[Git][security-tracker-team/security-tracker][master] Track fixed version for thunderbird issues in unstable

Salvatore Bonaccorso (@carnil) carnil at debian.org
Thu Sep 3 04:38:32 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
74a6e116 by Salvatore Bonaccorso at 2026-09-03T05:37:00+02:00
Track fixed version for thunderbird issues in unstable

Note that we switched from the 140 ESR series to the 153 ESR series with
this unstable upload. Thus mark as well CVE-2026-16365 fixed with
1:153.2.0esr-1.

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -518,13 +518,13 @@ CVE-2026-84642 (The values of the mail.allowed_attachment_hostnames advanced con
 	- thunderbird <not-affected> (Thunderbird ESR140 series not affected)
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-86/#CVE-2026-84642
 CVE-2026-84641 (A malicious IMAP server can trigger use-after-free and heap-memory dis ...)
-	- thunderbird <unfixed>
+	- thunderbird 1:153.2.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-87/#CVE-2026-84641
 CVE-2026-84640 (A maliciously constructed mail header could lead to a one byte read pa ...)
-	- thunderbird <unfixed>
+	- thunderbird 1:153.2.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-87/#CVE-2026-84640
 CVE-2026-84639 (Triggering an error condition in certain MIME bodies would cause unini ...)
-	- thunderbird <unfixed>
+	- thunderbird 1:153.2.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-87/#CVE-2026-84639
 CVE-2026-84637 (Malicious calendar invitations could use file URI attachments to launc ...)
 	- thunderbird <not-affected> (Windows-specific)
@@ -1674,7 +1674,7 @@ CVE-2023-54356 (Kyverno versions 1.9.4 and earlier support insecure 3DES cipher
 CVE-2026-84145 (Internally found bugs present in Thunderbird 154, Thunderbird ESR 153. ...)
 	- firefox 155.0-1
 	- firefox-esr 140.15.0esr-1
-	- thunderbird <unfixed>
+	- thunderbird 1:153.2.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84145
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-84/#CVE-2026-84145
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-87/#CVE-2026-84145
@@ -1684,7 +1684,7 @@ CVE-2026-84144 (Internally found bugs present in Thunderbird 154 and Thunderbird
 CVE-2026-84143 (Internally found bugs present in Thunderbird 154, Thunderbird ESR 153. ...)
 	- firefox 155.0-1
 	- firefox-esr 140.15.0esr-1
-	- thunderbird <unfixed>
+	- thunderbird 1:153.2.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84143
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-84/#CVE-2026-84143
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-87/#CVE-2026-84143
@@ -1724,7 +1724,7 @@ CVE-2026-84132 (Information disclosure in the Networking: HTTP component. This v
 CVE-2026-84131 (Privilege escalation due to invalid pointer in the Graphics component. ...)
 	- firefox 155.0-1
 	- firefox-esr 140.15.0esr-1
-	- thunderbird <unfixed>
+	- thunderbird 1:153.2.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84131
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-84/#CVE-2026-84131
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-87/#CVE-2026-84131
@@ -1749,7 +1749,7 @@ CVE-2026-84125 (Use-after-free in the DOM: Core & HTML component. This vulnerabi
 CVE-2026-84124 (Use-after-free in the DOM: Core & HTML component. This vulnerability w ...)
 	- firefox 155.0-1
 	- firefox-esr 140.15.0esr-1
-	- thunderbird <unfixed>
+	- thunderbird 1:153.2.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84124
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-84/#CVE-2026-84124
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-87/#CVE-2026-84124
@@ -1759,28 +1759,28 @@ CVE-2026-84123 (Privilege escalation due to use-after-free in the Graphics: WebG
 CVE-2026-84122 (Use-after-free in the Audio/Video component. This vulnerability was fi ...)
 	- firefox 155.0-1
 	- firefox-esr 140.15.0esr-1
-	- thunderbird <unfixed>
+	- thunderbird 1:153.2.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84122
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-84/#CVE-2026-84122
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-87/#CVE-2026-84122
 CVE-2026-84121 (Sandbox escape due to use-after-free in the DOM: Security component. T ...)
 	- firefox 155.0-1
 	- firefox-esr 140.15.0esr-1
-	- thunderbird <unfixed>
+	- thunderbird 1:153.2.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84121
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-84/#CVE-2026-84121
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-87/#CVE-2026-84121
 CVE-2026-84120 (Use-after-free in the Audio/Video component. This vulnerability was fi ...)
 	- firefox 155.0-1
 	- firefox-esr 140.15.0esr-1
-	- thunderbird <unfixed>
+	- thunderbird 1:153.2.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84120
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-84/#CVE-2026-84120
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-87/#CVE-2026-84120
 CVE-2026-84119 (Sandbox escape due to use-after-free in the DOM: Navigation component. ...)
 	- firefox 155.0-1
 	- firefox-esr 140.15.0esr-1
-	- thunderbird <unfixed>
+	- thunderbird 1:153.2.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84119
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-84/#CVE-2026-84119
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-87/#CVE-2026-84119
@@ -16516,7 +16516,7 @@ CVE-2026-75890
 CVE-2026-75874 (Sandbox escape in the Remote Settings Client component. This vulnerabi ...)
 	- firefox 154.0-1
 	- firefox-esr 140.15.0esr-1
-	- thunderbird <unfixed>
+	- thunderbird 1:153.2.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-75874
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-84/#CVE-2026-75874
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-87/#CVE-2026-75874
@@ -49561,7 +49561,7 @@ CVE-2026-16366 (Privilege escalation in the DOM: Navigation component. This vuln
 CVE-2026-16365 (Privilege escalation in the DOM: Workers component. This vulnerability ...)
 	- firefox 153.0-1
 	- firefox-esr 140.15.0esr-1
-	- thunderbird <unfixed>
+	- thunderbird 1:153.2.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16365
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-84/#CVE-2026-16365
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-87/#CVE-2026-16365



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/74a6e1165c0414c240e4f8126fb4b966b2a024e5

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/74a6e1165c0414c240e4f8126fb4b966b2a024e5
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260903/261437df/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list