Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package MozillaThunderbird for openSUSE:Factory checked in at 2026-07-23 23:13:56 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/MozillaThunderbird (Old) and /work/SRC/openSUSE:Factory/.MozillaThunderbird.new.2004 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "MozillaThunderbird" Thu Jul 23 23:13:56 2026 rev:391 rq:1367364 version:140.13.0 Changes: -------- --- /work/SRC/openSUSE:Factory/MozillaThunderbird/MozillaThunderbird.changes 2026-07-01 16:39:56.055944954 +0200 +++ /work/SRC/openSUSE:Factory/.MozillaThunderbird.new.2004/MozillaThunderbird.changes 2026-07-23 23:15:49.415829601 +0200 @@ -1,0 +2,99 @@ +Tue Jul 21 13:42:04 UTC 2026 - Wolfgang Rosenauer <[email protected]> + +- Mozilla Thunderbird 140.13.0 ESR + MFSA 2026-72 (bsc#1271649) + * CVE-2026-14899 (bmo#2046137) + Off-by-one out of bounds read in MIME header parser for forwarding + * CVE-2026-15718 (bmo#2045443) + Invalid pointer in the JavaScript: WebAssembly component + * CVE-2026-15719 (bmo#2043820) + Site isolation issue in the DOM: Navigation component + * CVE-2026-16349 (bmo#2034682) + Same-origin policy bypass in the DOM: Navigation component + * CVE-2026-16350 (bmo#2042033) + Incorrect boundary conditions in the Audio/Video: cubeb component + * CVE-2026-16362 (bmo#2043188) + Use-after-free in the WebRTC: Audio/Video component + * CVE-2026-16351 (bmo#2045468) + Sandbox escape due to use-after-free in the DOM: Navigation component + * CVE-2026-16352 (bmo#2046416) + Sandbox escape due to use-after-free in the Disability Access + APIs component + * CVE-2026-16363 (bmo#2047689) + JIT miscompilation in the JavaScript: WebAssembly component + * CVE-2026-16353 (bmo#2049523) + Invalid pointer in the DOM: Bindings (WebIDL) component + * CVE-2026-16354 (bmo#2050626) + Information disclosure in the Graphics: ImageLib component + * CVE-2026-16368 (bmo#2051015) + Incorrect boundary conditions in the JavaScript: WebAssembly component + * CVE-2026-16369 (bmo#2051854) + Integer overflow in the JavaScript: WebAssembly component + * CVE-2026-16355 (bmo#2052207) + JIT miscompilation in the JavaScript Engine: JIT component + * CVE-2026-16356 (bmo#2052562) + Sandbox escape due to use-after-free in the Disability Access + APIs component + * CVE-2026-16357 (bmo#2053326) + Incorrect boundary conditions in the Graphics component + * CVE-2026-16371 (bmo#2008369) + Privilege escalation in the DOM: Navigation component + * CVE-2026-16374 (bmo#2027519) + Information disclosure in the Framework component in DevTools + * CVE-2026-16375 (bmo#2032140) + Site isolation issue in the Networking: HTTP component + * CVE-2026-16377 (bmo#2037770) + Mitigation bypass in the PDF Viewer component + * CVE-2026-16379 (bmo#2039452) + Privilege escalation in the DOM: Content Processes component + * CVE-2026-16358 (bmo#2040119) + Site isolation issue in the Graphics: WebRender component + * CVE-2026-16381 (bmo#2041001) + Same-origin policy bypass in the Networking: DNS component + * CVE-2026-16383 (bmo#2041902) + Mitigation bypass in the DOM: Networking component + * CVE-2026-16387 (bmo#2043200) + Site isolation issue in the Networking component + * CVE-2026-16390 (bmo#2044527) + Mitigation bypass in the Enterprise Policies component + * CVE-2026-16391 (bmo#2044536) + Information disclosure in the Storage: IndexedDB component + * CVE-2026-16359 (bmo#2045424) + Incorrect boundary conditions in the Audio/Video: GMP component + * CVE-2026-16396 (bmo#2047240) + Privilege escalation in WebExtensions + * CVE-2026-16405 (bmo#2036591) + Information disclosure in the Networking: WebSockets component + * CVE-2026-16412 (bmo#2005113, bmo#2025369, bmo#2026301, bmo#2028663, + bmo#2029761, bmo#2042242, bmo#2043035, bmo#2043271, bmo#2043300, + bmo#2044612, bmo#2045057, bmo#2045187, bmo#2045378, bmo#2045402, + bmo#2045406, bmo#2045407, bmo#2045413, bmo#2045417, bmo#2045482, + bmo#2045611, bmo#2045616, bmo#2045618, bmo#2045626, bmo#2045730, + bmo#2045732, bmo#2045756, bmo#2045769, bmo#2045771, bmo#2046917, + bmo#2047718, bmo#2047957, bmo#2048934, bmo#2049818, bmo#2049822, + bmo#2050151, bmo#2050368, bmo#2051653, bmo#2051658, bmo#2053635, + bmo#2053637) + Memory safety bugs fixed in Thunderbird ESR 140.13 and + Thunderbird 153 + * CVE-2026-16360 (bmo#2022635, bmo#2028004, bmo#2035756, bmo#2043739, + bmo#2045184, bmo#2045185, bmo#2045198, bmo#2045281, bmo#2045392, + bmo#2045395, bmo#2045396, bmo#2045397, bmo#2045405, bmo#2045414, + bmo#2045415, bmo#2045451, bmo#2045454, bmo#2045508, bmo#2045510, + bmo#2045513, bmo#2045515, bmo#2045518, bmo#2045604, bmo#2045607, + bmo#2045612, bmo#2045614, bmo#2045617, bmo#2045619, bmo#2045624, + bmo#2045625, bmo#2045729, bmo#2045737, bmo#2045741, bmo#2045742, + bmo#2045744, bmo#2045763, bmo#2045767, bmo#2045770, bmo#2045772, + bmo#2045773, bmo#2045775, bmo#2045783, bmo#2045833, bmo#2045848, + bmo#2045865, bmo#2045875, bmo#2045957, bmo#2047719, bmo#2047723, + bmo#2047729, bmo#2048795, bmo#2048799, bmo#2048801, bmo#2049392, + bmo#2049397, bmo#2049398, bmo#2049399, bmo#2049404, bmo#2049405, + bmo#2049407, bmo#2049805, bmo#2049812, bmo#2050657, bmo#2050668, + bmo#2050990, bmo#2051666, bmo#2053166, bmo#2053273, bmo#2053576, + bmo#2053583, bmo#2053587) + Memory safety bugs fixed in Thunderbird ESR 140.13 and + Thunderbird 153 + * CVE-2026-16361 (bmo#2029734, bmo#2036518) + Memory safety bugs fixed in Thunderbird ESR 140.13 +- require transitional rust-cbindgen-0_29_<F2> package to build + +------------------------------------------------------------------- Old: ---- l10n-140.12.1esr.tar.xz thunderbird-140.12.1esr.source.tar.xz thunderbird-140.12.1esr.source.tar.xz.asc New: ---- l10n-140.13.0esr.tar.xz thunderbird-140.13.0esr.source.tar.xz thunderbird-140.13.0esr.source.tar.xz.asc ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ MozillaThunderbird.spec ++++++ --- /var/tmp/diff_new_pack.67liIZ/_old 2026-07-23 23:16:22.492991266 +0200 +++ /var/tmp/diff_new_pack.67liIZ/_new 2026-07-23 23:16:22.496991407 +0200 @@ -30,8 +30,8 @@ # major 69 # mainver %%major.99 %define major 140 -%define mainver %major.12.1 -%define orig_version 140.12.1 +%define mainver %major.13.0 +%define orig_version 140.13.0 %define orig_suffix esr %define update_channel esr %define source_prefix thunderbird-%{orig_version} @@ -136,7 +136,7 @@ BuildRequires: python3-devel %endif %endif -BuildRequires: rust-cbindgen >= 0.27 +BuildRequires: rust-cbindgen-0_29_2 BuildRequires: translate-suse-desktop BuildRequires: unzip BuildRequires: xorg-x11-libXt-devel ++++++ l10n-140.12.1esr.tar.xz -> l10n-140.13.0esr.tar.xz ++++++ ++++++ tar_stamps ++++++ --- /var/tmp/diff_new_pack.67liIZ/_old 2026-07-23 23:16:22.801002038 +0200 +++ /var/tmp/diff_new_pack.67liIZ/_new 2026-07-23 23:16:22.809002317 +0200 @@ -1,11 +1,11 @@ PRODUCT="thunderbird" CHANNEL="esr140" -VERSION="140.12.1" +VERSION="140.13.0" VERSION_SUFFIX="esr" -REV_VERSION="140.12.0" +REV_VERSION="140.12.1" PREV_VERSION_SUFFIX="esr" #SKIP_LOCALES="" # Uncomment to skip l10n and compare-locales-generation RELEASE_REPO="https://hg.mozilla.org/releases/comm-esr140" -RELEASE_TAG="13d851e90bd757b9432a16a9766610b28bf5c3e1" -RELEASE_TIMESTAMP="20260628021646" +RELEASE_TAG="faf78db7dfb184002adc6b859c8ad395ff216239" +RELEASE_TIMESTAMP="20260721190809" ++++++ thunderbird-140.12.1esr.source.tar.xz -> thunderbird-140.13.0esr.source.tar.xz ++++++ /work/SRC/openSUSE:Factory/MozillaThunderbird/thunderbird-140.12.1esr.source.tar.xz /work/SRC/openSUSE:Factory/.MozillaThunderbird.new.2004/thunderbird-140.13.0esr.source.tar.xz differ: char 15, line 1
