Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2025:8324 - Security Advisory
Issued:
2025-05-29
Updated:
2025-05-29

RHSA-2025:8324 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: thunderbird security update

Type/Severity

Security Advisory: Important

Red Hat Insights patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for thunderbird is now available for Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Mozilla Thunderbird is a standalone mail and newsgroup client.

Security Fix(es):

  • thunderbird: JavaScript Execution via Spoofed PDF Attachment and file:/// Link (CVE-2025-3909)
  • thunderbird: Sender Spoofing via Malformed From Header in Thunderbird (CVE-2025-3875)
  • thunderbird: Unsolicited File Download, Disk Space Exhaustion, and Credential Leakage via mailbox:/// Links (CVE-2025-3877)
  • thunderbird: Tracking Links in Attachments Bypassed Remote Content Blocking (CVE-2025-3932)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.0 ppc64le
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.0 x86_64
  • Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.0 aarch64
  • Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.0 s390x

Fixes

  • BZ - 2366283 - CVE-2025-3909 thunderbird: JavaScript Execution via Spoofed PDF Attachment and file:/// Link
  • BZ - 2366287 - CVE-2025-3875 thunderbird: Sender Spoofing via Malformed From Header in Thunderbird
  • BZ - 2366291 - CVE-2025-3877 thunderbird: Unsolicited File Download, Disk Space Exhaustion, and Credential Leakage via mailbox:/// Links
  • BZ - 2366297 - CVE-2025-3932 thunderbird: Tracking Links in Attachments Bypassed Remote Content Blocking

CVEs

  • CVE-2025-3875
  • CVE-2025-3877
  • CVE-2025-3909
  • CVE-2025-3932

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.0

SRPM
thunderbird-128.10.1-1.el9_0.src.rpm SHA-256: 9e2740cabf69d7518b17c18817714d6af9d1e7d9d5eb520efe6ecb463ad4435b
ppc64le
thunderbird-128.10.1-1.el9_0.ppc64le.rpm SHA-256: 744f26e7fd8bb454f4077c7be6532c37cb417c6d0ebe87df4ffda30a1a095751
thunderbird-debuginfo-128.10.1-1.el9_0.ppc64le.rpm SHA-256: f1256e2c28babdab32316b6c73e2dedc8a0739611a1d81bf8f14e8fedac91cb8
thunderbird-debugsource-128.10.1-1.el9_0.ppc64le.rpm SHA-256: b81c72fe899dc169a6b48a0013aad3f4fcea013a1c15481a0a0dc6b32931c2b6

Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.0

SRPM
thunderbird-128.10.1-1.el9_0.src.rpm SHA-256: 9e2740cabf69d7518b17c18817714d6af9d1e7d9d5eb520efe6ecb463ad4435b
x86_64
thunderbird-128.10.1-1.el9_0.x86_64.rpm SHA-256: b367a1073916e796e011c03f5e2d76345b1683e3aae3740b9d0b02d48fbb5d56
thunderbird-debuginfo-128.10.1-1.el9_0.x86_64.rpm SHA-256: 0136a242542a1cfae3430e5c2780fcd78aeae7104caf5fb2a7086d201424242e
thunderbird-debugsource-128.10.1-1.el9_0.x86_64.rpm SHA-256: a3169dc2ff3c0e563071cd8749b7fa8322bc12d0b1a71fa4d917d1ef568c80f1

Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.0

SRPM
thunderbird-128.10.1-1.el9_0.src.rpm SHA-256: 9e2740cabf69d7518b17c18817714d6af9d1e7d9d5eb520efe6ecb463ad4435b
aarch64
thunderbird-128.10.1-1.el9_0.aarch64.rpm SHA-256: 25f6ed360ecbb7f6ea343bd1b1c182436ac443d2e05e929cd3c899c30709eca2
thunderbird-debuginfo-128.10.1-1.el9_0.aarch64.rpm SHA-256: bebc016a24bfd67cc2ee52bc630a72cdd52dbc92c151e40f3f26c41891b8729a
thunderbird-debugsource-128.10.1-1.el9_0.aarch64.rpm SHA-256: 1bed158683412d64049905765610aa8d6215c0642c70fa8c2ff73f691ec22039

Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.0

SRPM
thunderbird-128.10.1-1.el9_0.src.rpm SHA-256: 9e2740cabf69d7518b17c18817714d6af9d1e7d9d5eb520efe6ecb463ad4435b
s390x
thunderbird-128.10.1-1.el9_0.s390x.rpm SHA-256: 21de5d6f07bff946123faba1f9abba60a2dad82a598e01c4341fa1420228b957
thunderbird-debuginfo-128.10.1-1.el9_0.s390x.rpm SHA-256: 75b8d802400b54f6bcc5be2b14aec1d11d8a131bd41bf4fcae767e9756ff91cd
thunderbird-debugsource-128.10.1-1.el9_0.s390x.rpm SHA-256: 0d6522011a42b998def0e324d641247fe98968264162c1941d3b31964df824f6

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility