-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 16 Sep 2026 16:41:34 +0200 Source: thunderbird Architecture: source Version: 1:153.3.0esr-1 Distribution: unstable Urgency: medium Maintainer: Carsten Schoenert <[email protected]> Changed-By: Carsten Schoenert <[email protected]> Changes: thunderbird (1:153.3.0esr-1) unstable; urgency=medium . [ Christoph Goehre ] * [4340b21] d/control: re-Adding s390x architecture . [ Carsten Schoenert ] * [c7926a8] New upstream version 153.3.0esr Fixed CVE issues in upstream version 153.3 (MFSA 2026-93): CVE-2026-92005: Use-after-free in the Audio/Video: Web Codecs component CVE-2026-92006: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component CVE-2026-92007: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component CVE-2026-92008: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component CVE-2026-92009: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component CVE-2026-92010: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component CVE-2026-92011: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component CVE-2026-92012: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component CVE-2026-92013: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component CVE-2026-92015: Privilege escalation in the WebExtensions component CVE-2026-92035: Sandbox escape due to incorrect boundary conditions in the Graphics component CVE-2026-92016: Use-after-free in the Disability Access APIs component CVE-2026-92017: Privilege escalation in the DOM: Service Workers component CVE-2026-92018: Sandbox escape in the DOM: Core & HTML component CVE-2026-92019: Mitigation bypass in the Remote Settings Client component CVE-2026-92020: Privilege escalation due to incorrect boundary conditions in the Graphics: WebRender component CVE-2026-92022: Use-after-free in the DOM: HTML Parser component CVE-2026-92023: Use-after-free in the XML component CVE-2026-92024: Use-after-free in the SVG component CVE-2026-92025: Use-after-free in the DOM: Navigation component CVE-2026-92026: Use-after-free in the Networking component CVE-2026-92027: Use-after-free in the DOM: Streams component CVE-2026-92028: Use-after-free in the DOM: Core & HTML component CVE-2026-92029: Use-after-free in the SVG component CVE-2026-92038: Mitigation bypass in the Remote Settings Client component CVE-2026-92039: Mitigation bypass in the DOM: Notifications component CVE-2026-92041: Mitigation bypass in the DOM: Networking component CVE-2026-92042: Race condition in the DOM: Content Processes component CVE-2026-92043: Privilege escalation due to incorrect boundary conditions in the Audio/Video component CVE-2026-92044: Information disclosure in the Networking: HTTP component CVE-2026-92045: Sandbox escape due to incorrect boundary conditions in the WebRTC component CVE-2026-92030: Mitigation bypass in the DOM: Copy & Paste and Drag & Drop component CVE-2026-92046: Use-after-free in the Graphics component CVE-2026-92047: Privilege escalation in the Crash Reporting component CVE-2026-92048: Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component CVE-2026-92049: Use-after-free in the Widget: Win32 component CVE-2026-92052: Privilege escalation due to uninitialized memory in the Graphics: CanvasWebGL component CVE-2026-92053: Privilege escalation in the Graphics: CanvasWebGL component CVE-2026-92054: Privilege escalation in the Memory component CVE-2026-92055: Privilege escalation in the DevTools component CVE-2026-92056: Use-after-free in the Graphics: Text component CVE-2026-92057: Mitigation bypass in the Enterprise Policies component CVE-2026-92031: Information disclosure in the Graphics: ImageLib component CVE-2026-92032: Sandbox escape due to invalid pointer in the Graphics component CVE-2026-92058: Use-after-free in the Graphics component CVE-2026-92059: Incorrect boundary conditions in the DOM: Editor component CVE-2026-92060: Use-after-free in the Internationalization component CVE-2026-92062: Privilege escalation in the Session Restore component CVE-2026-92064: Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component CVE-2026-92065: Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component CVE-2026-92067: Use-after-free in the Widget: Gtk component CVE-2026-92068: Site isolation issue in the Reader Mode component CVE-2026-92069: Spoofing issue in the DOM: Navigation component CVE-2026-92070: Information disclosure in the Networking component CVE-2026-92071: Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component CVE-2026-92072: Incorrect boundary conditions in the Safe Browsing component CVE-2026-92073: Privilege escalation in the Enterprise Policies component CVE-2026-92074: Mitigation bypass in the Popup Blocker component CVE-2026-92075: Mitigation bypass in the Networking component CVE-2026-92076: Incorrect boundary conditions in the Networking component CVE-2026-92077: Denial-of-service in the SVG component CVE-2026-92078: Denial-of-service in the Security component CVE-2026-92079: Mitigation bypass in the Widget: Win32 component * [724bd8a] d/thunderbird.lintian-overrides: Drop override about bzip2 * [2d39531] d/copyright: Fix misspelled word thunderbird-l10n Checksums-Sha1: bb163cd671cce660275b003e527c6e0a87b2cce8 8467 thunderbird_153.3.0esr-1.dsc 895ce456782e29d9ef3edf2123ef8bcf8035b199 12832576 thunderbird_153.3.0esr.orig-thunderbird-l10n.tar.xz 800a296e75e0568af7190810e0437c6ae837f37b 903565728 thunderbird_153.3.0esr.orig.tar.xz 8d263b20caabd33d5721b06028b75d83f5d1ebb2 556556 thunderbird_153.3.0esr-1.debian.tar.xz 672dde3f35a3f19ed15f7ae34b2eac970210a75f 41011 thunderbird_153.3.0esr-1_amd64.buildinfo Checksums-Sha256: 0f4023b891544380afaf0c0196c0c7e189664e4cf1f0d9c90a9c8f53284480bf 8467 thunderbird_153.3.0esr-1.dsc eca895eb471d200cb52c4a4fb0302ad9604e9d93f354599589958dcd9e91a4eb 12832576 thunderbird_153.3.0esr.orig-thunderbird-l10n.tar.xz e0cdd0a3feec2dfc530f50fdc48db522f1299bdf1a37c1a29631b581c2c5cc11 903565728 thunderbird_153.3.0esr.orig.tar.xz 35f1d9e99301cd8d6792e9bc283f83310609349809e8e0132d3752d38f5f55e1 556556 thunderbird_153.3.0esr-1.debian.tar.xz 73f3886d80058fc4b3d47f77e827102879f05154df544370251ffbc3fd8f7b89 41011 thunderbird_153.3.0esr-1_amd64.buildinfo Files: 058f80696ddded73eff0b6442fb65100 8467 mail optional thunderbird_153.3.0esr-1.dsc 0166f2f697b2d642cb05603fa49cf655 12832576 mail optional thunderbird_153.3.0esr.orig-thunderbird-l10n.tar.xz 549c099e9f834a7c44d806a1a2a0da34 903565728 mail optional thunderbird_153.3.0esr.orig.tar.xz ee55ab062e190c7b0ed29ea98b775c9c 556556 mail optional thunderbird_153.3.0esr-1.debian.tar.xz 491470efe6701da8e9961b6183dc45ee 41011 mail optional thunderbird_153.3.0esr-1_amd64.buildinfo
-----BEGIN PGP SIGNATURE----- iQJMBAEBCgA2FiEEtw38bxNP7PwBHmKqgwFgFCUdHbAFAmqrlRkYHGMuc2Nob2Vu ZXJ0QHQtb25saW5lLmRlAAoJEIMBYBQlHR2w9jwP/0LKCkOKwLYO8x5Bxx240fSv N7JdhaHq9Up1K5Wta1vCwSS60zeAg4PeCs1IPkYjuv7DBemr2LtSDGL13+U/MbRX bZWM7EHkGJM7dj/YA+xJo+P0LJvi76BMWS+Gv0s0H2oO4FMEsmPRST8xLu8EAvEx 9st6IPdLdfbo5JoNJoLUR4XC/TMKEkTBFAa5hXo0Hje+TVFKyFZyBKhdGbfBzxVh /cHDbyODUcIailXG7jMr0StIRojfj5fjW14BHPGZhVVHYxOB6bKnPh+iwa7Pfu3o 5s46Qh+57XQ5KriX41x+cHncm73IUf4Orju1UmyGXuEsWwLyMWIJ1wrxGfHVHa4N Xoq532MmuGsSd166VCaMBLh45YBWEer3VNByYc09YAB+DPJglxNY6CFh1mX7jhzN L3QGc5gJIDa6YroBP1ArZbgKudsb2618Pe/pAu/xJgbyjnNsB61wbYtEV8NU/WJR qziO5zRNhOYK1Kb7y+Au66PSmQ9lW6O4Ma/ZhpFq/j++60VRM2+eSVLWmoG80GI7 fPJ6zpkiaAQzynrgBnFhL8wS+IMJzct0St0HuCw+OpB33gKMBm8a2QsFaALi3mNB wP8n2EwafAqQxC3Vw5yXnrckG8r6y9N46iaoAw2pYjGbx9bTSBqm0UH8hjCHVEEB NNLYYCLKoOu9yprBb0Zt =i1PY -----END PGP SIGNATURE-----
pgpfgK43Dbb6a.pgp
Description: PGP signature

