概述
Important: thunderbird security update
类型/严重性
Security Advisory: Important
标题
An update for thunderbird is now available for Red Hat Enterprise Linux 9.
Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.
描述
Mozilla Thunderbird is a standalone mail and newsgroup client.
Security Fix(es):
- firefox: Incorrect boundary conditions in the JavaScript Engine: JIT component (CVE-2026-8388)
- firefox: Other issue in the JavaScript Engine component (CVE-2026-8391)
- firefox: Sandbox escape in the Profile Backup component (CVE-2026-8401)
- firefox: Integer overflow in the Networking: JAR component (CVE-2026-8956)
- firefox: Memory safety bugs fixed in Firefox ESR 115.36, Firefox ESR 140.11 and Firefox 151 (CVE-2026-8975)
- firefox: Privilege escalation in the DOM: Workers component (CVE-2026-8955)
- firefox: Denial-of-service due to invalid pointer in the Audio/Video: Web Codecs component (CVE-2026-8968)
- firefox: Incorrect boundary conditions, integer overflow in the Audio/Video component (CVE-2026-8954)
- firefox: Information disclosure, sandbox escape in the Security: Process Sandboxing component (CVE-2026-8958)
- firefox: Incorrect boundary conditions in the Audio/Video: Web Codecs component (CVE-2026-8946)
- firefox: Privilege escalation in the Security component (CVE-2026-8970)
- firefox: Same-origin policy bypass in the Networking: HTTP component (CVE-2026-8950)
- firefox: Memory safety bugs fixed in Firefox ESR 140.11 and Firefox 151 (CVE-2026-8974)
- firefox: Sandbox escape due to use-after-free in the Disability Access APIs component (CVE-2026-8953)
- firefox: Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component (CVE-2026-8959)
- firefox: Spoofing issue in the Form Autofill component (CVE-2026-8961)
- firefox: Use-after-free in the DOM: Bindings (WebIDL) component (CVE-2026-8947)
- firefox: Mitigation bypass in the DOM: Security component (CVE-2026-8962)
- firefox: Privilege escalation in the Enterprise Policies component (CVE-2026-8957)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
受影响的产品
-
Red Hat Enterprise Linux for x86_64 9 x86_64
-
Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.8 x86_64
-
Red Hat Enterprise Linux for IBM z Systems 9 s390x
-
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.8 s390x
-
Red Hat Enterprise Linux for Power, little endian 9 ppc64le
-
Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.8 ppc64le
-
Red Hat Enterprise Linux for ARM 64 9 aarch64
-
Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.8 aarch64
-
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.8 ppc64le
-
Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.8 x86_64
-
Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.8 aarch64
-
Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.8 s390x
-
Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.8 x86_64
-
Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.8 aarch64
-
Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.8 ppc64le
-
Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.8 s390x
修复
-
BZ - 2476469
- CVE-2026-8388 firefox: Incorrect boundary conditions in the JavaScript Engine: JIT component
-
BZ - 2476475
- CVE-2026-8391 firefox: Other issue in the JavaScript Engine component
-
BZ - 2476492
- CVE-2026-8401 firefox: Sandbox escape in the Profile Backup component
-
BZ - 2479839
- CVE-2026-8956 firefox: Integer overflow in the Networking: JAR component
-
BZ - 2479840
- CVE-2026-8975 firefox: Memory safety bugs fixed in Firefox ESR 115.36, Firefox ESR 140.11 and Firefox 151
-
BZ - 2479842
- CVE-2026-8955 firefox: Privilege escalation in the DOM: Workers component
-
BZ - 2479846
- CVE-2026-8968 firefox: Denial-of-service due to invalid pointer in the Audio/Video: Web Codecs component
-
BZ - 2479847
- CVE-2026-8954 firefox: Incorrect boundary conditions, integer overflow in the Audio/Video component
-
BZ - 2479848
- CVE-2026-8958 firefox: Information disclosure, sandbox escape in the Security: Process Sandboxing component
-
BZ - 2479849
- CVE-2026-8946 firefox: Incorrect boundary conditions in the Audio/Video: Web Codecs component
-
BZ - 2479852
- CVE-2026-8970 firefox: Privilege escalation in the Security component
-
BZ - 2479853
- CVE-2026-8950 firefox: Same-origin policy bypass in the Networking: HTTP component
-
BZ - 2479855
- CVE-2026-8974 firefox: Memory safety bugs fixed in Firefox ESR 140.11 and Firefox 151
-
BZ - 2479860
- CVE-2026-8953 firefox: Sandbox escape due to use-after-free in the Disability Access APIs component
-
BZ - 2479861
- CVE-2026-8959 firefox: Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component
-
BZ - 2479871
- CVE-2026-8961 firefox: Spoofing issue in the Form Autofill component
-
BZ - 2479873
- CVE-2026-8947 firefox: Use-after-free in the DOM: Bindings (WebIDL) component
-
BZ - 2479876
- CVE-2026-8962 firefox: Mitigation bypass in the DOM: Security component
-
BZ - 2479880
- CVE-2026-8957 firefox: Privilege escalation in the Enterprise Policies component
备注:
可能有这些软件包的更新版本。
点击软件包名称查看详情。
Red Hat Enterprise Linux for x86_64 9
| SRPM |
|
thunderbird-140.11.0-1.el9_8.src.rpm
|
SHA-256: a20b3594d8b9295b159a654f83095f27a1e4472db37f37a8811df14f7482faff |
| x86_64 |
|
thunderbird-140.11.0-1.el9_8.x86_64.rpm
|
SHA-256: a4533fc61a365e2ee40138ee8d693212138f324436d39f304a421040586ad34c |
|
thunderbird-debuginfo-140.11.0-1.el9_8.x86_64.rpm
|
SHA-256: d102e59d9e9a4d6764be1220cc55b43c274ab25f9d45ae2b0991d8220818d3dd |
|
thunderbird-debugsource-140.11.0-1.el9_8.x86_64.rpm
|
SHA-256: 9347ac6d6be9dd68bd4aecd103ed351078587476325fd32062c5e8526d18e28a |
Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.8
| SRPM |
|
thunderbird-140.11.0-1.el9_8.src.rpm
|
SHA-256: a20b3594d8b9295b159a654f83095f27a1e4472db37f37a8811df14f7482faff |
| x86_64 |
|
thunderbird-140.11.0-1.el9_8.x86_64.rpm
|
SHA-256: a4533fc61a365e2ee40138ee8d693212138f324436d39f304a421040586ad34c |
|
thunderbird-debuginfo-140.11.0-1.el9_8.x86_64.rpm
|
SHA-256: d102e59d9e9a4d6764be1220cc55b43c274ab25f9d45ae2b0991d8220818d3dd |
|
thunderbird-debugsource-140.11.0-1.el9_8.x86_64.rpm
|
SHA-256: 9347ac6d6be9dd68bd4aecd103ed351078587476325fd32062c5e8526d18e28a |
Red Hat Enterprise Linux for IBM z Systems 9
| SRPM |
|
thunderbird-140.11.0-1.el9_8.src.rpm
|
SHA-256: a20b3594d8b9295b159a654f83095f27a1e4472db37f37a8811df14f7482faff |
| s390x |
|
thunderbird-140.11.0-1.el9_8.s390x.rpm
|
SHA-256: 8525204d0b8744dc138ca96a0065b8b68eaebde304152b70a72979105bada8a7 |
|
thunderbird-debuginfo-140.11.0-1.el9_8.s390x.rpm
|
SHA-256: bbbcc1c4ed2fcd78ea4c7b85946f9237ef06a2ac59d18e91897de5cca791b542 |
|
thunderbird-debugsource-140.11.0-1.el9_8.s390x.rpm
|
SHA-256: 73150f77917d4efbbc061a96a0ed4bef3ab84a6496a9eeae3f2a83d3d12258f2 |
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.8
| SRPM |
|
thunderbird-140.11.0-1.el9_8.src.rpm
|
SHA-256: a20b3594d8b9295b159a654f83095f27a1e4472db37f37a8811df14f7482faff |
| s390x |
|
thunderbird-140.11.0-1.el9_8.s390x.rpm
|
SHA-256: 8525204d0b8744dc138ca96a0065b8b68eaebde304152b70a72979105bada8a7 |
|
thunderbird-debuginfo-140.11.0-1.el9_8.s390x.rpm
|
SHA-256: bbbcc1c4ed2fcd78ea4c7b85946f9237ef06a2ac59d18e91897de5cca791b542 |
|
thunderbird-debugsource-140.11.0-1.el9_8.s390x.rpm
|
SHA-256: 73150f77917d4efbbc061a96a0ed4bef3ab84a6496a9eeae3f2a83d3d12258f2 |
Red Hat Enterprise Linux for Power, little endian 9
| SRPM |
|
thunderbird-140.11.0-1.el9_8.src.rpm
|
SHA-256: a20b3594d8b9295b159a654f83095f27a1e4472db37f37a8811df14f7482faff |
| ppc64le |
|
thunderbird-140.11.0-1.el9_8.ppc64le.rpm
|
SHA-256: 32dbb77d61ee311d087d8580d7920396e8ab31b31461d304faccd1e4252a8e11 |
|
thunderbird-debuginfo-140.11.0-1.el9_8.ppc64le.rpm
|
SHA-256: ed27e3420225738b8023e4cf17529731bfbed3aadd2cc8084979303be5ae41b3 |
|
thunderbird-debugsource-140.11.0-1.el9_8.ppc64le.rpm
|
SHA-256: 80df5c3fcb76250d806bf5bf389e004a0a7c56819ee2827924220edfac89dfaf |
Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.8
| SRPM |
|
thunderbird-140.11.0-1.el9_8.src.rpm
|
SHA-256: a20b3594d8b9295b159a654f83095f27a1e4472db37f37a8811df14f7482faff |
| ppc64le |
|
thunderbird-140.11.0-1.el9_8.ppc64le.rpm
|
SHA-256: 32dbb77d61ee311d087d8580d7920396e8ab31b31461d304faccd1e4252a8e11 |
|
thunderbird-debuginfo-140.11.0-1.el9_8.ppc64le.rpm
|
SHA-256: ed27e3420225738b8023e4cf17529731bfbed3aadd2cc8084979303be5ae41b3 |
|
thunderbird-debugsource-140.11.0-1.el9_8.ppc64le.rpm
|
SHA-256: 80df5c3fcb76250d806bf5bf389e004a0a7c56819ee2827924220edfac89dfaf |
Red Hat Enterprise Linux for ARM 64 9
| SRPM |
|
thunderbird-140.11.0-1.el9_8.src.rpm
|
SHA-256: a20b3594d8b9295b159a654f83095f27a1e4472db37f37a8811df14f7482faff |
| aarch64 |
|
thunderbird-140.11.0-1.el9_8.aarch64.rpm
|
SHA-256: c5f20cfa4b6bf5a382293213d251be7b46188892bbdb2adde8cf3c142e5ea23f |
|
thunderbird-debuginfo-140.11.0-1.el9_8.aarch64.rpm
|
SHA-256: c2377066545c645f45ad2e8158bb223cbad0870aad4cb7a5b6f041bdf3f3856b |
|
thunderbird-debugsource-140.11.0-1.el9_8.aarch64.rpm
|
SHA-256: 48f8c38d9446b9891fd3c7639605c70dc7911826d8a2be012da5792d44151582 |
Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.8
| SRPM |
|
thunderbird-140.11.0-1.el9_8.src.rpm
|
SHA-256: a20b3594d8b9295b159a654f83095f27a1e4472db37f37a8811df14f7482faff |
| aarch64 |
|
thunderbird-140.11.0-1.el9_8.aarch64.rpm
|
SHA-256: c5f20cfa4b6bf5a382293213d251be7b46188892bbdb2adde8cf3c142e5ea23f |
|
thunderbird-debuginfo-140.11.0-1.el9_8.aarch64.rpm
|
SHA-256: c2377066545c645f45ad2e8158bb223cbad0870aad4cb7a5b6f041bdf3f3856b |
|
thunderbird-debugsource-140.11.0-1.el9_8.aarch64.rpm
|
SHA-256: 48f8c38d9446b9891fd3c7639605c70dc7911826d8a2be012da5792d44151582 |
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.8
| SRPM |
|
thunderbird-140.11.0-1.el9_8.src.rpm
|
SHA-256: a20b3594d8b9295b159a654f83095f27a1e4472db37f37a8811df14f7482faff |
| ppc64le |
|
thunderbird-140.11.0-1.el9_8.ppc64le.rpm
|
SHA-256: 32dbb77d61ee311d087d8580d7920396e8ab31b31461d304faccd1e4252a8e11 |
|
thunderbird-debuginfo-140.11.0-1.el9_8.ppc64le.rpm
|
SHA-256: ed27e3420225738b8023e4cf17529731bfbed3aadd2cc8084979303be5ae41b3 |
|
thunderbird-debugsource-140.11.0-1.el9_8.ppc64le.rpm
|
SHA-256: 80df5c3fcb76250d806bf5bf389e004a0a7c56819ee2827924220edfac89dfaf |
Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.8
| SRPM |
|
thunderbird-140.11.0-1.el9_8.src.rpm
|
SHA-256: a20b3594d8b9295b159a654f83095f27a1e4472db37f37a8811df14f7482faff |
| x86_64 |
|
thunderbird-140.11.0-1.el9_8.x86_64.rpm
|
SHA-256: a4533fc61a365e2ee40138ee8d693212138f324436d39f304a421040586ad34c |
|
thunderbird-debuginfo-140.11.0-1.el9_8.x86_64.rpm
|
SHA-256: d102e59d9e9a4d6764be1220cc55b43c274ab25f9d45ae2b0991d8220818d3dd |
|
thunderbird-debugsource-140.11.0-1.el9_8.x86_64.rpm
|
SHA-256: 9347ac6d6be9dd68bd4aecd103ed351078587476325fd32062c5e8526d18e28a |
Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.8
| SRPM |
|
thunderbird-140.11.0-1.el9_8.src.rpm
|
SHA-256: a20b3594d8b9295b159a654f83095f27a1e4472db37f37a8811df14f7482faff |
| aarch64 |
|
thunderbird-140.11.0-1.el9_8.aarch64.rpm
|
SHA-256: c5f20cfa4b6bf5a382293213d251be7b46188892bbdb2adde8cf3c142e5ea23f |
|
thunderbird-debuginfo-140.11.0-1.el9_8.aarch64.rpm
|
SHA-256: c2377066545c645f45ad2e8158bb223cbad0870aad4cb7a5b6f041bdf3f3856b |
|
thunderbird-debugsource-140.11.0-1.el9_8.aarch64.rpm
|
SHA-256: 48f8c38d9446b9891fd3c7639605c70dc7911826d8a2be012da5792d44151582 |
Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.8
| SRPM |
|
thunderbird-140.11.0-1.el9_8.src.rpm
|
SHA-256: a20b3594d8b9295b159a654f83095f27a1e4472db37f37a8811df14f7482faff |
| s390x |
|
thunderbird-140.11.0-1.el9_8.s390x.rpm
|
SHA-256: 8525204d0b8744dc138ca96a0065b8b68eaebde304152b70a72979105bada8a7 |
|
thunderbird-debuginfo-140.11.0-1.el9_8.s390x.rpm
|
SHA-256: bbbcc1c4ed2fcd78ea4c7b85946f9237ef06a2ac59d18e91897de5cca791b542 |
|
thunderbird-debugsource-140.11.0-1.el9_8.s390x.rpm
|
SHA-256: 73150f77917d4efbbc061a96a0ed4bef3ab84a6496a9eeae3f2a83d3d12258f2 |
Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.8
| SRPM |
|
thunderbird-140.11.0-1.el9_8.src.rpm
|
SHA-256: a20b3594d8b9295b159a654f83095f27a1e4472db37f37a8811df14f7482faff |
| x86_64 |
|
thunderbird-140.11.0-1.el9_8.x86_64.rpm
|
SHA-256: a4533fc61a365e2ee40138ee8d693212138f324436d39f304a421040586ad34c |
|
thunderbird-debuginfo-140.11.0-1.el9_8.x86_64.rpm
|
SHA-256: d102e59d9e9a4d6764be1220cc55b43c274ab25f9d45ae2b0991d8220818d3dd |
|
thunderbird-debugsource-140.11.0-1.el9_8.x86_64.rpm
|
SHA-256: 9347ac6d6be9dd68bd4aecd103ed351078587476325fd32062c5e8526d18e28a |
Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.8
| SRPM |
|
thunderbird-140.11.0-1.el9_8.src.rpm
|
SHA-256: a20b3594d8b9295b159a654f83095f27a1e4472db37f37a8811df14f7482faff |
| aarch64 |
|
thunderbird-140.11.0-1.el9_8.aarch64.rpm
|
SHA-256: c5f20cfa4b6bf5a382293213d251be7b46188892bbdb2adde8cf3c142e5ea23f |
|
thunderbird-debuginfo-140.11.0-1.el9_8.aarch64.rpm
|
SHA-256: c2377066545c645f45ad2e8158bb223cbad0870aad4cb7a5b6f041bdf3f3856b |
|
thunderbird-debugsource-140.11.0-1.el9_8.aarch64.rpm
|
SHA-256: 48f8c38d9446b9891fd3c7639605c70dc7911826d8a2be012da5792d44151582 |
Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.8
| SRPM |
|
thunderbird-140.11.0-1.el9_8.src.rpm
|
SHA-256: a20b3594d8b9295b159a654f83095f27a1e4472db37f37a8811df14f7482faff |
| ppc64le |
|
thunderbird-140.11.0-1.el9_8.ppc64le.rpm
|
SHA-256: 32dbb77d61ee311d087d8580d7920396e8ab31b31461d304faccd1e4252a8e11 |
|
thunderbird-debuginfo-140.11.0-1.el9_8.ppc64le.rpm
|
SHA-256: ed27e3420225738b8023e4cf17529731bfbed3aadd2cc8084979303be5ae41b3 |
|
thunderbird-debugsource-140.11.0-1.el9_8.ppc64le.rpm
|
SHA-256: 80df5c3fcb76250d806bf5bf389e004a0a7c56819ee2827924220edfac89dfaf |
Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.8
| SRPM |
|
thunderbird-140.11.0-1.el9_8.src.rpm
|
SHA-256: a20b3594d8b9295b159a654f83095f27a1e4472db37f37a8811df14f7482faff |
| s390x |
|
thunderbird-140.11.0-1.el9_8.s390x.rpm
|
SHA-256: 8525204d0b8744dc138ca96a0065b8b68eaebde304152b70a72979105bada8a7 |
|
thunderbird-debuginfo-140.11.0-1.el9_8.s390x.rpm
|
SHA-256: bbbcc1c4ed2fcd78ea4c7b85946f9237ef06a2ac59d18e91897de5cca791b542 |
|
thunderbird-debugsource-140.11.0-1.el9_8.s390x.rpm
|
SHA-256: 73150f77917d4efbbc061a96a0ed4bef3ab84a6496a9eeae3f2a83d3d12258f2 |