[CLSA-2026:1787115646] thunderbird: Fix of 48 CVEs
Type:
security
Severity:
Critical
Release date:
2026-08-20 10:20:38 UTC
Description:
- update to 153.0.1 ESR (MFSA 2026-71) - drop six patches made obsolete by 153: P02 firefox-gcc-build (fixed upstream), P15 build-system-nss + P16 build-tb-system-nss (both patch third_party/rust/neqo-crypto, a directory 153 no longer has), P19 build-min-lexical, P52 exceptionHandled-for-IO-error-processhandler and P111 av1-else-condition-add (all upstreamed) - Source404 nss-3.126.0-1.el9.src.rpm is a locally rebranded Fedora artifact (md5 1fc9b7b02f848fc99e06d5a8680ea5a3), rebuilt from Fedora rawhide dist-git commit 43cbb021d9886d5abc3d4cb546d022929b9bb1dc (2026-07-29) whose own NVR is nss-3.126.0-1; there is no public nss-3.126.0-1.el9, so the .el9 disttag reflects the build target, not an upstream vendor NVR. The EL9-vs-Fedora patch disposition (Alma c9 carries 29 downstream patches, Fedora 3.126 carries 14) is tracked as a follow-up; NSS stays private to thunderbird either way - P103 mozilla-bmo1504834-part1 loses its gfx/2d/Types.h hunk: that hunk rewrote an `#if MOZ_LITTLE_ENDIAN()/#elif MOZ_BIG_ENDIAN()` block which 153 replaced with `A8R8G8B8_UINT32 = std::endian::native == std::endian::little ? B8G8R8A8 : A8R8G8B8`, so it had nothing left to apply; on little-endian that ternary yields B8G8R8A8, which is what the hunk forced. The surviving DrawTargetSkia.cpp `kARGBAlphaOffset = 0` is a pre-existing Fedora-inherited override that does NOT match the upstream little-endian value there (that ternary yields 3), but it sits inside `#ifdef DEBUG` (gfx/2d/DrawTargetSkia.cpp:154-257) alongside VerifyRGBXFormat/VerifyRGBXCorners, so it is compiled out of release builds entirely and has no release impact on any arch - update bundled cbindgen to 0.29.4; Gecko 153 requires >= 0.29.4 and the previous bundle provided 0.27.0 - update bundled NSS to 3.126.0 (with NSPR 4.39); Gecko 153 requires nss >= 3.125 and no RHEL/AlmaLinux stream ships one (9.8 still has 3.112). Rebased on the Fedora nss packaging, which tracks 3.126 with a patch set that applies cleanly; the RHEL 3.112 patch set does not survive the jump. NSS stays private to thunderbird under /usr/lib64/thunderbird/bundled as before -- the platform NSS is untouched. Note Source403 (EL8 path) still carries 3.112. - fix the unsorted openssl-backend SOURCES list in comm/third_party/rnp/moz.build; mozbuild requires SOURCES to be appended in sorted order and upstream only exercises the botan backend, so the bug is invisible to them - CVE-2026-16364: Incorrect boundary conditions in the Audio/Video: Playback component - CVE-2026-16365: Privilege escalation in the DOM: Workers component - CVE-2026-16366: Privilege escalation in the DOM: Navigation component - CVE-2026-16367: Sandbox escape due to invalid pointer in the Disability Access APIs component - CVE-2026-16370: Mitigation bypass in the DOM: Networking component - CVE-2026-16372: Privilege escalation in the DOM: Content Processes component - CVE-2026-16376: Denial-of-service in the Graphics: WebGPU component - CVE-2026-16378: Other issue in the DOM: Copy & Paste and Drag & Drop component - CVE-2026-16380: Mitigation bypass in the Networking component - CVE-2026-16382: Mitigation bypass in the DOM: Service Workers component - CVE-2026-16384: Information disclosure due to uninitialized memory in the Graphics: WebGPU component - CVE-2026-16385: Information disclosure due to uninitialized memory in the Graphics: WebGPU component - CVE-2026-16386: Information disclosure due to uninitialized memory in the Graphics: WebGPU component - CVE-2026-16388: Sandbox escape in the DOM: Networking component - CVE-2026-16389: Incorrect boundary conditions, integer overflow in the Libraries component in NSS - CVE-2026-16392: JIT miscompilation in the JavaScript Engine: JIT component - CVE-2026-16393: Incorrect boundary conditions in the Graphics: WebGPU component - CVE-2026-16394: Mitigation bypass in the DOM: Security component - CVE-2026-16395: Integer overflow in the Audio/Video component - CVE-2026-16398: Site isolation issue in the Graphics component - CVE-2026-16399: Site isolation issue in the DOM: Navigation component - CVE-2026-16400: Information disclosure in the DOM: Security component - CVE-2026-16401: Privilege escalation in the Data Loss Prevention component - CVE-2026-16402: Integer overflow in the Graphics: ImageLib component - CVE-2026-16403: Spoofing issue in the Address Bar component - CVE-2026-16406: Mitigation bypass in the Networking component - CVE-2026-16407: Mitigation bypass in the DOM: Service Workers component - CVE-2026-16408: Integer overflow in the Audio/Video: Playback component - CVE-2026-16409: Invalid pointer in the Security: PSM component - CVE-2026-16410: JIT miscompilation in the JavaScript Engine: JIT component - CVE-2026-16411: Memory safety bugs fixed in Thunderbird 153
Updated packages:
  • thunderbird-153.0.1-1.el9_2.alma.1.tuxcare.els1.x86_64.rpm
    sha:a8bf8acc5be2aeebbbe3add152540e30341a2eebe82a753deed4e242145cf1ba
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.