-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Wed, 19 Aug 2026 19:55:34 +0200
Source: thunderbird
Architecture: source
Version: 1:153.1.0esr-1
Distribution: experimental
Urgency: medium
Maintainer: Carsten Schoenert <[email protected]>
Changed-By: Carsten Schoenert <[email protected]>
Changes:
 thunderbird (1:153.1.0esr-1) experimental; urgency=medium
 .
   * [91f5ed9] New upstream version 153.1.0esr
     Fixed CVE issues in upstream version 153.1 (MFSA 2026-80):
     CVE-2026-74934: Site isolation issue in the Graphics: CanvasWebGL
                     component
     CVE-2026-74935: Privilege escalation in the DOM: Networking component
     CVE-2026-74936: Use-after-free in the JavaScript: WebAssembly component
     CVE-2026-74937: Use-after-free in the JavaScript: GC component
     CVE-2026-74938: Mitigation bypass in the JavaScript: GC component
     CVE-2026-74939: Privilege escalation in the DOM: Navigation component
     CVE-2026-74940: Use-after-free in the Graphics: Text component
     CVE-2026-74941: Privilege escalation in the Graphics: CanvasWebGL
                     component
     CVE-2026-74942: Privilege escalation in the Remote Settings Client
                     component
     CVE-2026-74943: Use-after-free in the Graphics: ImageLib component
     CVE-2026-74944: Use-after-free in the DOM: Core &amp; HTML component
     CVE-2026-74945: Information disclosure in the Graphics: Text component
     CVE-2026-74946: Privilege escalation due to incorrect boundary
                     conditions in the Graphics: CanvasWebGL component
     CVE-2026-74947: Privilege escalation due to invalid pointer in the
                     Graphics component
     CVE-2026-74948: Information disclosure in the Graphics component
     CVE-2026-74949: Privilege escalation due to use-after-free in the
                     Graphics: Canvas2D component
     CVE-2026-74950: Privilege escalation in the Downloads API component
     CVE-2026-74953: Privilege escalation in the Networking: Cookies component
     CVE-2026-74954: Information disclosure due to side-channel in the Storage:
                     Cache API component
     CVE-2026-74955: Privilege escalation in the Request Handling component
     CVE-2026-74956: Same-origin policy bypass in the DOM: Service Workers
                     component
     CVE-2026-74957: Mitigation bypass in the Safe Browsing component
     CVE-2026-74958: Information disclosure in the WebRTC component
     CVE-2026-74959: Mitigation bypass in the Storage: Cache API component
     CVE-2026-74960: Site isolation issue in the WebExtensions component
     CVE-2026-74961: Side-channel in the Web Audio component
     CVE-2026-74962: Site isolation issue in the Networking: Cookies component
     CVE-2026-74963: Same-origin policy bypass in the Networking: Cookies
                     component
     CVE-2026-74964: Integer overflow in the Graphics component
     CVE-2026-74965: Privilege escalation in the Shell Integration component
     CVE-2026-74966: Information disclosure in the Form Autofill component
     CVE-2026-74967: Same-origin policy bypass in the Audio/Video: Playback
                     component
     CVE-2026-74968: Site isolation issue in the Graphics: WebRender component
     CVE-2026-74969: Use-after-free in the Layout: Text and Fonts component
     CVE-2026-74970: Site isolation issue in the Graphics component
     CVE-2026-74971: Information disclosure in the DOM: UI Events &amp; Focus
                     Handling component
     CVE-2026-74972: Information disclosure in the DOM: Push Subscriptions
                     component
     CVE-2026-74973: Race condition, use-after-free in the Graphics component
     CVE-2026-74974: Same-origin policy bypass in the Graphics: ImageLib
                     component
     CVE-2026-74976: JIT miscompilation in the JavaScript Engine: JIT component
     CVE-2026-74977: Integer overflow in the Graphics component
     CVE-2026-74978: Clickjacking issue in the Widget component
     CVE-2026-74979: Mitigation bypass in the Add-ons Manager component
     CVE-2026-74981: Site isolation issue in the Audio/Video: Web Codecs
                     component
     CVE-2026-74982: Denial-of-service in the Widget component
     CVE-2026-74983: Mitigation bypass in the Data Loss Prevention component
     CVE-2026-74984: Race condition in the JavaScript Engine component
     CVE-2026-74985: Privilege escalation in the Enterprise Policies component
     CVE-2026-74986: Site isolation issue in the CSS Parsing and Computation
                     component
     CVE-2026-74987: Internally found bugs fixed in Thunderbird ESR 140.14,
                     Thunderbird ESR 153.1 and Thunderbird 154
     CVE-2026-74988: Internally found bugs fixed in Thunderbird ESR 153.1
                     and Thunderbird 154
     CVE-2026-74990: Internally found bugs fixed in Thunderbird ESR 140.14,
                     Thunderbird ESR 153.1 and Thunderbird 154
   * [792af83] Rebuild patch queue from patch-queue branch
     Removed patches:
     porting-armel/Avoid-using-vmrs-vmsr-on-armel.patch
     porting/Disable-optimization-on-alpha-for-the-url-classifier.patch
     We don't build packages for armel and alpha any more for some time, time
     to drop the patches now too.
Checksums-Sha1:
 3eab7d81cd1424719ea088ddb8fd20a972b6cefd 8452 thunderbird_153.1.0esr-1.dsc
 384db38566b9397f92123bbaccb75c569ac8631c 12805028 
thunderbird_153.1.0esr.orig-thunderbird-l10n.tar.xz
 90c825d337f7c04ff7f27b81616f3d73404d477c 904462536 
thunderbird_153.1.0esr.orig.tar.xz
 fdce232440db36222a01ac868f400611de1cab44 538668 
thunderbird_153.1.0esr-1.debian.tar.xz
 b2f4db6406d92823f115a57b6e263c10447486c4 41149 
thunderbird_153.1.0esr-1_amd64.buildinfo
Checksums-Sha256:
 4852804420a94ae0fcc80ebab1972fcd5f82285a86e3e3cdddad1c63f97224dd 8452 
thunderbird_153.1.0esr-1.dsc
 0cfc9677417cbaa8d97874e644a6cf93e813de3ab64480fe1995d11ecbd70464 12805028 
thunderbird_153.1.0esr.orig-thunderbird-l10n.tar.xz
 167f032f51858b1ff1076245175813983d4b3ee3bd77514d11a201a730da0485 904462536 
thunderbird_153.1.0esr.orig.tar.xz
 0390c5a3b1fd2a1947814f919487d50c2f5dc0e179e980f281828a7d930bad14 538668 
thunderbird_153.1.0esr-1.debian.tar.xz
 d5f065fdc2fa67adf5d01e2367b6b277ee700516f3b91b43b02c1fa73d8a1541 41149 
thunderbird_153.1.0esr-1_amd64.buildinfo
Files:
 58fd33f5ed541ea78887a6777144e5da 8452 mail optional 
thunderbird_153.1.0esr-1.dsc
 367b1cfaad6e6df6802727d43f15dd5d 12805028 mail optional 
thunderbird_153.1.0esr.orig-thunderbird-l10n.tar.xz
 c3ff262578844189608ff267da9b1700 904462536 mail optional 
thunderbird_153.1.0esr.orig.tar.xz
 358fe9c3fc0e2171421462b8fd7e4dd6 538668 mail optional 
thunderbird_153.1.0esr-1.debian.tar.xz
 34dfdb904e2385745af642b5b331b759 41149 mail optional 
thunderbird_153.1.0esr-1_amd64.buildinfo

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEtw38bxNP7PwBHmKqgwFgFCUdHbAFAmqGATAACgkQgwFgFCUd
HbAhdQ//SK/kdW2ZzGTFiDWDPs7m88rZjpQP+7OOSJ5+gQCFmMpv+PbE5CYAqWR+
zJK8qIxSFfHQHwA6zfYJ/8eUP7FNXtOgaKmyeKxhpb/jdGpb9++zywSMxRl4UNUu
URmmAwBS62zCxVtlCbXFSGxS2MmGj0l/4TdiINGE1eO1J+KzxHYrQR7iZqo+mQz3
w1eshQ1t+ytCKybrnMA0ksnAYf6IVdQoR9LUlkK5krpsv7Zn8Z75FkqR9DEGeF0D
2d9/Tg48xc6MXMxtx/kSzNXXOM1nTi9d867gmiwxHiqA4nKmfEK6l0pd4N7f1Qlm
sf9A6Q0B0wFBQgM/1K36J2SN6n8WAHWyEkbrOyXDW7xwGGhVDSYHTxzAHlnlNVA9
e4agNVdxo6tA2JjgOVlqcwctaZOgAdBx/BvngoWlvTmvSSe3D8bvBYcygsLICbqO
/jIEjgGhaKWVI6UDO0+ZB90lSyBTIpUZqar4R0gDXJgEKDix85+t/nAcitFozTqu
3Td+DRYVXdfYZb9F4Ful+BErH0GSljFbCoDOI04JmbLP9G921bTApzzeSp0GwFZl
f0SNey4GJwm4VRE3bDTvkhoMyppeai7pmMtolVeiZjoMMTkDUdX5AcOG63lBSPym
ftlINzwc+mCk+VAdB3EKz2UhnkOq4JoxCnUcCzoVUIiSgkos/QY=
=4B6d
-----END PGP SIGNATURE-----

Attachment: pgpSe_7dMcJox.pgp
Description: PGP signature

Reply via email to