-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 03 Aug 2026 11:08:48 +0200 Source: thunderbird Architecture: source Version: 1:153.0.1esr-1 Distribution: experimental Urgency: medium Maintainer: Carsten Schoenert <[email protected]> Changed-By: Carsten Schoenert <[email protected]> Changes: thunderbird (1:153.0.1esr-1) experimental; urgency=medium . * [0adf2ac] New upstream version 153.0.1esr Fixed CVE issues in upstream version 153 (MFSA 2026-71): CVE-2026-14899: Off-by-one out of bounds read in MIME header parser for forwarding CVE-2026-16349: Same-origin policy bypass in the DOM: Navigation component CVE-2026-16350: Incorrect boundary conditions in the Audio/Video: cubeb component CVE-2026-16362: Use-after-free in the WebRTC: Audio/Video component CVE-2026-16351: Sandbox escape due to use-after-free in the DOM: Navigation component CVE-2026-16352: Sandbox escape due to use-after-free in the Disability Access APIs component CVE-2026-16363: JIT miscompilation in the JavaScript: WebAssembly component CVE-2026-16364: Incorrect boundary conditions in the Audio/Video: Playback component CVE-2026-16365: Privilege escalation in the DOM: Workers component CVE-2026-16366: Privilege escalation in the DOM: Navigation component CVE-2026-16353: Invalid pointer in the DOM: Bindings (WebIDL) component CVE-2026-16354: Information disclosure in the Graphics: ImageLib component CVE-2026-16367: Sandbox escape due to invalid pointer in the Disability Access APIs component CVE-2026-16368: Incorrect boundary conditions in the JavaScript: WebAssembly component CVE-2026-16369: Integer overflow in the JavaScript: WebAssembly component CVE-2026-16355: JIT miscompilation in the JavaScript Engine: JIT component CVE-2026-16356: Sandbox escape due to use-after-free in the Disability Access APIs component CVE-2026-16357: Incorrect boundary conditions in the Graphics component CVE-2026-16370: Mitigation bypass in the DOM: Networking component CVE-2026-16371: Privilege escalation in the DOM: Navigation component CVE-2026-16372: Privilege escalation in the DOM: Content Processes component CVE-2026-16374: Information disclosure in the Framework component in DevTools CVE-2026-16375: Site isolation issue in the Networking: HTTP component CVE-2026-16376: Denial-of-service in the Graphics: WebGPU component CVE-2026-16377: Mitigation bypass in the PDF Viewer component CVE-2026-16378: Other issue in the DOM: Copy & Paste and Drag & Drop component CVE-2026-16379: Privilege escalation in the DOM: Content Processes component CVE-2026-16358: Site isolation issue in the Graphics: WebRender component CVE-2026-16380: Mitigation bypass in the Networking component CVE-2026-16381: Same-origin policy bypass in the Networking: DNS component CVE-2026-16382: Mitigation bypass in the DOM: Service Workers component CVE-2026-16383: Mitigation bypass in the DOM: Networking component CVE-2026-16384: Information disclosure due to uninitialized memory in the Graphics: WebGPU component CVE-2026-16385: Information disclosure due to uninitialized memory in the Graphics: WebGPU component CVE-2026-16386: Information disclosure due to uninitialized memory in the Graphics: WebGPU component CVE-2026-16387: Site isolation issue in the Networking component CVE-2026-16388: Sandbox escape in the DOM: Networking component CVE-2026-16389: Incorrect boundary conditions, integer overflow in the Libraries component in NSS CVE-2026-16390: Mitigation bypass in the Enterprise Policies component CVE-2026-16391: Information disclosure in the Storage: IndexedDB component CVE-2026-16392: JIT miscompilation in the JavaScript Engine: JIT component CVE-2026-16393: Incorrect boundary conditions in the Graphics: WebGPU component CVE-2026-16359: Incorrect boundary conditions in the Audio/Video: GMP component CVE-2026-16394: Mitigation bypass in the DOM: Security component CVE-2026-16395: Integer overflow in the Audio/Video component CVE-2026-16396: Privilege escalation in WebExtensions CVE-2026-16398: Site isolation issue in the Graphics component CVE-2026-16399: Site isolation issue in the DOM: Navigation component CVE-2026-16400: Information disclosure in the DOM: Security component CVE-2026-16401: Privilege escalation in the Data Loss Prevention component CVE-2026-16402: Integer overflow in the Graphics: ImageLib component CVE-2026-16403: Spoofing issue in the Address Bar component CVE-2026-16405: Information disclosure in the Networking: WebSockets component CVE-2026-16406: Mitigation bypass in the Networking component CVE-2026-16407: Mitigation bypass in the DOM: Service Workers component CVE-2026-16408: Integer overflow in the Audio/Video: Playback component CVE-2026-16409: Invalid pointer in the Security: PSM component CVE-2026-16410: JIT miscompilation in the JavaScript Engine: JIT component CVE-2026-16411: Memory safety bugs fixed in Thunderbird 153 CVE-2026-16360: Memory safety bugs fixed in Thunderbird ESR 140.13 and Thunderbird 153 Checksums-Sha1: 4061e7986b3f653adf15cc194051f318b015327b 8485 thunderbird_153.0.1esr-1.dsc 5d8adcc197d8d27ebed8c87a49286ffdcc810d06 12808384 thunderbird_153.0.1esr.orig-thunderbird-l10n.tar.xz ca320d9aa14aeff57d3ba40c56e726541d2cb3f2 936885348 thunderbird_153.0.1esr.orig.tar.xz c20c93ef17767ddc2ac2386abcefc4977e3f5c77 538360 thunderbird_153.0.1esr-1.debian.tar.xz 432ebb5d31e57bbbeac96328e100b2c3a8d96d79 41096 thunderbird_153.0.1esr-1_amd64.buildinfo Checksums-Sha256: d0f1c87275187a3be0f77dc410dac6e3baa4bb03202f0b700ad651e750c7c0da 8485 thunderbird_153.0.1esr-1.dsc 5701af32b85239640b071bd14d5da5c56b9468cc7520669d20994c5176a48547 12808384 thunderbird_153.0.1esr.orig-thunderbird-l10n.tar.xz ce4f1ddbf1b3add184cc48e72b3767d59b89ffe41ee398aad7158f8c9ebc218a 936885348 thunderbird_153.0.1esr.orig.tar.xz 64bf8571547ea6aa3a8873c391df86fdf501bc39e45dcb0aae657e863e5af205 538360 thunderbird_153.0.1esr-1.debian.tar.xz 03486af5c99fdc9af5b0e1c93b170cbc1315c6ae70c3f3850d85f0a811596006 41096 thunderbird_153.0.1esr-1_amd64.buildinfo Files: b5808b3373a101bdcbfe63ee34674d8f 8485 mail optional thunderbird_153.0.1esr-1.dsc f5e53dca4e9e29b313793a0d479cf754 12808384 mail optional thunderbird_153.0.1esr.orig-thunderbird-l10n.tar.xz e08c769a2989d5db5065b52d85e1ac91 936885348 mail optional thunderbird_153.0.1esr.orig.tar.xz f15dee796ce6288b1f01f3f6d66d94e2 538360 mail optional thunderbird_153.0.1esr-1.debian.tar.xz afadbdbc184b755e856f98ffc6271c24 41096 mail optional thunderbird_153.0.1esr-1_amd64.buildinfo
-----BEGIN PGP SIGNATURE----- iQJMBAEBCgA2FiEEtw38bxNP7PwBHmKqgwFgFCUdHbAFAmpwrqsYHGMuc2Nob2Vu ZXJ0QHQtb25saW5lLmRlAAoJEIMBYBQlHR2wvC4P/1/RGYQU43c4w0haSdlYeEO7 KmtBRfWrub4ujR0kXaSDaaSs3171SKahwx7RswfnD+6gVuh4hAj+te6AFq/EMzt/ s5G+WrqzNTy+uZe6bPVZ8tzm0xXoiL3WFIuzhJD5K9DWci6uK62LGhf3NnueikrH 3VcEUF0xOS8ivxKQ7KivwEoU53bOO7UokhMV/JwMCH4XX8ARJITzMyLVBXiPoXks xn7KFmtMQ5IMvdmAYJI9q52QVOz9MnfoIKDPNVWNS1MW3tZoRKQLv7aDEmUNKC9+ JoQex0GZ1fSf6FAUFOrH3U89v2WP4Jk9IHGrWIMDBNFraei4ZGTUI4OtTqIiZPwQ KN+2YzsNIN7Gh6Ue3brkC8laYPM1lsl+HjtIGc6oI7dyyL7ndOxS0Cct2HpmCCUL Mi+jS/MeNUeqDTfXvfuSbO3bavcYPIHapGAD73+aqMu/zLYGYHIeb2Tw6LJ1DvIL V7RsxqJv3PAhmMFkZsPQtZFslP8zgINGC2PQEfQdCmUgRKt+qPduCGzTB++F9d0G 4nAQS2pm89/77EgVwt3Mh2T2RboGCHAWDg1acXPRRPxfatoyHsGNcPEctoRROpv+ Nytc2AnrwcmGsBhT4Tk0Uz43iw5rSORJO02ME0YJ1D12Sjl1j2c1apdmsP0Wc/mA cssw0H996+XC1Rj9kKLW =KRss -----END PGP SIGNATURE-----
pgpFrSw_vo0HG.pgp
Description: PGP signature
