RHSA-2026:49621: Important: thunderbird security update
Important: thunderbird security update
Other sources
Mozilla Thunderbird is a standalone mail and newsgroup client.Security Fix(es): firefox: thunderbird: Site isolation issue in the DOM: Navigation component (CVE-2026-15719) firefox: thunderbird: Invalid pointer in the JavaScript: WebAssembly component (CVE-2026-15718) firefox: thunderbird: Mitigation bypass in the Enterprise Policies component (CVE-2026-16390) firefox: thunderbird: Incorrect boundary conditions in the Audio/Video: cubeb component (CVE-2026-16350) firefox: thunderbird: Information disclosure in the Storage: IndexedDB component (CVE-2026-16391) firefox: thunderbird: Site isolation issue in the Networking: HTTP component (CVE-2026-16375) firefox: thunderbird: Sandbox escape due to use-after-free in the Disability Access APIs component (CVE-2026-16356) firefox: thunderbird: JIT miscompilation in the JavaScript: WebAssembly component (CVE-2026-16363) firefox: thunderbird: Memory safety bugs fixed in Firefox ESR 140.13 and Firefox 153 (CVE-2026-16412) firefox: thunderbird: Same-origin policy bypass in the Networking: DNS component (CVE-2026-16381) firefox: thunderbird: JIT miscompilation in the JavaScript Engine: JIT component (CVE-2026-16355) firefox: thunderbird: Memory safety bugs fixed in Firefox ESR 115.38 and Firefox ESR 140.13 (CVE-2026-16361) firefox: thunderbird: Sandbox escape due to use-after-free in the Disability Access APIs component (CVE-2026-16352) firefox: thunderbird: Incorrect boundary conditions in the JavaScript: WebAssembly component (CVE-2026-16368) firefox: thunderbird: Mitigation bypass in the PDF Viewer component (CVE-2026-16377) firefox: thunderbird: Memory safety bugs fixed in Firefox ESR 115.38, Firefox ESR 140.13 and Firefox 153 (CVE-2026-16360) firefox: thunderbird: Use-after-free in the WebRTC: Audio/Video component (CVE-2026-16362) firefox: thunderbird: Site isolation issue in the Graphics: WebRender component (CVE-2026-16358) firefox: thunderbird: Site isolation issue in the Networking component (CVE-2026-16387) firefox: thunderbird: Same-origin policy bypass in the DOM: Navigation component (CVE-2026-16349) firefox: thunderbird: Incorrect boundary conditions in the Graphics component (CVE-2026-16357) firefox: thunderbird: Sandbox escape due to use-after-free in the DOM: Navigation component (CVE-2026-16351) firefox: thunderbird: Privilege escalation in the DOM: Navigation component (CVE-2026-16371) firefox: thunderbird: Privilege escalation in the DOM: Content Processes component (CVE-2026-16379) firefox: thunderbird: Information disclosure in the Graphics: ImageLib component (CVE-2026-16354) firefox: thunderbird: Information disclosure in the Framework component in DevTools (CVE-2026-16374) firefox: thunderbird: Incorrect boundary conditions in the Audio/Video: GMP component (CVE-2026-16359) firefox: thunderbird: Mitigation bypass in the DOM: Networking component (CVE-2026-16383) firefox: thunderbird: Integer overflow in the JavaScript: WebAssembly component (CVE-2026-16369) firefox: thunderbird: Invalid pointer in the DOM: Bindings (WebIDL) component (CVE-2026-16353) firefox: thunderbird: Privilege escalation in WebExtensions (CVE-2026-16396) firefox: thunderbird: Information disclosure in the Networking: WebSockets component (CVE-2026-16405) thunderbird: Off-by-one out of bounds read in MIME header parser for forwarding (CVE-2026-14899) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/thunderbirdto a version that resolves this vulnerability.Fixed in 140.13.0-1.el10_2 - Upgrade
Upgrade
redhat/thunderbird-debuginfoto a version that resolves this vulnerability.Fixed in 140.13.0-1.el10_2 - Upgrade
Upgrade
redhat/thunderbird-debugsourceto a version that resolves this vulnerability.Fixed in 140.13.0-1.el10_2 - Upgrade
Upgrade
redhat/thunderbirdto a version that resolves this vulnerability.Fixed in 140.13.0-1.el10_2.aa - Upgrade
Upgrade
redhat/thunderbird-debuginfoto a version that resolves this vulnerability.Fixed in 140.13.0-1.el10_2.aa - Upgrade
Upgrade
redhat/thunderbird-debugsourceto a version that resolves this vulnerability.Fixed in 140.13.0-1.el10_2.aa - Upgrade
Upgrade
Firefox ESR 115.38to a version that resolves this vulnerability.Fixed in 115.38 - Upgrade
Upgrade
Firefox ESR 140.13to a version that resolves this vulnerability.Fixed in 140.13 - Upgrade
Upgrade
Firefox 153to a version that resolves this vulnerability.Fixed in 153 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch CVE-2026-16361 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch CVE-2026-16360 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch CVE-2026-16412 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch CVE-2026-15719 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch CVE-2026-15718 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch CVE-2026-14899 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch CVE-2026-16383
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:49621?
The severity of RHSA-2026:49621 is high with a score of 7.
What vulnerabilities are addressed in RHSA-2026:49621?
RHSA-2026:49621 addresses a site isolation issue in the DOM and an invalid pointer in the JavaScript: WebAssembly component.
How do I fix RHSA-2026:49621?
To fix RHSA-2026:49621, you should update your Thunderbird software to the latest version provided in the security update.
Which software versions are affected by RHSA-2026:49621?
RHSA-2026:49621 affects several Red Hat Enterprise Linux packages for architectures including Power, IBM z Systems, and x86_64.
What types of issues does RHSA-2026:49621 mitigate?
RHSA-2026:49621 mitigates issues related to Integer Overflow and Use After Free conditions.