CVE-2026-12329: Memory safety bug fixed in Thunderbird ESR 140.12
Memory safety bug fixed in Thunderbird ESR 140.12. This vulnerability was fixed in Firefox ESR 140.12 and Thunderbird 140.12.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 140.12 - Upgrade
Upgrade
Firefox ESRto a version that resolves this vulnerability.Fixed in 140.12 - Upgrade
Upgrade
Thunderbird ESRto a version that resolves this vulnerability.Fixed in 140.12
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2026-12289
- CVE-2026-12290
- CVE-2026-12291
- CVE-2026-12292
- CVE-2026-12294
- CVE-2026-12295
- CVE-2026-12298
- CVE-2026-12296
- CVE-2026-12297
- CVE-2026-12299
- CVE-2026-12329
- CVE-2026-12302
- CVE-2026-12304
- CVE-2026-12305
- CVE-2026-12306
- CVE-2026-12307
- CVE-2026-12308
- CVE-2026-12309
- CVE-2026-12310
- CVE-2026-12311
- CVE-2026-12312
- CVE-2026-12313
- CVE-2026-12314
- CVE-2026-12315
- CVE-2026-12330
- CVE-2026-12324
- CVE-2026-12325
- CVE-2026-12327
- CVE-2026-12328
Frequently Asked Questions
What is the severity of CVE-2026-12329?
CVE-2026-12329 has a medium severity rating of 5.3.
What types of vulnerabilities are associated with CVE-2026-12329?
CVE-2026-12329 is associated with buffer overflow, use after free, and null pointer dereference vulnerabilities.
How do I fix CVE-2026-12329?
To fix CVE-2026-12329, update to Thunderbird ESR 140.12 or Firefox ESR 140.12.
When was CVE-2026-12329 published?
CVE-2026-12329 was published on June 16, 2026.
What software is affected by CVE-2026-12329?
CVE-2026-12329 affects Mozilla Thunderbird and Mozilla Firefox ESR.