Release date:
2026-08-20 10:20:38 UTC
Description:
- update to 153.0.1 ESR (MFSA 2026-71)
- drop six patches made obsolete by 153: P02 firefox-gcc-build (fixed upstream),
P15 build-system-nss + P16 build-tb-system-nss (both patch
third_party/rust/neqo-crypto, a directory 153 no longer has), P19
build-min-lexical, P52 exceptionHandled-for-IO-error-processhandler and P111
av1-else-condition-add (all upstreamed)
- Source404 nss-3.126.0-1.el9.src.rpm is a locally rebranded Fedora artifact
(md5 1fc9b7b02f848fc99e06d5a8680ea5a3), rebuilt from Fedora rawhide dist-git
commit 43cbb021d9886d5abc3d4cb546d022929b9bb1dc (2026-07-29) whose own NVR is
nss-3.126.0-1; there is no public nss-3.126.0-1.el9, so the .el9 disttag
reflects the build target, not an upstream vendor NVR. The EL9-vs-Fedora patch
disposition (Alma c9 carries 29 downstream patches, Fedora 3.126 carries 14) is
tracked as a follow-up; NSS stays private to thunderbird either way
- P103 mozilla-bmo1504834-part1 loses its gfx/2d/Types.h hunk: that hunk rewrote an
`#if MOZ_LITTLE_ENDIAN()/#elif MOZ_BIG_ENDIAN()` block which 153 replaced with
`A8R8G8B8_UINT32 = std::endian::native == std::endian::little ? B8G8R8A8 : A8R8G8B8`,
so it had nothing left to apply; on little-endian that ternary yields B8G8R8A8,
which is what the hunk forced. The surviving DrawTargetSkia.cpp
`kARGBAlphaOffset = 0` is a pre-existing Fedora-inherited override that does NOT
match the upstream little-endian value there (that ternary yields 3), but it sits
inside `#ifdef DEBUG` (gfx/2d/DrawTargetSkia.cpp:154-257) alongside
VerifyRGBXFormat/VerifyRGBXCorners, so it is compiled out of release builds
entirely and has no release impact on any arch
- update bundled cbindgen to 0.29.4; Gecko 153 requires >= 0.29.4 and the
previous bundle provided 0.27.0
- update bundled NSS to 3.126.0 (with NSPR 4.39); Gecko 153 requires nss >= 3.125
and no RHEL/AlmaLinux stream ships one (9.8 still has 3.112). Rebased on the
Fedora nss packaging, which tracks 3.126 with a patch set that applies cleanly;
the RHEL 3.112 patch set does not survive the jump. NSS stays private to
thunderbird under /usr/lib64/thunderbird/bundled as before -- the platform NSS is
untouched. Note Source403 (EL8 path) still carries 3.112.
- fix the unsorted openssl-backend SOURCES list in comm/third_party/rnp/moz.build;
mozbuild requires SOURCES to be appended in sorted order and upstream only
exercises the botan backend, so the bug is invisible to them
- CVE-2026-16364: Incorrect boundary conditions in the Audio/Video: Playback
component
- CVE-2026-16365: Privilege escalation in the DOM: Workers component
- CVE-2026-16366: Privilege escalation in the DOM: Navigation component
- CVE-2026-16367: Sandbox escape due to invalid pointer in the Disability
Access APIs component
- CVE-2026-16370: Mitigation bypass in the DOM: Networking component
- CVE-2026-16372: Privilege escalation in the DOM: Content Processes component
- CVE-2026-16376: Denial-of-service in the Graphics: WebGPU component
- CVE-2026-16378: Other issue in the DOM: Copy & Paste and Drag & Drop
component
- CVE-2026-16380: Mitigation bypass in the Networking component
- CVE-2026-16382: Mitigation bypass in the DOM: Service Workers component
- CVE-2026-16384: Information disclosure due to uninitialized memory in the
Graphics: WebGPU component
- CVE-2026-16385: Information disclosure due to uninitialized memory in the
Graphics: WebGPU component
- CVE-2026-16386: Information disclosure due to uninitialized memory in the
Graphics: WebGPU component
- CVE-2026-16388: Sandbox escape in the DOM: Networking component
- CVE-2026-16389: Incorrect boundary conditions, integer overflow in the
Libraries component in NSS
- CVE-2026-16392: JIT miscompilation in the JavaScript Engine: JIT component
- CVE-2026-16393: Incorrect boundary conditions in the Graphics: WebGPU
component
- CVE-2026-16394: Mitigation bypass in the DOM: Security component
- CVE-2026-16395: Integer overflow in the Audio/Video component
- CVE-2026-16398: Site isolation issue in the Graphics component
- CVE-2026-16399: Site isolation issue in the DOM: Navigation component
- CVE-2026-16400: Information disclosure in the DOM: Security component
- CVE-2026-16401: Privilege escalation in the Data Loss Prevention component
- CVE-2026-16402: Integer overflow in the Graphics: ImageLib component
- CVE-2026-16403: Spoofing issue in the Address Bar component
- CVE-2026-16406: Mitigation bypass in the Networking component
- CVE-2026-16407: Mitigation bypass in the DOM: Service Workers component
- CVE-2026-16408: Integer overflow in the Audio/Video: Playback component
- CVE-2026-16409: Invalid pointer in the Security: PSM component
- CVE-2026-16410: JIT miscompilation in the JavaScript Engine: JIT component
- CVE-2026-16411: Memory safety bugs fixed in Thunderbird 153
Updated packages:
-
thunderbird-153.0.1-1.el9_2.alma.1.tuxcare.els1.x86_64.rpm
sha:a8bf8acc5be2aeebbbe3add152540e30341a2eebe82a753deed4e242145cf1ba
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.