Security News

Cybersecurity news aggregator

🔄
HIGH Updates Red Hat Errata

RHSA-2026:24718: Important: thunderbird security update

This Red Hat security advisory addresses four Important-severity vulnerabilities in Thunderbird, including memory safety bugs (CVE-2026-7323, CVE-2026-7322), an information disclosure via the Audio/Video component (CVE-2026-7320), and a WebRTC sandbox escape (CVE-2026-7321). The CVSS scores for the specified CVEs range from 7.3 to 7.5 (High). Affected versions are Thunderbird versions prior to 140.10.1 and 150.0.1, with the specific fixed versions varying per CVE as detailed in the NVD data.
Read Full Article →

Red Hat Product Errata RHSA-2026:24718 - Security Advisory Issued: 2026-06-09 Updated: 2026-06-09 RHSA-2026:24718 - Security Advisory Overview Updated Packages Synopsis Important: thunderbird security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for thunderbird is now available for Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support and Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description Mozilla Thunderbird is a standalone mail and newsgroup client. Security Fix(es): firefox: thunderbird: Memory safety bugs fixed in Firefox ESR 140.10.1 and Firefox 150.0.1 (CVE-2026-7323) firefox: thunderbird: Information disclosure due to incorrect boundary conditions in the Audio/Video component (CVE-2026-7320) firefox: thunderbird: Memory safety bugs fixed in Thunderbird ESR 140.10.1 and Thunderbird 150.0.1 (CVE-2026-7322) firefox: thunderbird: webrtc: Sandbox escape due to incorrect boundary conditions in the WebRTC: Networking component (CVE-2026-7321) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 - Extended Update Support Extension 8.4 x86_64 Red Hat Enterprise Linux Server - AUS 8.4 x86_64 Fixes BZ - 2463481 - CVE-2026-7323 firefox: thunderbird: Memory safety bugs fixed in Firefox ESR 140.10.1 and Firefox 150.0.1 BZ - 2463483 - CVE-2026-7320 firefox: thunderbird: Information disclosure due to incorrect boundary conditions in the Audio/Video component BZ - 2463484 - CVE-2026-7322 firefox: thunderbird: Memory safety bugs fixed in Thunderbird ESR 140.10.1 and Thunderbird 150.0.1 BZ - 2463485 - CVE-2026-7321 firefox: thunderbird: webrtc: Sandbox escape due to incorrect boundary conditions in the WebRTC: Networking component CVEs CVE-2026-7320 CVE-2026-7321 CVE-2026-7322 CVE-2026-7323 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 - Extended Update Support Extension 8.4 SRPM thunderbird-140.10.1-1.el8_4.src.rpm SHA-256: bb261361eef472233835f58ad69d379599f5c1abb90699ad0d5d716ad7f80408 x86_64 thunderbird-140.10.1-1.el8_4.x86_64.rpm SHA-256: d5c0deeaf4799a7ea359ddba1fdea5759d486f3d642e014dc51fa4032a17610f thunderbird-debuginfo-140.10.1-1.el8_4.x86_64.rpm SHA-256: 50446980f625de0e146c7fbfc79f23bbd1f0d87f2cd5adec77be8034c432afb4 thunderbird-debugsource-140.10.1-1.el8_4.x86_64.rpm SHA-256: 2e7a3fd490b3b43182bd833f784923496968555539a1d1a4905a81547e454ce5 Red Hat Enterprise Linux Server - AUS 8.4 SRPM thunderbird-140.10.1-1.el8_4.src.rpm SHA-256: bb261361eef472233835f58ad69d379599f5c1abb90699ad0d5d716ad7f80408 x86_64 thunderbird-140.10.1-1.el8_4.x86_64.rpm SHA-256: d5c0deeaf4799a7ea359ddba1fdea5759d486f3d642e014dc51fa4032a17610f thunderbird-debuginfo-140.10.1-1.el8_4.x86_64.rpm SHA-256: 50446980f625de0e146c7fbfc79f23bbd1f0d87f2cd5adec77be8034c432afb4 thunderbird-debugsource-140.10.1-1.el8_4.x86_64.rpm SHA-256: 2e7a3fd490b3b43182bd833f784923496968555539a1d1a4905a81547e454ce5 The Red Hat security contact is secalert@redhat.com . More contact details at https://access.redhat.com/security/team/contact/ .

Share this article