-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Tue, 04 Aug 2026 17:36:13 +0200
Source: thunderbird
Architecture: source
Version: 1:140.13.0esr-1
Distribution: unstable
Urgency: medium
Maintainer: Carsten Schoenert <c.schoenert@t-online.de>
Changed-By: Carsten Schoenert <c.schoenert@t-online.de>
Changes:
thunderbird (1:140.13.0esr-1) unstable; urgency=medium
.
* [41e5476] New upstream version 140.13.0esr
Fixed CVE issues in upstream version 140.13 (MFSA 2026-72):
CVE-2026-14899: Off-by-one out of bounds read in MIME header parser
for forwarding
CVE-2026-15718: Invalid pointer in the JavaScript: WebAssembly component
CVE-2026-15719: Site isolation issue in the DOM: Navigation component
CVE-2026-16349: Same-origin policy bypass in the DOM: Navigation
component
CVE-2026-16350: Incorrect boundary conditions in the Audio/Video: cubeb
component
CVE-2026-16362: Use-after-free in the WebRTC: Audio/Video component
CVE-2026-16351: Sandbox escape due to use-after-free in the DOM:
Navigation component
CVE-2026-16352: Sandbox escape due to use-after-free in the Disability
Access APIs component
CVE-2026-16363: JIT miscompilation in the JavaScript: WebAssembly
component
CVE-2026-16353: Invalid pointer in the DOM: Bindings (WebIDL) component
CVE-2026-16354: Information disclosure in the Graphics: ImageLib
component
CVE-2026-16368: Incorrect boundary conditions in the JavaScript:
WebAssembly component
CVE-2026-16369: Integer overflow in the JavaScript: WebAssembly component
CVE-2026-16355: JIT miscompilation in the JavaScript Engine: JIT
component
CVE-2026-16356: Sandbox escape due to use-after-free in the Disability
Access APIs component
CVE-2026-16357: Incorrect boundary conditions in the Graphics component
CVE-2026-16371: Privilege escalation in the DOM: Navigation component
CVE-2026-16374: Information disclosure in the Framework component in
DevTools
CVE-2026-16375: Site isolation issue in the Networking: HTTP component
CVE-2026-16377: Mitigation bypass in the PDF Viewer component
CVE-2026-16379: Privilege escalation in the DOM: Content Processes
component
CVE-2026-16358: Site isolation issue in the Graphics: WebRender component
CVE-2026-16381: Same-origin policy bypass in the Networking: DNS
component
CVE-2026-16383: Mitigation bypass in the DOM: Networking component
CVE-2026-16387: Site isolation issue in the Networking component
CVE-2026-16390: Mitigation bypass in the Enterprise Policies component
CVE-2026-16391: Information disclosure in the Storage: IndexedDB
component
CVE-2026-16359: Incorrect boundary conditions in the Audio/Video: GMP
component
CVE-2026-16396: Privilege escalation in WebExtensions
CVE-2026-16405: Information disclosure in the Networking: WebSockets
component
CVE-2026-16412: Memory safety bugs fixed in Thunderbird ESR 140.13 and
Thunderbird 153
CVE-2026-16360: Memory safety bugs fixed in Thunderbird ESR 140.13 and
Thunderbird 153
CVE-2026-16361: Memory safety bugs fixed in Thunderbird ESR 140.13
* [fe5c7e7] Rebuild patch queue from patch-queue branch
Added patches (picked from firefox-esr):
fixes/Bug-1969769-Change-uses-of-ast.Str-with-ast.Constant.-r-f.patch
fixes/Bug-1983713-Use-non-deprecated-ast-value.-r-firefox-build.patch
fixes/Bug-1983736-Patch-jsonschema-to-work-with-Python-3.14-r-m.patch
.
Adjusted patches (removed wrong used metadata field 'Forwared'):
fixes/Add-missing-.gitmodules-files-which-are-needed-to-build-t.patch
fixes/Fix-conflicting-types-for-once_flag-and-call_once-with-gl.patch
fixes/Fix-sandbox-to-build-with-glibc-2.43.patch
fixes/Install-vaapitest-v4l2test-only-when-build.patch
* [79acc18] d/control: Increase Standards-Version to 4.7.4
No further changes needed.
* [d6c0a0f] d/rules: Move/rename third party Python modul temporarly
Checksums-Sha1:
54c4c00af5ba19be481c48417c8bddf290c3fb7f 8478 thunderbird_140.13.0esr-1.dsc
de103d0c924e407fe5f2186976c1dd8dad9ca464 12267700 thunderbird_140.13.0esr.orig-thunderbird-l10n.tar.xz
09d7fba6b0f1c83004aac5d0d1de11f9101e8b9d 790026404 thunderbird_140.13.0esr.orig.tar.xz
0ca8e8806ca4b2c4d06c4f5391b1eed1ea8779a0 571900 thunderbird_140.13.0esr-1.debian.tar.xz
cb3b6d015e89ee3bfb9548f223304fed1dd1719e 41448 thunderbird_140.13.0esr-1_amd64.buildinfo
Checksums-Sha256:
d79a5b312589cfab3f329c299d0308ee8008fef0c34b7706e772fed8953b09e3 8478 thunderbird_140.13.0esr-1.dsc
3b56a1f24e2797d14b2fcc79904fbed70f3fc82dd85f9dffc1ac12c65c0f3d45 12267700 thunderbird_140.13.0esr.orig-thunderbird-l10n.tar.xz
eefa02949bd02f85827313f36b24a613570a9dd2d93df3286ca62f3b5bf7d75a 790026404 thunderbird_140.13.0esr.orig.tar.xz
4d737023b561182ab0fe9ec9dea41b65db9527eaf36bb8578cd8a2a4994e0d5f 571900 thunderbird_140.13.0esr-1.debian.tar.xz
2b265fdf2c738a5db94a001ee17f66b1fdd2698877d2387d1cc3897a7eb577fb 41448 thunderbird_140.13.0esr-1_amd64.buildinfo
Files:
498bf6270cb870f8f6cfc2a9049650c2 8478 mail optional thunderbird_140.13.0esr-1.dsc
7cf47970c17189bfb0a3d78e8bb2c134 12267700 mail optional thunderbird_140.13.0esr.orig-thunderbird-l10n.tar.xz
27912317063b8e6103e477611169b8ba 790026404 mail optional thunderbird_140.13.0esr.orig.tar.xz
f98cdc06c69b2c51f472a842b9e61f23 571900 mail optional thunderbird_140.13.0esr-1.debian.tar.xz
cc0f781e4077afd53d84663f952f4811 41448 mail optional thunderbird_140.13.0esr-1_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----
iQJMBAEBCgA2FiEEtw38bxNP7PwBHmKqgwFgFCUdHbAFAmpyNxUYHGMuc2Nob2Vu
ZXJ0QHQtb25saW5lLmRlAAoJEIMBYBQlHR2wmjMQAIJk0FXbkJTwjZx8Em7S8Ntb
LqRbcC8Qqs0nAoD9ALsDmkPxBa6OO+buvWjDm+6ldW3AOZZhZCKfydqVLf9fvWyz
xXnhpIbys9hk7jK1eXFt9gpdllJg9vBF8juxSD2Rqe315l8DCSeTeKmjunG7BCyx
J2myVP3N1yM4ur7OsD3RxhqM/nPpqBULOsyMokyQVhbRMLHbfoElr91NyoaRl05L
jYEk94iAIFK9x+GZFHFh1yfinjlg38DlGundIxRI262QDYRq6YOpFUqqyuEdQFyS
C4RSlp6bIAXD0O3x6Y+cIblMYvfg0f6IrJM9iV+M37Zigi8+qh8ISwjo4Apb+uzp
Nyzh0cc+imEEqUWexsJaKGVzMS484RU2JstuZ0ssmxUnoduNcW4T1J9sZJYUlXEc
SyzI72TJy7JxbhdIfQqhI9P9nw3Nv2LCeZckRIDARvYQk6W7mbbI5rrw30aCQykp
i9JluJIz1vbDKDO5Rcvwd5h88XtPuLX6NV3j9EqYbZPAo87+A8Zu8rSRaNpLQjoU
YK3eRSaMxrQk3w0LR+xEGu2sgmiOGgjldW2x9CMZuKeEsjguu38PxxJnmEeSUbiv
HIm0oFHa1e+8l7Oc/3TmrAriU9dB0Vimb/mBh5IqRc4vkB3m23MIvWH2kC7gVqVK
kAH2y7xwXgDdTbypSuSs
=Oiwd
-----END PGP SIGNATURE-----