-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 19 Aug 2026 19:55:34 +0200 Source: thunderbird Architecture: source Version: 1:153.1.0esr-1 Distribution: experimental Urgency: medium Maintainer: Carsten Schoenert <[email protected]> Changed-By: Carsten Schoenert <[email protected]> Changes: thunderbird (1:153.1.0esr-1) experimental; urgency=medium . * [91f5ed9] New upstream version 153.1.0esr Fixed CVE issues in upstream version 153.1 (MFSA 2026-80): CVE-2026-74934: Site isolation issue in the Graphics: CanvasWebGL component CVE-2026-74935: Privilege escalation in the DOM: Networking component CVE-2026-74936: Use-after-free in the JavaScript: WebAssembly component CVE-2026-74937: Use-after-free in the JavaScript: GC component CVE-2026-74938: Mitigation bypass in the JavaScript: GC component CVE-2026-74939: Privilege escalation in the DOM: Navigation component CVE-2026-74940: Use-after-free in the Graphics: Text component CVE-2026-74941: Privilege escalation in the Graphics: CanvasWebGL component CVE-2026-74942: Privilege escalation in the Remote Settings Client component CVE-2026-74943: Use-after-free in the Graphics: ImageLib component CVE-2026-74944: Use-after-free in the DOM: Core & HTML component CVE-2026-74945: Information disclosure in the Graphics: Text component CVE-2026-74946: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component CVE-2026-74947: Privilege escalation due to invalid pointer in the Graphics component CVE-2026-74948: Information disclosure in the Graphics component CVE-2026-74949: Privilege escalation due to use-after-free in the Graphics: Canvas2D component CVE-2026-74950: Privilege escalation in the Downloads API component CVE-2026-74953: Privilege escalation in the Networking: Cookies component CVE-2026-74954: Information disclosure due to side-channel in the Storage: Cache API component CVE-2026-74955: Privilege escalation in the Request Handling component CVE-2026-74956: Same-origin policy bypass in the DOM: Service Workers component CVE-2026-74957: Mitigation bypass in the Safe Browsing component CVE-2026-74958: Information disclosure in the WebRTC component CVE-2026-74959: Mitigation bypass in the Storage: Cache API component CVE-2026-74960: Site isolation issue in the WebExtensions component CVE-2026-74961: Side-channel in the Web Audio component CVE-2026-74962: Site isolation issue in the Networking: Cookies component CVE-2026-74963: Same-origin policy bypass in the Networking: Cookies component CVE-2026-74964: Integer overflow in the Graphics component CVE-2026-74965: Privilege escalation in the Shell Integration component CVE-2026-74966: Information disclosure in the Form Autofill component CVE-2026-74967: Same-origin policy bypass in the Audio/Video: Playback component CVE-2026-74968: Site isolation issue in the Graphics: WebRender component CVE-2026-74969: Use-after-free in the Layout: Text and Fonts component CVE-2026-74970: Site isolation issue in the Graphics component CVE-2026-74971: Information disclosure in the DOM: UI Events & Focus Handling component CVE-2026-74972: Information disclosure in the DOM: Push Subscriptions component CVE-2026-74973: Race condition, use-after-free in the Graphics component CVE-2026-74974: Same-origin policy bypass in the Graphics: ImageLib component CVE-2026-74976: JIT miscompilation in the JavaScript Engine: JIT component CVE-2026-74977: Integer overflow in the Graphics component CVE-2026-74978: Clickjacking issue in the Widget component CVE-2026-74979: Mitigation bypass in the Add-ons Manager component CVE-2026-74981: Site isolation issue in the Audio/Video: Web Codecs component CVE-2026-74982: Denial-of-service in the Widget component CVE-2026-74983: Mitigation bypass in the Data Loss Prevention component CVE-2026-74984: Race condition in the JavaScript Engine component CVE-2026-74985: Privilege escalation in the Enterprise Policies component CVE-2026-74986: Site isolation issue in the CSS Parsing and Computation component CVE-2026-74987: Internally found bugs fixed in Thunderbird ESR 140.14, Thunderbird ESR 153.1 and Thunderbird 154 CVE-2026-74988: Internally found bugs fixed in Thunderbird ESR 153.1 and Thunderbird 154 CVE-2026-74990: Internally found bugs fixed in Thunderbird ESR 140.14, Thunderbird ESR 153.1 and Thunderbird 154 * [792af83] Rebuild patch queue from patch-queue branch Removed patches: porting-armel/Avoid-using-vmrs-vmsr-on-armel.patch porting/Disable-optimization-on-alpha-for-the-url-classifier.patch We don't build packages for armel and alpha any more for some time, time to drop the patches now too. Checksums-Sha1: 3eab7d81cd1424719ea088ddb8fd20a972b6cefd 8452 thunderbird_153.1.0esr-1.dsc 384db38566b9397f92123bbaccb75c569ac8631c 12805028 thunderbird_153.1.0esr.orig-thunderbird-l10n.tar.xz 90c825d337f7c04ff7f27b81616f3d73404d477c 904462536 thunderbird_153.1.0esr.orig.tar.xz fdce232440db36222a01ac868f400611de1cab44 538668 thunderbird_153.1.0esr-1.debian.tar.xz b2f4db6406d92823f115a57b6e263c10447486c4 41149 thunderbird_153.1.0esr-1_amd64.buildinfo Checksums-Sha256: 4852804420a94ae0fcc80ebab1972fcd5f82285a86e3e3cdddad1c63f97224dd 8452 thunderbird_153.1.0esr-1.dsc 0cfc9677417cbaa8d97874e644a6cf93e813de3ab64480fe1995d11ecbd70464 12805028 thunderbird_153.1.0esr.orig-thunderbird-l10n.tar.xz 167f032f51858b1ff1076245175813983d4b3ee3bd77514d11a201a730da0485 904462536 thunderbird_153.1.0esr.orig.tar.xz 0390c5a3b1fd2a1947814f919487d50c2f5dc0e179e980f281828a7d930bad14 538668 thunderbird_153.1.0esr-1.debian.tar.xz d5f065fdc2fa67adf5d01e2367b6b277ee700516f3b91b43b02c1fa73d8a1541 41149 thunderbird_153.1.0esr-1_amd64.buildinfo Files: 58fd33f5ed541ea78887a6777144e5da 8452 mail optional thunderbird_153.1.0esr-1.dsc 367b1cfaad6e6df6802727d43f15dd5d 12805028 mail optional thunderbird_153.1.0esr.orig-thunderbird-l10n.tar.xz c3ff262578844189608ff267da9b1700 904462536 mail optional thunderbird_153.1.0esr.orig.tar.xz 358fe9c3fc0e2171421462b8fd7e4dd6 538668 mail optional thunderbird_153.1.0esr-1.debian.tar.xz 34dfdb904e2385745af642b5b331b759 41149 mail optional thunderbird_153.1.0esr-1_amd64.buildinfo
-----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEtw38bxNP7PwBHmKqgwFgFCUdHbAFAmqGATAACgkQgwFgFCUd HbAhdQ//SK/kdW2ZzGTFiDWDPs7m88rZjpQP+7OOSJ5+gQCFmMpv+PbE5CYAqWR+ zJK8qIxSFfHQHwA6zfYJ/8eUP7FNXtOgaKmyeKxhpb/jdGpb9++zywSMxRl4UNUu URmmAwBS62zCxVtlCbXFSGxS2MmGj0l/4TdiINGE1eO1J+KzxHYrQR7iZqo+mQz3 w1eshQ1t+ytCKybrnMA0ksnAYf6IVdQoR9LUlkK5krpsv7Zn8Z75FkqR9DEGeF0D 2d9/Tg48xc6MXMxtx/kSzNXXOM1nTi9d867gmiwxHiqA4nKmfEK6l0pd4N7f1Qlm sf9A6Q0B0wFBQgM/1K36J2SN6n8WAHWyEkbrOyXDW7xwGGhVDSYHTxzAHlnlNVA9 e4agNVdxo6tA2JjgOVlqcwctaZOgAdBx/BvngoWlvTmvSSe3D8bvBYcygsLICbqO /jIEjgGhaKWVI6UDO0+ZB90lSyBTIpUZqar4R0gDXJgEKDix85+t/nAcitFozTqu 3Td+DRYVXdfYZb9F4Ful+BErH0GSljFbCoDOI04JmbLP9G921bTApzzeSp0GwFZl f0SNey4GJwm4VRE3bDTvkhoMyppeai7pmMtolVeiZjoMMTkDUdX5AcOG63lBSPym ftlINzwc+mCk+VAdB3EKz2UhnkOq4JoxCnUcCzoVUIiSgkos/QY= =4B6d -----END PGP SIGNATURE-----
pgpSe_7dMcJox.pgp
Description: PGP signature
