Security News

Cybersecurity news aggregator

🔄
HIGH Updates Red Hat Errata

RHSA-2026:30846: Important: thunderbird security update

This Red Hat security advisory addresses multiple critical vulnerabilities in Thunderbird, including a critical sandbox escape in the DOM: Workers component (CVE-2026-12294, CVSS 9.6) and several other sandbox escapes, privilege escalations, and memory safety bugs. Affected versions include Mozilla Thunderbird < 140.12.0 and Thunderbird < 152.0.0. The update requires upgrading to Thunderbird ESR 140.12.0 or Thunderbird 152.0.0 to remediate these issues.
Read Full Article →

Red Hat Product Errata RHSA-2026:30846 - Security Advisory Issued: 2026-06-29 Updated: 2026-06-29 RHSA-2026:30846 - Security Advisory Overview Updated Packages Synopsis Important: thunderbird security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for thunderbird is now available for Red Hat Enterprise Linux 10. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description Mozilla Thunderbird is a standalone mail and newsgroup client. Security Fix(es): firefox: thunderbird: Sandbox escape in the DOM: Workers component (CVE-2026-12294) firefox: thunderbird: Information disclosure, sandbox escape in the Security: Process Sandboxing component (CVE-2026-12313) firefox: thunderbird: Information disclosure, sandbox escape in the Security: Process Sandboxing component (CVE-2026-12311) firefox: thunderbird: Memory safety bug fixed in Thunderbird ESR 140.12 (CVE-2026-12290) firefox: thunderbird: Memory safety bugs fixed in Firefox ESR 140.12, Thunderbird ESR 140.12, Firefox 152 and Thunderbird 152 (CVE-2026-12327) firefox: thunderbird: JIT miscompilation in the DOM: Core & HTML component (CVE-2026-12299) firefox: thunderbird: Memory safety bug fixed in Thunderbird ESR 140.12 (CVE-2026-12329) firefox: thunderbird: Memory safety bug fixed in Thunderbird ESR 140.12 (CVE-2026-12312) firefox: thunderbird: Mitigation bypass in the DOM: Security component (CVE-2026-12302) firefox: thunderbird: Memory safety bugs fixed in Firefox ESR 115.37, Firefox ESR 140.12, Thunderbird ESR 140.12, Firefox 152 and Thunderbird 152 (CVE-2026-12328) firefox: thunderbird: Incorrect boundary conditions in the Internationalization component (CVE-2026-12330) firefox: thunderbird: Memory safety bug fixed in Thunderbird ESR 140.12 (CVE-2026-12314) firefox: thunderbird: Memory safety bug fixed in Thunderbird ESR 140.12 (CVE-2026-12309) firefox: thunderbird: Memory safety bug fixed in Thunderbird ESR 140.12 (CVE-2026-12310) firefox: thunderbird: Denial-of-service in the Graphics: ImageLib component (CVE-2026-12325) firefox: thunderbird: Sandbox escape in the DOM: Navigation component (CVE-2026-12295) firefox: thunderbird: Privilege escalation in the Graphics: WebRender component (CVE-2026-12289) firefox: thunderbird: Mitigation bypass in the DOM: Security component (CVE-2026-12315) firefox: thunderbird: Sandbox escape in the Security: Process Sandboxing component (CVE-2026-12296) firefox: thunderbird: Memory safety bug fixed in Thunderbird ESR 140.12 (CVE-2026-12306) firefox: thunderbird: Memory safety bug fixed in Thunderbird ESR 140.12 (CVE-2026-12307) firefox: thunderbird: Sandbox escape due to incorrect boundary conditions in the Networking component (CVE-2026-12297) firefox: thunderbird: Memory safety bug fixed in Thunderbird ESR 140.12 (CVE-2026-12305) firefox: thunderbird: Incorrect boundary conditions in the Web Audio component (CVE-2026-12292) firefox: thunderbird: Memory safety bug fixed in Thunderbird ESR 140.12 (CVE-2026-12308) firefox: thunderbird: Incorrect boundary conditions in the Graphics: CanvasWebGL component (CVE-2026-12324) firefox: thunderbird: Same-origin policy bypass in the Networking: Cookies component (CVE-2026-12304) firefox: thunderbird: Use-after-free in the Networking: HTTP component (CVE-2026-12291) firefox: thunderbird: Memory safety bug fixed in Firefox ESR 140.12 (CVE-2026-12298) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 10 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.2 x86_64 Red Hat Enterprise Linux for IBM z Systems 10 s390x Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.2 s390x Red Hat Enterprise Linux for Power, little endian 10 ppc64le Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.2 ppc64le Red Hat Enterprise Linux for ARM 64 10 aarch64 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.2 aarch64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 10.2 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 10.2 s390x Red Hat Enterprise Linux for Power, little endian - 4 years of support 10.2 ppc64le Red Hat Enterprise Linux for x86_64 - 4 years of updates 10.2 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 10.2 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 10.2 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 10.2 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 10.2 s390x Fixes BZ - 2489207 - CVE-2026-12294 firefox: thunderbird: Sandbox escape in the DOM: Workers component BZ - 2489208 - CVE-2026-12313 firefox: thunderbird: Information disclosure, sandbox escape in the Security: Process Sandboxing component BZ - 2489209 - CVE-2026-12311 firefox: thunderbird: Information disclosure, sandbox escape in the Security: Process Sandboxing component BZ - 2489210 - CVE-2026-12290 firefox: thunderbird: Memory safety bug fixed in Thunderbird ESR 140.12 BZ - 2489211 - CVE-2026-12327 firefox: thunderbird: Memory safety bugs fixed in Firefox ESR 140.12, Thunderbird ESR 140.12, Firefox 152 and Thunderbird 152 BZ - 2489212 - CVE-2026-12299 firefox: thunderbird: JIT miscompilation in the DOM: Core & HTML component BZ - 2489214 - CVE-2026-12329 firefox: thunderbird: Memory safety bug fixed in Thunderbird ESR 140.12 BZ - 2489215 - CVE-2026-12312 firefox: thunderbird: Memory safety bug fixed in Thunderbird ESR 140.12 BZ - 2489217 - CVE-2026-12302 firefox: thunderbird: Mitigation bypass in the DOM: Security component BZ - 2489218 - CVE-2026-12328 firefox: thunderbird: Memory safety bugs fixed in Firefox ESR 115.37, Firefox ESR 140.12, Thunderbird ESR 140.12, Firefox 152 and Thunderbird 152 BZ - 2489220 - CVE-2026-12330 firefox: thunderbird: Incorrect boundary conditions in the Internationalization component BZ - 2489221 - CVE-2026-12314 firefox: thunderbird: Memory safety bug fixed in Thunderbird ESR 140.12 BZ - 2489223 - CVE-2026-12309 firefox: thunderbird: Memory safety bug fixed in Thunderbird ESR 140.12 BZ - 2489224 - CVE-2026-12310 firefox: thunderbird: Memory safety bug fixed in Thunderbird ESR 140.12 BZ - 2489225 - CVE-2026-12325 firefox: thunderbird: Denial-of-service in the Graphics: ImageLib component BZ - 2489226 - CVE-2026-12295 firefox: thunderbird: Sandbox escape in the DOM: Navigation component BZ - 2489229 - CVE-2026-12289 firefox: thunderbird: Privilege escalation in the Graphics: WebRender component BZ - 2489231 - CVE-2026-12315 firefox: thunderbird: Mitigation bypass in the DOM: Security component BZ - 2489232 - CVE-2026-12296 firefox: thunderbird: Sandbox escape in the Security: Process Sandboxing component BZ - 2489233 - CVE-2026-12306 firefox: thunderbird: Memory safety bug fixed in Thunderbird ESR 140.12 BZ - 2489234 - CVE-2026-12307 firefox: thunderbird: Memory safety bug fixed in Thunderbird ESR 140.12 BZ - 2489235 - CVE-2026-12297 firefox: thunderbird: Sandbox escape due to incorrect boundary conditions in the Networking component BZ - 2489236 - CVE-2026-12305 firefox: thunderbird: Memory safety bug fixed in Thunderbird ESR 140.12 BZ - 2489237 - CVE-2026-12292 firefox: thunderbird: Incorrect boundary conditions in the Web Audio component BZ - 2489239 - CVE-2026-12308 firefox: thunderbird: Memory safety bug fixed in Thunderbird ESR 140.12 BZ - 2489240 - CVE-2026-12324 firefox: thunderbird: Incorrect boundary conditions in the Graphics: CanvasWebGL component BZ - 2489243 - CVE-2026-12304 firefox: thunderbird: Same-origin policy bypass in the Networking: Cookies component BZ - 2489244 - CVE-2026-12291 firefox: thunderbird: Use-after-free in the Networking: HTTP component BZ - 2489248 - CVE-2026-12298 firefox: thunderbird: Memory safety bug fixed in Firefox ESR 140.12 CVEs CVE-2026-12289 CVE-2026-12290 CVE-2026-12291 CVE-2026-12292 CVE-2026-12294 CVE-2026-12295 CVE-2026-12296 CVE-2026-12297 CVE-2026-12298 CVE-2026-12299 CVE-2026-12302 CVE-2026-12304 CVE-2026-12305 CVE-2026-12306 CVE-2026-12307 CVE-2026-12308 CVE-2026-12309 CVE-2026-12310 CVE-2026-12311 CVE-2026-12312 CVE-2026-12313 CVE-2026-12314 CVE-2026-12315 CVE-2026-12324 CVE-2026-12325 CVE-2026-12327 CVE-2026-12328 CVE-2026-12329 CVE-2026-12330 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 10 SRPM thunderbird-140.12.0-1.el10_2.src.rpm SHA-256: b41f1aaac7589610e43b45011faf0f0a8b8bc3e425968b4de2c0c71fa52e77d0 x86_64 thunderbird-140.12.0-1.el10_2.x86_64.rpm SHA-256: f471089ac76cf4315fc63e2d3bf11f85bb019e1774040dd9f9dd4ef9bfd3debf thunderbird-debuginfo-140.12.0-1.el10_2.x86_64.rpm SHA-256: 5f5112544fac4e269da916e701d8ecfcc5ecd1137cc68a41cbef4e9590bbccd1 thunderbird-debugsource-140.12.0-1.el10_2.x86_64.rpm SHA-256: 766e8a18833ed72e8fe72e1e5ae090c1a5075e87fed621c926a33358bc7b394f Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.2 SRPM thunderbird-140.12.0-1.el10_2.src.rpm SHA-256: b41f1aaac7589610e43b45011faf0f0a8b8bc3e425968b4de2c0c71fa52e77d0 x86_64 thunderbird-140.12.0-1.el10_2.x86_64.rpm SHA-256: f471089ac76cf4315fc63e2d3bf11f85bb019e1774040dd9f9dd4ef9bfd3debf thunderbird-debuginfo-140.12.0-1.el10_2.x86_64.rpm SHA-256: 5f5112544fac4e269da916e701d8ecfcc5ecd1137cc68a

Share this article