[Git][security-tracker-team/security-tracker][master] thunderbird fixed in sid

Moritz Muehlenhoff (@jmm) jmm at debian.org
Thu Sep 17 16:47:02 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
24c334dc by Moritz Muehlenhoff at 2026-09-17T17:46:30+02:00
thunderbird fixed in sid

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -2839,13 +2839,13 @@ CVE-2024-11222 (GitLab has remediated an issue in GitLab CE/EE affecting all ver
 	NOT-FOR-US: GitLab (used to be packaged in the Debian archive as src:gitlab, but never in a stable release)
 CVE-2026-92238 (A maliciously constructed mail header could lead to multiple fields be ...)
 	{DSA-6503-1}
-	- thunderbird <unfixed>
+	- thunderbird 1:153.3.0esr-1
 CVE-2026-92239 (A maliciously constructed IMAP line could cause an out-of-bounds buffe ...)
 	{DSA-6503-1}
-	- thunderbird <unfixed>
+	- thunderbird 1:153.3.0esr-1
 CVE-2026-92240 (A malicious or compromised IMAP server can trigger an out-of-bounds re ...)
 	{DSA-6503-1}
-	- thunderbird <unfixed>
+	- thunderbird 1:153.3.0esr-1
 CVE-2026-91841 [Incomplete fix of CVE-2018-10900]
 	- network-manager-vpnc <unfixed> (bug #1148113)
 	NOTE: https://gitlab.gnome.org/Archive/NetworkManager-vpnc/-/work_items/20
@@ -4038,12 +4038,12 @@ CVE-2026-92082 (By default, Payara Server does not limit the number of failed lo
 CVE-2026-92021 (Use-after-free in the JavaScript Engine: JIT component. This vulnerabi ...)
 	{DSA-6503-1 DSA-6501-1}
 	- firefox-esr 140.16.0esr-1
-	- thunderbird <unfixed>
+	- thunderbird 1:153.3.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/#CVE-2026-92021
 CVE-2026-92014 (Privilege escalation due to incorrect boundary conditions in the Graph ...)
 	{DSA-6503-1 DSA-6501-1}
 	- firefox-esr 140.16.0esr-1
-	- thunderbird <unfixed>
+	- thunderbird 1:153.3.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/#CVE-2026-92014
 CVE-2026-92003 (Affected versions of MISP do not consistently apply the existing authe ...)
 	- misp <itp> (bug #1144317)
@@ -5043,14 +5043,14 @@ CVE-2026-92032 (Sandbox escape due to invalid pointer in the Graphics component.
 	{DSA-6503-1 DSA-6501-1}
 	- firefox 156.0-1
 	- firefox-esr 140.16.0esr-1
-	- thunderbird <unfixed>
+	- thunderbird 1:153.3.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92032
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/#CVE-2026-92032
 CVE-2026-92031 (Information disclosure in the Graphics: ImageLib component. This vulne ...)
 	{DSA-6503-1 DSA-6501-1}
 	- firefox 156.0-1
 	- firefox-esr 140.16.0esr-1
-	- thunderbird <unfixed>
+	- thunderbird 1:153.3.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92031
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/#CVE-2026-92031
 CVE-2026-92057 (Mitigation bypass in the Enterprise Policies component. This vulnerabi ...)
@@ -5093,7 +5093,7 @@ CVE-2026-92030 (Mitigation bypass in the DOM: Copy & Paste and Drag & Drop compo
 	{DSA-6503-1 DSA-6501-1}
 	- firefox 156.0-1
 	- firefox-esr 140.16.0esr-1
-	- thunderbird <unfixed>
+	- thunderbird 1:153.3.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92030
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/#CVE-2026-92030
 CVE-2026-92045 (Sandbox escape due to incorrect boundary conditions in the WebRTC comp ...)
@@ -5127,21 +5127,21 @@ CVE-2026-92029 (Use-after-free in the SVG component. This vulnerability was fixe
 	{DSA-6503-1 DSA-6501-1}
 	- firefox 156.0-1
 	- firefox-esr 140.16.0esr-1
-	- thunderbird <unfixed>
+	- thunderbird 1:153.3.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92029
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/#CVE-2026-92029
 CVE-2026-92028 (Use-after-free in the DOM: Core & HTML component. This vulnerability w ...)
 	{DSA-6503-1 DSA-6501-1}
 	- firefox 156.0-1
 	- firefox-esr 140.16.0esr-1
-	- thunderbird <unfixed>
+	- thunderbird 1:153.3.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92028
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/#CVE-2026-92028
 CVE-2026-92027 (Use-after-free in the DOM: Streams component. This vulnerability was f ...)
 	{DSA-6503-1 DSA-6501-1}
 	- firefox 156.0-1
 	- firefox-esr 140.16.0esr-1
-	- thunderbird <unfixed>
+	- thunderbird 1:153.3.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92027
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/#CVE-2026-92027
 CVE-2026-92036 (Incorrect boundary conditions in the Networking: HTTP component. This  ...)
@@ -5151,70 +5151,70 @@ CVE-2026-92026 (Use-after-free in the Networking component. This vulnerability w
 	{DSA-6503-1 DSA-6501-1}
 	- firefox 156.0-1
 	- firefox-esr 140.16.0esr-1
-	- thunderbird <unfixed>
+	- thunderbird 1:153.3.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92026
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/#CVE-2026-92026
 CVE-2026-92025 (Use-after-free in the DOM: Navigation component. This vulnerability wa ...)
 	{DSA-6503-1 DSA-6501-1}
 	- firefox 156.0-1
 	- firefox-esr 140.16.0esr-1
-	- thunderbird <unfixed>
+	- thunderbird 1:153.3.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92025
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/#CVE-2026-92025
 CVE-2026-92024 (Use-after-free in the SVG component. This vulnerability was fixed in F ...)
 	{DSA-6503-1 DSA-6501-1}
 	- firefox 156.0-1
 	- firefox-esr 140.16.0esr-1
-	- thunderbird <unfixed>
+	- thunderbird 1:153.3.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92024
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/#CVE-2026-92024
 CVE-2026-92023 (Use-after-free in the XML component. This vulnerability was fixed in F ...)
 	{DSA-6503-1 DSA-6501-1}
 	- firefox 156.0-1
 	- firefox-esr 140.16.0esr-1
-	- thunderbird <unfixed>
+	- thunderbird 1:153.3.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92023
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/#CVE-2026-92023
 CVE-2026-92022 (Use-after-free in the DOM: HTML Parser component. This vulnerability w ...)
 	{DSA-6503-1 DSA-6501-1}
 	- firefox 156.0-1
 	- firefox-esr 140.16.0esr-1
-	- thunderbird <unfixed>
+	- thunderbird 1:153.3.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92022
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/#CVE-2026-92022
 CVE-2026-92020 (Privilege escalation due to incorrect boundary conditions in the Graph ...)
 	{DSA-6503-1 DSA-6501-1}
 	- firefox 156.0-1
 	- firefox-esr 140.16.0esr-1
-	- thunderbird <unfixed>
+	- thunderbird 1:153.3.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92020
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/#CVE-2026-92020
 CVE-2026-92019 (Mitigation bypass in the Remote Settings Client component. This vulner ...)
 	{DSA-6503-1 DSA-6501-1}
 	- firefox 156.0-1
 	- firefox-esr 140.16.0esr-1
-	- thunderbird <unfixed>
+	- thunderbird 1:153.3.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92019
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/#CVE-2026-92019
 CVE-2026-92018 (Sandbox escape in the DOM: Core & HTML component. This vulnerability w ...)
 	{DSA-6503-1 DSA-6501-1}
 	- firefox 156.0-1
 	- firefox-esr 140.16.0esr-1
-	- thunderbird <unfixed>
+	- thunderbird 1:153.3.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92018
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/#CVE-2026-92018
 CVE-2026-92017 (Privilege escalation in the DOM: Service Workers component. This vulne ...)
 	{DSA-6503-1 DSA-6501-1}
 	- firefox 156.0-1
 	- firefox-esr 140.16.0esr-1
-	- thunderbird <unfixed>
+	- thunderbird 1:153.3.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92017
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/#CVE-2026-92017
 CVE-2026-92016 (Use-after-free in the Disability Access APIs component. This vulnerabi ...)
 	{DSA-6503-1 DSA-6501-1}
 	- firefox 156.0-1
 	- firefox-esr 140.16.0esr-1
-	- thunderbird <unfixed>
+	- thunderbird 1:153.3.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92016
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/#CVE-2026-92016
 CVE-2026-92035 (Sandbox escape due to incorrect boundary conditions in the Graphics co ...)
@@ -5227,70 +5227,70 @@ CVE-2026-92015 (Privilege escalation in the WebExtensions component. This vulner
 	{DSA-6503-1 DSA-6501-1}
 	- firefox 156.0-1
 	- firefox-esr 140.16.0esr-1
-	- thunderbird <unfixed>
+	- thunderbird 1:153.3.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92015
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/#CVE-2026-92015
 CVE-2026-92013 (Privilege escalation due to incorrect boundary conditions in the Graph ...)
 	{DSA-6503-1 DSA-6501-1}
 	- firefox 156.0-1
 	- firefox-esr 140.16.0esr-1
-	- thunderbird <unfixed>
+	- thunderbird 1:153.3.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92013
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/#CVE-2026-92013
 CVE-2026-92012 (Privilege escalation due to incorrect boundary conditions in the Graph ...)
 	{DSA-6503-1 DSA-6501-1}
 	- firefox 156.0-1
 	- firefox-esr 140.16.0esr-1
-	- thunderbird <unfixed>
+	- thunderbird 1:153.3.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92012
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/#CVE-2026-92012
 CVE-2026-92011 (Privilege escalation due to incorrect boundary conditions in the Graph ...)
 	{DSA-6503-1 DSA-6501-1}
 	- firefox 156.0-1
 	- firefox-esr 140.16.0esr-1
-	- thunderbird <unfixed>
+	- thunderbird 1:153.3.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92011
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/#CVE-2026-92011
 CVE-2026-92010 (Privilege escalation due to incorrect boundary conditions in the Graph ...)
 	{DSA-6503-1 DSA-6501-1}
 	- firefox 156.0-1
 	- firefox-esr 140.16.0esr-1
-	- thunderbird <unfixed>
+	- thunderbird 1:153.3.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92010
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/#CVE-2026-92010
 CVE-2026-92009 (Privilege escalation due to incorrect boundary conditions in the Graph ...)
 	{DSA-6503-1 DSA-6501-1}
 	- firefox 156.0-1
 	- firefox-esr 140.16.0esr-1
-	- thunderbird <unfixed>
+	- thunderbird 1:153.3.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92009
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/#CVE-2026-92009
 CVE-2026-92008 (Privilege escalation due to incorrect boundary conditions in the Graph ...)
 	{DSA-6503-1 DSA-6501-1}
 	- firefox 156.0-1
 	- firefox-esr 140.16.0esr-1
-	- thunderbird <unfixed>
+	- thunderbird 1:153.3.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92008
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/#CVE-2026-92008
 CVE-2026-92007 (Privilege escalation due to incorrect boundary conditions in the Graph ...)
 	{DSA-6503-1 DSA-6501-1}
 	- firefox 156.0-1
 	- firefox-esr 140.16.0esr-1
-	- thunderbird <unfixed>
+	- thunderbird 1:153.3.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92007
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/#CVE-2026-92007
 CVE-2026-92006 (Privilege escalation due to incorrect boundary conditions in the Graph ...)
 	{DSA-6503-1 DSA-6501-1}
 	- firefox 156.0-1
 	- firefox-esr 140.16.0esr-1
-	- thunderbird <unfixed>
+	- thunderbird 1:153.3.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92006
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/#CVE-2026-92006
 CVE-2026-92005 (Use-after-free in the Audio/Video: Web Codecs component. This vulnerab ...)
 	{DSA-6503-1 DSA-6501-1}
 	- firefox 156.0-1
 	- firefox-esr 140.16.0esr-1
-	- thunderbird <unfixed>
+	- thunderbird 1:153.3.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92005
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/#CVE-2026-92005
 CVE-2026-92033 (Privilege escalation in Firefox for Android. This vulnerability was fi ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/24c334dc3731992934767416397a291f4e17e4b1

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/24c334dc3731992934767416397a291f4e17e4b1
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260917/d5a19c98/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list