-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 15 Sep 2026 18:07:30 -0400 Source: thunderbird Binary: thunderbird thunderbird-dbgsym Architecture: amd64 Version: 1:140.16.0esr-1~deb13u1 Distribution: trixie-security Urgency: medium Maintainer: amd64 / i386 Build Daemon (x86-ubc-01) Changed-By: Christoph Goehre Description: thunderbird - mail/news client with RSS, chat and integrated spam filter suppor Changes: thunderbird (1:140.16.0esr-1~deb13u1) trixie-security; urgency=medium . * [fc5c7cf] New upstream version 140.16.0esr Fixed CVE issues in upstream version 140.16 (MFSA 2026-95): CVE-2026-92238: Ambiguous parsing of mail headers CVE-2026-92239: Buffer overrun in IMAP CVE-2026-92240: Out-of-bounds read in IMAP response parser CVE-2026-92005: Use-after-free in the Audio/Video: Web Codecs component CVE-2026-92006: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component CVE-2026-92007: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component CVE-2026-92008: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component CVE-2026-92009: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component CVE-2026-92010: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component CVE-2026-92011: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component CVE-2026-92012: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component CVE-2026-92013: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component CVE-2026-92014: Privilege escalation due to incorrect boundary conditions in the Graphics component CVE-2026-92015: Privilege escalation in the WebExtensions component CVE-2026-92016: Use-after-free in the Disability Access APIs component CVE-2026-92017: Privilege escalation in the DOM: Service Workers component CVE-2026-92018: Sandbox escape in the DOM: Core & HTML component CVE-2026-92019: Mitigation bypass in the Remote Settings Client component CVE-2026-92020: Privilege escalation due to incorrect boundary conditions in the Graphics: WebRender component CVE-2026-92021: Use-after-free in the JavaScript Engine: JIT component CVE-2026-92022: Use-after-free in the DOM: HTML Parser component CVE-2026-92023: Use-after-free in the XML component CVE-2026-92024: Use-after-free in the SVG component CVE-2026-92025: Use-after-free in the DOM: Navigation component CVE-2026-92026: Use-after-free in the Networking component CVE-2026-92027: Use-after-free in the DOM: Streams component CVE-2026-92028: Use-after-free in the DOM: Core & HTML component CVE-2026-92029: Use-after-free in the SVG component CVE-2026-92030: Mitigation bypass in the DOM: Copy & Paste and Drag & Drop component CVE-2026-92031: Information disclosure in the Graphics: ImageLib component CVE-2026-92032: Sandbox escape due to invalid pointer in the Graphics component Checksums-Sha1: 6fc2580b6a9b9f4990ec2843c52acb251151e4c6 531471428 thunderbird-dbgsym_140.16.0esr-1~deb13u1_amd64.deb 5c8ba02696e66987808b2ce91332c3d4ac4b9250 21440 thunderbird_140.16.0esr-1~deb13u1_amd64-buildd.buildinfo 9933c6c1596912c3a61d1189e841d98c37d8d42e 70240840 thunderbird_140.16.0esr-1~deb13u1_amd64.deb Checksums-Sha256: f1d6de54c0aea1ecb82571e5d05edf1af5f395478dc154977b58248ec73ad466 531471428 thunderbird-dbgsym_140.16.0esr-1~deb13u1_amd64.deb 35f9fdade6a3133f7a71d9e5822edf35eabc8fc5bd65988dc370aa54660168f0 21440 thunderbird_140.16.0esr-1~deb13u1_amd64-buildd.buildinfo 04fad2b1c2187513fe70535765c2bdeaab9f5c7d0e60f82426b595533576a70f 70240840 thunderbird_140.16.0esr-1~deb13u1_amd64.deb Files: 0251986f54912280955ac1cb1bbe0e93 531471428 debug optional thunderbird-dbgsym_140.16.0esr-1~deb13u1_amd64.deb 82d891757510102f8fd93f00e8a70550 21440 mail optional thunderbird_140.16.0esr-1~deb13u1_amd64-buildd.buildinfo 9b8e9341b7b0eea69d260065b00d0806 70240840 mail optional thunderbird_140.16.0esr-1~deb13u1_amd64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEmtr4KUMaso2EQ6NrTwt/65ON6zcFAmqp640ACgkQTwt/65ON 6zfHFQ/+KnuhmDq1DVz7bs/vJBwQWhPcnieQt1/hQXvCLw8K9NYsc0HWgHYniFw/ yyXQCl8J0x4hq3R2JgZOCyNhBSI0MS+hieO7Z+NDHE/8SvzvOr3684rDC9kSznRI tJW48ZDR2RhikS22CZ0KQW4ftvnQenOPC8pvSCjALN/TISh05r+ip4cSFNAP9CBb WoiXbHDYvfstjATlrgQQlcVLUO3cdy6YBtr4RjLNfdmDd3HcKolAFgTqtwxcJ4SM tPfFGsBc6Yi0k7uj053NX5riaYw1J6hAsadAeF6A0gL8s1OX9Y1Wu48wTfz+5N9f dRMVKKlY4fTkSnBLvrnRbFyK68q21VxAVS8in1oP7OFLdd91dOU9zWZHMfEEHpaR Dus24ImJLNfWidEeX7yH3QHYmF61yJP/Ci93AqfaaqgMuba5DvFFywPkGA1u5F9Q S2eJJUIploD1kpX0shFAHlF3ULYeZ5fNmgySAsZvkidPa7dCL2jD/DHEA/5zNVBK k/WUnH9Qc9CWRWXHUTpWMze7JLB+o4IOI9wb1iBoIEgfQ6IIsWzcYx2LU/uCyHCL hC5rqmd9dpkpyIy7KkOJI1UjpnqHY2uMSttCbrBUA7r1vlt6q8TytsOXW6B+xiqv +apExBKWpk8CY35/vSEGs7+E5x4LqrX05c4ikrbi+vhumi9zH0k= =eJEU -----END PGP SIGNATURE-----