Debian Package Tracker
Register | Log in
Subscribe

thunderbird

mail/news client with RSS, chat and integrated spam filter support

Choose email to subscribe with

general
  • source: thunderbird (main)
  • version: 1:153.3.0esr-1
  • maintainer: Carsten Schoenert (DMD)
  • uploaders: Christoph Goehre [DMD]
  • arch: all amd64 arm64 i386 loong64 mips64el ppc64 ppc64el riscv64 s390x
  • std-ver: 4.7.4
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 1:115.12.0-1~deb11u1
  • o-o-sec: 1:140.14.0esr-1~deb11u1
  • o-o-p-u: 1:115.14.0-1~deb11u1
  • oldstable: 1:140.12.0esr-1~deb12u1
  • old-sec: 1:140.16.0esr-1~deb12u1
  • old-p-u: 1:140.12.0esr-1~deb12u1
  • stable: 1:140.12.0esr-1~deb13u1
  • stable-sec: 1:140.16.0esr-1~deb13u1
  • stable-p-u: 1:140.15.0esr-1~deb13u1
  • testing: 1:140.14.0esr-1
  • unstable: 1:153.3.0esr-1
  • exp: 1:155.0.1-1
versioned links
  • 1:91.13.0-1~deb11u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1:115.12.0-1~deb11u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1:115.14.0-1~deb11u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1:115.16.0esr-1~deb12u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1:140.12.0esr-1~deb12u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1:140.12.0esr-1~deb13u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1:140.14.0esr-1~deb11u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1:140.14.0esr-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1:140.15.0esr-1~deb13u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1:140.16.0esr-1~deb12u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1:140.16.0esr-1~deb13u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1:153.1.0esr-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1:153.2.0esr-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1:153.3.0esr-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1:155.0.1-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • thunderbird (129 bugs: 0, 113, 16, 0)
  • thunderbird-l10n-af
  • thunderbird-l10n-all
  • thunderbird-l10n-ar
  • thunderbird-l10n-ast
  • thunderbird-l10n-be
  • thunderbird-l10n-bg
  • thunderbird-l10n-br
  • thunderbird-l10n-ca
  • thunderbird-l10n-cak
  • thunderbird-l10n-cs
  • thunderbird-l10n-cy
  • thunderbird-l10n-da (1 bugs: 0, 0, 1, 0)
  • thunderbird-l10n-de
  • thunderbird-l10n-dsb
  • thunderbird-l10n-el
  • thunderbird-l10n-en-ca
  • thunderbird-l10n-en-gb
  • thunderbird-l10n-es-ar
  • thunderbird-l10n-es-es
  • thunderbird-l10n-es-mx
  • thunderbird-l10n-et
  • thunderbird-l10n-eu
  • thunderbird-l10n-fi
  • thunderbird-l10n-fr (2 bugs: 0, 1, 1, 0)
  • thunderbird-l10n-fy-nl
  • thunderbird-l10n-ga-ie
  • thunderbird-l10n-gd
  • thunderbird-l10n-gl
  • thunderbird-l10n-he
  • thunderbird-l10n-hr
  • thunderbird-l10n-hsb
  • thunderbird-l10n-hu
  • thunderbird-l10n-hy-am
  • thunderbird-l10n-id
  • thunderbird-l10n-is
  • thunderbird-l10n-it
  • thunderbird-l10n-ja
  • thunderbird-l10n-ka
  • thunderbird-l10n-kab
  • thunderbird-l10n-kk
  • thunderbird-l10n-ko
  • thunderbird-l10n-lt
  • thunderbird-l10n-lv
  • thunderbird-l10n-ms
  • thunderbird-l10n-nb-no
  • thunderbird-l10n-nl (1 bugs: 0, 1, 0, 0)
  • thunderbird-l10n-nn-no
  • thunderbird-l10n-pa-in
  • thunderbird-l10n-pl
  • thunderbird-l10n-pt-br
  • thunderbird-l10n-pt-pt
  • thunderbird-l10n-rm
  • thunderbird-l10n-ro
  • thunderbird-l10n-ru
  • thunderbird-l10n-sk
  • thunderbird-l10n-sl
  • thunderbird-l10n-sq
  • thunderbird-l10n-sr
  • thunderbird-l10n-sv-se
  • thunderbird-l10n-th
  • thunderbird-l10n-tr
  • thunderbird-l10n-uk
  • thunderbird-l10n-uz
  • thunderbird-l10n-vi
  • thunderbird-l10n-zh-cn
  • thunderbird-l10n-zh-tw
action needed
lintian reports 1 error and 1 warning high
Lintian reports 1 error and 1 warning about this package. You should make the package lintian clean getting rid of them.
Created: 2026-09-17 Last update: 2026-09-18 04:01
debian/patches: 1 patch with invalid metadata, 15 patches to forward upstream high

Among the 20 debian patches available in version 1:153.3.0esr-1 of the package, we noticed the following issues:

  • 1 patch with invalid metadata that ought to be fixed.
  • 15 patches where the metadata indicates that the patch has not yet been forwarded upstream. You should either forward the patch upstream or update the metadata to document its real status.
Created: 2023-02-26 Last update: 2026-09-17 21:01
75 security issues in forky high

There are 75 open security issues in forky.

75 important issues:
  • CVE-2026-16365: Privilege escalation in the DOM: Workers component. This vulnerability was fixed in Firefox 153, Thunderbird 153, Firefox ESR 140.15, and Thunderbird 140.15.
  • CVE-2026-75874: Sandbox escape in the Remote Settings Client component. This vulnerability was fixed in Firefox 154, Thunderbird 154, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 140.15, and Thunderbird 153.2.
  • CVE-2026-84119: Sandbox escape due to use-after-free in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.
  • CVE-2026-84120: Use-after-free in the Audio/Video component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.
  • CVE-2026-84121: Sandbox escape due to use-after-free in the DOM: Security component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.
  • CVE-2026-84122: Use-after-free in the Audio/Video component. This vulnerability was fixed in Firefox 155, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.
  • CVE-2026-84124: Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 155, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.
  • CVE-2026-84131: Privilege escalation due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.
  • CVE-2026-84143: Internally found bugs present in Thunderbird 154, Thunderbird ESR 153.1 and Thunderbird ESR 140.14. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 155, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.
  • CVE-2026-84145: Internally found bugs present in Thunderbird 154, Thunderbird ESR 153.1 and Thunderbird ESR 140.14. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.
  • CVE-2026-84639: Triggering an error condition in certain MIME bodies would cause uninitialized memory to be used. This vulnerability was fixed in Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.
  • CVE-2026-84640: A maliciously constructed mail header could lead to a one byte read past the end of a buffer. This vulnerability was fixed in Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.
  • CVE-2026-84641: A malicious IMAP server can trigger use-after-free and heap-memory disclosure by sending a crafted ID response. Heap contents can ultimately be persisted to prefs.js. This vulnerability was fixed in Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.
  • CVE-2026-92005: Use-after-free in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.
  • CVE-2026-92006: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.
  • CVE-2026-92007: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.
  • CVE-2026-92008: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.
  • CVE-2026-92009: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.
  • CVE-2026-92010: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.
  • CVE-2026-92011: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.
  • CVE-2026-92012: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.
  • CVE-2026-92013: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.
  • CVE-2026-92014: Privilege escalation due to incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox ESR 115.41, Firefox ESR 140.16, and Thunderbird 140.16.
  • CVE-2026-92015: Privilege escalation in the WebExtensions component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.
  • CVE-2026-92016: Use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.
  • CVE-2026-92017: Privilege escalation in the DOM: Service Workers component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.
  • CVE-2026-92018: Sandbox escape in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.
  • CVE-2026-92019: Mitigation bypass in the Remote Settings Client component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.
  • CVE-2026-92020: Privilege escalation due to incorrect boundary conditions in the Graphics: WebRender component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.
  • CVE-2026-92021: Use-after-free in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox ESR 140.16 and Thunderbird 140.16.
  • CVE-2026-92022: Use-after-free in the DOM: HTML Parser component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.
  • CVE-2026-92023: Use-after-free in the XML component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.
  • CVE-2026-92024: Use-after-free in the SVG component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.
  • CVE-2026-92025: Use-after-free in the DOM: Navigation component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.
  • CVE-2026-92026: Use-after-free in the Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.
  • CVE-2026-92027: Use-after-free in the DOM: Streams component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.
  • CVE-2026-92028: Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.
  • CVE-2026-92029: Use-after-free in the SVG component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.
  • CVE-2026-92030: Mitigation bypass in the DOM: Copy & Paste and Drag & Drop component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.
  • CVE-2026-92031: Information disclosure in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.
  • CVE-2026-92032: Sandbox escape due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.
  • CVE-2026-92035: Sandbox escape due to incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
  • CVE-2026-92038: Mitigation bypass in the Remote Settings Client component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
  • CVE-2026-92039: Mitigation bypass in the DOM: Notifications component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
  • CVE-2026-92041: Mitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
  • CVE-2026-92042: Race condition in the DOM: Content Processes component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
  • CVE-2026-92043: Privilege escalation due to incorrect boundary conditions in the Audio/Video component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
  • CVE-2026-92044: Information disclosure in the Networking: HTTP component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
  • CVE-2026-92045: Sandbox escape due to incorrect boundary conditions in the WebRTC component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
  • CVE-2026-92046: Use-after-free in the Graphics component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
  • CVE-2026-92047: Privilege escalation in the Crash Reporting component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
  • CVE-2026-92052: Privilege escalation due to uninitialized memory in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
  • CVE-2026-92053: Privilege escalation in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
  • CVE-2026-92054: Privilege escalation in the Memory component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
  • CVE-2026-92055: Privilege escalation in the DevTools component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
  • CVE-2026-92056: Use-after-free in the Graphics: Text component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
  • CVE-2026-92057: Mitigation bypass in the Enterprise Policies component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
  • CVE-2026-92058: Use-after-free in the Graphics component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
  • CVE-2026-92059: Incorrect boundary conditions in the DOM: Editor component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
  • CVE-2026-92060: Use-after-free in the Internationalization component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
  • CVE-2026-92062: Privilege escalation in the Session Restore component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
  • CVE-2026-92067: Use-after-free in the Widget: Gtk component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
  • CVE-2026-92068: Site isolation issue in the Reader Mode component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
  • CVE-2026-92069: Spoofing issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
  • CVE-2026-92070: Information disclosure in the Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
  • CVE-2026-92072: Incorrect boundary conditions in the Safe Browsing component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
  • CVE-2026-92073: Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
  • CVE-2026-92074: Mitigation bypass in the Popup Blocker component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
  • CVE-2026-92075: Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
  • CVE-2026-92076: Incorrect boundary conditions in the Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
  • CVE-2026-92077: Denial-of-service in the SVG component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
  • CVE-2026-92078: Denial-of-service in the Security component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
  • CVE-2026-92238: A maliciously constructed mail header could lead to multiple fields being parsed as one, or potential memory safety violations. This vulnerability was fixed in Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.
  • CVE-2026-92239: A maliciously constructed IMAP line could cause an out-of-bounds buffer read. This vulnerability was fixed in Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.
  • CVE-2026-92240: A malicious or compromised IMAP server can trigger an out-of-bounds read in the IMAP response parser by sending an untagged '* ID' response, crashing Thunderbird. The affected parsing path is reachable before authentication. This vulnerability was fixed in Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.
Created: 2026-09-02 Last update: 2026-09-17 21:00
31 security issues in trixie high

There are 31 open security issues in trixie.

31 important issues:
  • CVE-2026-92035: Sandbox escape due to incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
  • CVE-2026-92038: Mitigation bypass in the Remote Settings Client component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
  • CVE-2026-92039: Mitigation bypass in the DOM: Notifications component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
  • CVE-2026-92041: Mitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
  • CVE-2026-92042: Race condition in the DOM: Content Processes component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
  • CVE-2026-92043: Privilege escalation due to incorrect boundary conditions in the Audio/Video component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
  • CVE-2026-92044: Information disclosure in the Networking: HTTP component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
  • CVE-2026-92045: Sandbox escape due to incorrect boundary conditions in the WebRTC component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
  • CVE-2026-92046: Use-after-free in the Graphics component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
  • CVE-2026-92047: Privilege escalation in the Crash Reporting component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
  • CVE-2026-92052: Privilege escalation due to uninitialized memory in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
  • CVE-2026-92053: Privilege escalation in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
  • CVE-2026-92054: Privilege escalation in the Memory component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
  • CVE-2026-92055: Privilege escalation in the DevTools component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
  • CVE-2026-92056: Use-after-free in the Graphics: Text component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
  • CVE-2026-92057: Mitigation bypass in the Enterprise Policies component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
  • CVE-2026-92058: Use-after-free in the Graphics component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
  • CVE-2026-92059: Incorrect boundary conditions in the DOM: Editor component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
  • CVE-2026-92060: Use-after-free in the Internationalization component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
  • CVE-2026-92062: Privilege escalation in the Session Restore component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
  • CVE-2026-92067: Use-after-free in the Widget: Gtk component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
  • CVE-2026-92068: Site isolation issue in the Reader Mode component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
  • CVE-2026-92069: Spoofing issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
  • CVE-2026-92070: Information disclosure in the Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
  • CVE-2026-92072: Incorrect boundary conditions in the Safe Browsing component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
  • CVE-2026-92073: Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
  • CVE-2026-92074: Mitigation bypass in the Popup Blocker component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
  • CVE-2026-92075: Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
  • CVE-2026-92076: Incorrect boundary conditions in the Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
  • CVE-2026-92077: Denial-of-service in the SVG component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
  • CVE-2026-92078: Denial-of-service in the Security component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Created: 2026-09-17 Last update: 2026-09-17 21:00
31 security issues in bookworm high

There are 31 open security issues in bookworm.

31 important issues:
  • CVE-2026-92035: Sandbox escape due to incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
  • CVE-2026-92038: Mitigation bypass in the Remote Settings Client component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
  • CVE-2026-92039: Mitigation bypass in the DOM: Notifications component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
  • CVE-2026-92041: Mitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
  • CVE-2026-92042: Race condition in the DOM: Content Processes component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
  • CVE-2026-92043: Privilege escalation due to incorrect boundary conditions in the Audio/Video component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
  • CVE-2026-92044: Information disclosure in the Networking: HTTP component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
  • CVE-2026-92045: Sandbox escape due to incorrect boundary conditions in the WebRTC component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
  • CVE-2026-92046: Use-after-free in the Graphics component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
  • CVE-2026-92047: Privilege escalation in the Crash Reporting component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
  • CVE-2026-92052: Privilege escalation due to uninitialized memory in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
  • CVE-2026-92053: Privilege escalation in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
  • CVE-2026-92054: Privilege escalation in the Memory component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
  • CVE-2026-92055: Privilege escalation in the DevTools component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
  • CVE-2026-92056: Use-after-free in the Graphics: Text component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
  • CVE-2026-92057: Mitigation bypass in the Enterprise Policies component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
  • CVE-2026-92058: Use-after-free in the Graphics component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
  • CVE-2026-92059: Incorrect boundary conditions in the DOM: Editor component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
  • CVE-2026-92060: Use-after-free in the Internationalization component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
  • CVE-2026-92062: Privilege escalation in the Session Restore component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
  • CVE-2026-92067: Use-after-free in the Widget: Gtk component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
  • CVE-2026-92068: Site isolation issue in the Reader Mode component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
  • CVE-2026-92069: Spoofing issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
  • CVE-2026-92070: Information disclosure in the Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
  • CVE-2026-92072: Incorrect boundary conditions in the Safe Browsing component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
  • CVE-2026-92073: Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
  • CVE-2026-92074: Mitigation bypass in the Popup Blocker component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
  • CVE-2026-92075: Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
  • CVE-2026-92076: Incorrect boundary conditions in the Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
  • CVE-2026-92077: Denial-of-service in the SVG component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
  • CVE-2026-92078: Denial-of-service in the Security component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Created: 2026-09-17 Last update: 2026-09-17 21:00
2 bugs tagged patch in the BTS normal
The BTS contains patches fixing 2 bugs, consider including or untagging them.
Created: 2026-09-02 Last update: 2026-09-20 01:30
Depends on packages which need a new maintainer normal
The packages that thunderbird depends on which need a new maintainer are:
  • libidl (#738870)
    • Build-Depends: libidl-dev
  • hunspell-kk (#879871)
    • Recommends: hunspell-kk
  • ifrench-gut (#1006643)
    • Recommends: myspell-fr-gut
  • uzbek-wordlist (#841696)
    • Recommends: hunspell-uz
Created: 2019-11-22 Last update: 2026-09-20 01:03
Fails to build during reproducibility testing normal
A package building reproducibly enables third parties to verify that the source matches the distributed binaries. It has been identified that this source package produced different results, failed to build or had other issues in a test environment. Please read about how to improve the situation!
Created: 2026-08-28 Last update: 2026-09-20 00:31
version in VCS is newer than in repository, is it time to upload? normal
vcswatch reports that this package seems to have a new changelog entry (version 1:155.0.1-2, distribution experimental) and new commits in its VCS. You should consider whether it's time to make an upload.

https://salsa.debian.org/api/v4/projects/mozilla-team%2Fthunderbird API request failed: 401 Unauthorized at /srv/qa.debian.org/data/vcswatch/vcswatch line 410.
Created: 2026-09-19 Last update: 2026-09-19 22:00
AppStream hints: 1 warning normal
AppStream found metadata issues for packages:
  • thunderbird: 1 warning
You should get rid of them to provide more metadata about this software.
Created: 2021-12-22 Last update: 2021-12-22 06:06
testing migrations
  • This package is part of the ongoing testing transition known as auto-upperlimit-thunderbird. Please avoid uploads unrelated to this transition, they would likely delay it and require supplementary work from the release managers. On the other hand, if your package has problems preventing it to migrate to testing, please fix them as soon as possible. You can probably find supplementary information in the debian-release archives or in the corresponding release.debian.org bug.
  • excuses:
    • Migration status for thunderbird (1:140.14.0esr-1 to 1:153.3.0esr-1): BLOCKED: Maybe temporary, maybe blocked but Britney is missing information (check below)
    • Issues preventing migration:
    • ∙ ∙ Missing build on i386
    • ∙ ∙ Missing build on riscv64
    • ∙ ∙ Autopkgtest deferred on i386: missing arch:i386 build
    • ∙ ∙ Autopkgtest deferred on riscv64: missing arch:riscv64 build
    • ∙ ∙ Autopkgtest for thunderbird/1:153.3.0esr-1: amd64: Pass, arm64: Test triggered (failure will be ignored), ppc64el: No tests, superficial or marked flaky ♻
    • ∙ ∙ Lintian check waiting for test results on riscv64, i386 - info
    • ∙ ∙ Reproducibility check deferred on i386: missing builds - info
    • ∙ ∙ Too young, only 3 of 5 days old
    • Additional info (not blocking):
    • ∙ ∙ Piuparts tested OK - https://piuparts.debian.org/sid/source/t/thunderbird.html
    • ∙ ∙ Autopkgtest skipped on armhf: not installable (which is allowed)
    • ∙ ∙ Reproduced on amd64 - info
    • ∙ ∙ Reproduced on arm64 - info
    • ∙ ∙ Reproduced on armhf - info
    • Not considered
news
[rss feed]
  • [2026-09-19] Accepted thunderbird 1:155.0.1-2 (source) into experimental (Christoph Goehre)
  • [2026-09-17] Accepted thunderbird 1:153.3.0esr-1 (source) into unstable (Carsten Schoenert)
  • [2026-09-16] Accepted thunderbird 1:140.16.0esr-1~deb13u1 (source) into stable-security (Debian FTP Masters) (signed by: Christoph Goehre)
  • [2026-09-16] Accepted thunderbird 1:140.16.0esr-1~deb12u1 (source) into oldstable-security (Christoph Goehre)
  • [2026-09-14] Accepted thunderbird 1:155.0.1-1 (source) into experimental (Carsten Schoenert)
  • [2026-09-05] Accepted thunderbird 1:140.15.0esr-1~deb13u1 (source) into proposed-updates (Debian FTP Masters) (signed by: Christoph Goehre)
  • [2026-09-04] Accepted thunderbird 1:140.15.0esr-1~deb13u1 (source) into stable-security (Debian FTP Masters) (signed by: Christoph Goehre)
  • [2026-09-02] Accepted thunderbird 1:153.2.0esr-1 (source) into unstable (Carsten Schoenert)
  • [2026-09-02] Accepted thunderbird 1:140.15.0esr-1~deb12u1 (source) into oldstable-security (Christoph Goehre)
  • [2026-08-26] thunderbird 1:140.14.0esr-1 MIGRATED to testing (Debian testing watch)
  • [2026-08-24] Accepted thunderbird 1:140.14.0esr-1~deb13u1 (source) into proposed-updates (Debian FTP Masters) (signed by: Carsten Schoenert)
  • [2026-08-24] Accepted thunderbird 1:140.14.0esr-1~deb11u1 (source) into oldoldstable-security (Carsten Schoenert)
  • [2026-08-23] Accepted thunderbird 1:140.14.0esr-1~deb13u1 (source) into stable-security (Debian FTP Masters) (signed by: Carsten Schoenert)
  • [2026-08-23] Accepted thunderbird 1:140.14.0esr-1~deb12u1 (source) into oldstable-security (Carsten Schoenert)
  • [2026-08-20] Accepted thunderbird 1:140.14.0esr-1 (source) into unstable (Carsten Schoenert)
  • [2026-08-19] Accepted thunderbird 1:153.1.0esr-1 (source) into experimental (Carsten Schoenert)
  • [2026-08-17] Accepted thunderbird 1:153.0.3esr-1 (source) into experimental (Carsten Schoenert)
  • [2026-08-11] thunderbird 1:140.13.0esr-2 MIGRATED to testing (Debian testing watch)
  • [2026-08-09] Accepted thunderbird 1:140.13.0esr-2~deb13u1 (source) into proposed-updates (Debian FTP Masters) (signed by: Carsten Schoenert)
  • [2026-08-09] Accepted thunderbird 1:140.13.0esr-2~deb11u1 (source) into oldoldstable-security (Carsten Schoenert)
  • [2026-08-07] Accepted thunderbird 1:140.13.0esr-2~deb13u1 (source) into stable-security (Debian FTP Masters) (signed by: Carsten Schoenert)
  • [2026-08-07] Accepted thunderbird 1:140.13.0esr-2~deb12u1 (source) into oldstable-security (Carsten Schoenert)
  • [2026-08-05] Accepted thunderbird 1:140.13.0esr-2 (source) into unstable (Carsten Schoenert)
  • [2026-08-04] Accepted thunderbird 1:140.13.0esr-1 (source) into unstable (Carsten Schoenert)
  • [2026-08-03] Accepted thunderbird 1:153.0.1esr-1 (source) into experimental (Carsten Schoenert)
  • [2026-06-23] thunderbird 1:140.12.0esr-1 MIGRATED to testing (Debian testing watch)
  • [2026-06-22] Accepted thunderbird 1:152.0-1 (source) into experimental (Carsten Schoenert)
  • [2026-06-19] Accepted thunderbird 1:140.12.0esr-1~deb12u1 (source) into oldstable-proposed-updates (Debian FTP Masters) (signed by: Christoph Goehre)
  • [2026-06-19] Accepted thunderbird 1:140.12.0esr-1~deb13u1 (source) into proposed-updates (Debian FTP Masters) (signed by: Christoph Goehre)
  • [2026-06-18] Accepted thunderbird 1:140.12.0esr-1~deb13u1 (source) into stable-security (Debian FTP Masters) (signed by: Christoph Goehre)
  • 1
  • 2
bugs [bug history graph]
  • all: 340 343
  • RC: 0
  • I&N: 264 266
  • M&W: 76 77
  • F&P: 0
  • patch: 2
links
  • homepage
  • lintian (1, 1)
  • buildd: logs, exp, reproducibility, cross
  • popcon
  • browse source code
  • other distros
  • security tracker
  • screenshots
  • l10n (-, 73)
  • debian patches
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 2:1snap1-0ubuntu5
  • 403 bugs (4 patches)
  • patches for 2:1snap1-0ubuntu5

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing