782"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-2783"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-2784"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-2785"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-2786"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-2787"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-2788"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-2789"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-2790"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-2791"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-2792"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-2793"}],"affected":[{"package":{"name":"MozillaThunderbird","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/MozillaThunderbird&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"140.8.1-bp160.1.1"}]}],"ecosystem_specific":{"binaries":[{"MozillaThunderbird-openpgp-librnp":"140.8.1-bp160.1.1","MozillaThunderbird-translations-common":"140.8.1-bp160.1.1","MozillaThunderbird-translations-other":"140.8.1-bp160.1.1","MozillaThunderbird":"140.8.1-bp160.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:20391-1.json"}}],"schema_version":"1.7.5"}