-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Mon, 03 Aug 2026 11:08:48 +0200
Source: thunderbird
Architecture: source
Version: 1:153.0.1esr-1
Distribution: experimental
Urgency: medium
Maintainer: Carsten Schoenert <c.schoenert@t-online.de>
Changed-By: Carsten Schoenert <c.schoenert@t-online.de>
Changes:
thunderbird (1:153.0.1esr-1) experimental; urgency=medium
.
* [0adf2ac] New upstream version 153.0.1esr
Fixed CVE issues in upstream version 153 (MFSA 2026-71):
CVE-2026-14899: Off-by-one out of bounds read in MIME header
parser for forwarding
CVE-2026-16349: Same-origin policy bypass in the DOM: Navigation
component
CVE-2026-16350: Incorrect boundary conditions in the
Audio/Video: cubeb component
CVE-2026-16362: Use-after-free in the WebRTC: Audio/Video component
CVE-2026-16351: Sandbox escape due to use-after-free in the
DOM: Navigation component
CVE-2026-16352: Sandbox escape due to use-after-free in the
Disability Access APIs component
CVE-2026-16363: JIT miscompilation in the JavaScript: WebAssembly
component
CVE-2026-16364: Incorrect boundary conditions in the
Audio/Video: Playback component
CVE-2026-16365: Privilege escalation in the DOM: Workers component
CVE-2026-16366: Privilege escalation in the
DOM: Navigation component
CVE-2026-16353: Invalid pointer in the
DOM: Bindings (WebIDL) component
CVE-2026-16354: Information disclosure in the Graphics: ImageLib
component
CVE-2026-16367: Sandbox escape due to invalid pointer in the
Disability Access APIs component
CVE-2026-16368: Incorrect boundary conditions in the JavaScript:
WebAssembly component
CVE-2026-16369: Integer overflow in the JavaScript: WebAssembly
component
CVE-2026-16355: JIT miscompilation in the JavaScript Engine:
JIT component
CVE-2026-16356: Sandbox escape due to use-after-free in the Disability
Access APIs component
CVE-2026-16357: Incorrect boundary conditions in the Graphics component
CVE-2026-16370: Mitigation bypass in the DOM: Networking component
CVE-2026-16371: Privilege escalation in the DOM: Navigation component
CVE-2026-16372: Privilege escalation in the DOM: Content Processes
component
CVE-2026-16374: Information disclosure in the Framework component in
DevTools
CVE-2026-16375: Site isolation issue in the Networking: HTTP component
CVE-2026-16376: Denial-of-service in the Graphics: WebGPU component
CVE-2026-16377: Mitigation bypass in the PDF Viewer component
CVE-2026-16378: Other issue in the DOM: Copy & Paste and Drag & Drop
component
CVE-2026-16379: Privilege escalation in the DOM: Content Processes
component
CVE-2026-16358: Site isolation issue in the Graphics: WebRender component
CVE-2026-16380: Mitigation bypass in the Networking component
CVE-2026-16381: Same-origin policy bypass in the Networking: DNS
component
CVE-2026-16382: Mitigation bypass in the DOM: Service Workers component
CVE-2026-16383: Mitigation bypass in the DOM: Networking component
CVE-2026-16384: Information disclosure due to uninitialized memory in the
Graphics: WebGPU component
CVE-2026-16385: Information disclosure due to uninitialized memory in the
Graphics: WebGPU component
CVE-2026-16386: Information disclosure due to uninitialized memory in the
Graphics: WebGPU component
CVE-2026-16387: Site isolation issue in the Networking component
CVE-2026-16388: Sandbox escape in the DOM: Networking component
CVE-2026-16389: Incorrect boundary conditions, integer overflow in the
Libraries component in NSS
CVE-2026-16390: Mitigation bypass in the Enterprise Policies component
CVE-2026-16391: Information disclosure in the Storage: IndexedDB
component
CVE-2026-16392: JIT miscompilation in the JavaScript Engine: JIT
component
CVE-2026-16393: Incorrect boundary conditions in the Graphics: WebGPU
component
CVE-2026-16359: Incorrect boundary conditions in the Audio/Video: GMP
component
CVE-2026-16394: Mitigation bypass in the DOM: Security component
CVE-2026-16395: Integer overflow in the Audio/Video component
CVE-2026-16396: Privilege escalation in WebExtensions
CVE-2026-16398: Site isolation issue in the Graphics component
CVE-2026-16399: Site isolation issue in the DOM: Navigation component
CVE-2026-16400: Information disclosure in the DOM: Security component
CVE-2026-16401: Privilege escalation in the Data Loss Prevention component
CVE-2026-16402: Integer overflow in the Graphics: ImageLib component
CVE-2026-16403: Spoofing issue in the Address Bar component
CVE-2026-16405: Information disclosure in the Networking: WebSockets
component
CVE-2026-16406: Mitigation bypass in the Networking component
CVE-2026-16407: Mitigation bypass in the DOM: Service Workers component
CVE-2026-16408: Integer overflow in the Audio/Video: Playback component
CVE-2026-16409: Invalid pointer in the Security: PSM component
CVE-2026-16410: JIT miscompilation in the JavaScript Engine: JIT component
CVE-2026-16411: Memory safety bugs fixed in Thunderbird 153
CVE-2026-16360: Memory safety bugs fixed in Thunderbird ESR 140.13 and
Thunderbird 153
Checksums-Sha1:
4061e7986b3f653adf15cc194051f318b015327b 8485 thunderbird_153.0.1esr-1.dsc
5d8adcc197d8d27ebed8c87a49286ffdcc810d06 12808384 thunderbird_153.0.1esr.orig-thunderbird-l10n.tar.xz
ca320d9aa14aeff57d3ba40c56e726541d2cb3f2 936885348 thunderbird_153.0.1esr.orig.tar.xz
c20c93ef17767ddc2ac2386abcefc4977e3f5c77 538360 thunderbird_153.0.1esr-1.debian.tar.xz
432ebb5d31e57bbbeac96328e100b2c3a8d96d79 41096 thunderbird_153.0.1esr-1_amd64.buildinfo
Checksums-Sha256:
d0f1c87275187a3be0f77dc410dac6e3baa4bb03202f0b700ad651e750c7c0da 8485 thunderbird_153.0.1esr-1.dsc
5701af32b85239640b071bd14d5da5c56b9468cc7520669d20994c5176a48547 12808384 thunderbird_153.0.1esr.orig-thunderbird-l10n.tar.xz
ce4f1ddbf1b3add184cc48e72b3767d59b89ffe41ee398aad7158f8c9ebc218a 936885348 thunderbird_153.0.1esr.orig.tar.xz
64bf8571547ea6aa3a8873c391df86fdf501bc39e45dcb0aae657e863e5af205 538360 thunderbird_153.0.1esr-1.debian.tar.xz
03486af5c99fdc9af5b0e1c93b170cbc1315c6ae70c3f3850d85f0a811596006 41096 thunderbird_153.0.1esr-1_amd64.buildinfo
Files:
b5808b3373a101bdcbfe63ee34674d8f 8485 mail optional thunderbird_153.0.1esr-1.dsc
f5e53dca4e9e29b313793a0d479cf754 12808384 mail optional thunderbird_153.0.1esr.orig-thunderbird-l10n.tar.xz
e08c769a2989d5db5065b52d85e1ac91 936885348 mail optional thunderbird_153.0.1esr.orig.tar.xz
f15dee796ce6288b1f01f3f6d66d94e2 538360 mail optional thunderbird_153.0.1esr-1.debian.tar.xz
afadbdbc184b755e856f98ffc6271c24 41096 mail optional thunderbird_153.0.1esr-1_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----
iQJMBAEBCgA2FiEEtw38bxNP7PwBHmKqgwFgFCUdHbAFAmpwrqsYHGMuc2Nob2Vu
ZXJ0QHQtb25saW5lLmRlAAoJEIMBYBQlHR2wvC4P/1/RGYQU43c4w0haSdlYeEO7
KmtBRfWrub4ujR0kXaSDaaSs3171SKahwx7RswfnD+6gVuh4hAj+te6AFq/EMzt/
s5G+WrqzNTy+uZe6bPVZ8tzm0xXoiL3WFIuzhJD5K9DWci6uK62LGhf3NnueikrH
3VcEUF0xOS8ivxKQ7KivwEoU53bOO7UokhMV/JwMCH4XX8ARJITzMyLVBXiPoXks
xn7KFmtMQ5IMvdmAYJI9q52QVOz9MnfoIKDPNVWNS1MW3tZoRKQLv7aDEmUNKC9+
JoQex0GZ1fSf6FAUFOrH3U89v2WP4Jk9IHGrWIMDBNFraei4ZGTUI4OtTqIiZPwQ
KN+2YzsNIN7Gh6Ue3brkC8laYPM1lsl+HjtIGc6oI7dyyL7ndOxS0Cct2HpmCCUL
Mi+jS/MeNUeqDTfXvfuSbO3bavcYPIHapGAD73+aqMu/zLYGYHIeb2Tw6LJ1DvIL
V7RsxqJv3PAhmMFkZsPQtZFslP8zgINGC2PQEfQdCmUgRKt+qPduCGzTB++F9d0G
4nAQS2pm89/77EgVwt3Mh2T2RboGCHAWDg1acXPRRPxfatoyHsGNcPEctoRROpv+
Nytc2AnrwcmGsBhT4Tk0Uz43iw5rSORJO02ME0YJ1D12Sjl1j2c1apdmsP0Wc/mA
cssw0H996+XC1Rj9kKLW
=KRss
-----END PGP SIGNATURE-----