SUSE-SU-2026:4268-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-20264268-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4268-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/SUSE-SU-2026:4268-1
Upstream
CVE (143)
  • CVE-2024-34703
  • CVE-2026-14899
  • CVE-2026-16349
  • CVE-2026-16350
  • CVE-2026-16351
  • CVE-2026-16352
  • CVE-2026-16353
  • CVE-2026-16354
  • CVE-2026-16355
  • CVE-2026-16356
  • CVE-2026-16357
  • CVE-2026-16358
  • CVE-2026-16359
  • CVE-2026-16360
  • CVE-2026-16362
  • CVE-2026-16363
  • CVE-2026-16364
  • CVE-2026-16365
  • CVE-2026-16366
  • CVE-2026-16367
  • CVE-2026-16368
  • CVE-2026-16369
  • CVE-2026-16370
  • CVE-2026-16371
  • CVE-2026-16372
  • CVE-2026-16374
  • CVE-2026-16375
  • CVE-2026-16376
  • CVE-2026-16377
  • CVE-2026-16378
  • CVE-2026-16379
  • CVE-2026-16380
  • CVE-2026-16381
  • CVE-2026-16382
  • CVE-2026-16383
  • CVE-2026-16384
  • CVE-2026-16385
  • CVE-2026-16386
  • CVE-2026-16387
  • CVE-2026-16388
  • CVE-2026-16389
  • CVE-2026-16390
  • CVE-2026-16391
  • CVE-2026-16392
  • CVE-2026-16393
  • CVE-2026-16394
  • CVE-2026-16395
  • CVE-2026-16396
  • CVE-2026-16398
  • CVE-2026-16399
  • CVE-2026-16400
  • CVE-2026-16401
  • CVE-2026-16402
  • CVE-2026-16403
  • CVE-2026-16405
  • CVE-2026-16406
  • CVE-2026-16407
  • CVE-2026-16408
  • CVE-2026-16409
  • CVE-2026-16410
  • CVE-2026-16411
  • CVE-2026-16412
  • CVE-2026-74934
  • CVE-2026-74935
  • CVE-2026-74936
  • CVE-2026-74937
  • CVE-2026-74938
  • CVE-2026-74939
  • CVE-2026-74940
  • CVE-2026-74941
  • CVE-2026-74942
  • CVE-2026-74943
  • CVE-2026-74944
  • CVE-2026-74945
  • CVE-2026-74946
  • CVE-2026-74947
  • CVE-2026-74948
  • CVE-2026-74949
  • CVE-2026-74950
  • CVE-2026-74952
  • CVE-2026-74953
  • CVE-2026-74954
  • CVE-2026-74955
  • CVE-2026-74956
  • CVE-2026-74957
  • CVE-2026-74958
  • CVE-2026-74959
  • CVE-2026-74960
  • CVE-2026-74961
  • CVE-2026-74962
  • CVE-2026-74963
  • CVE-2026-74964
  • CVE-2026-74965
  • CVE-2026-74966
  • CVE-2026-74967
  • CVE-2026-74968
  • CVE-2026-74969
  • CVE-2026-74970
  • CVE-2026-74971
  • CVE-2026-74972
  • CVE-2026-74973
  • CVE-2026-74974
  • CVE-2026-74976
  • CVE-2026-74977
  • CVE-2026-74978
  • CVE-2026-74979
  • CVE-2026-74981
  • CVE-2026-74982
  • CVE-2026-74983
  • CVE-2026-74984
  • CVE-2026-74985
  • CVE-2026-74986
  • CVE-2026-74987
  • CVE-2026-74988
  • CVE-2026-74990
  • CVE-2026-75874
  • CVE-2026-84118
  • CVE-2026-84119
  • CVE-2026-84120
  • CVE-2026-84121
  • CVE-2026-84122
  • CVE-2026-84123
  • CVE-2026-84124
  • CVE-2026-84125
  • CVE-2026-84129
  • CVE-2026-84130
  • CVE-2026-84131
  • CVE-2026-84132
  • CVE-2026-84133
  • CVE-2026-84134
  • CVE-2026-84136
  • CVE-2026-84137
  • CVE-2026-84139
  • CVE-2026-84140
  • CVE-2026-84141
  • CVE-2026-84143
  • CVE-2026-84144
  • CVE-2026-84145
  • CVE-2026-84637
  • CVE-2026-84639
  • CVE-2026-84640
  • CVE-2026-84641
  • CVE-2026-84642
Related
Published
2026-09-18T14:51:02Z
Modified
2026-09-19T09:00:03Z
Summary
Security update for MozillaThunderbird
Details

This update for MozillaThunderbird fixes the following issues:

Mozilla Thunderbird 153.2:

  • fixed: Deleting an Exchange account retained the outgoing server settings
  • fixed: Thunderbird upgrade disabled Settings menu for versions before macOS 13
  • fixed: Windows jump list menu no longer functioned correctly
  • fixed: Security fixes MFSA 2026-88 (bsc#1278001):
  • CVE-2026-84639 Uninitialized memory in MIME parsing
  • CVE-2026-84640 One byte overflow read in mail parser
  • CVE-2026-84641 Information disclosure due to malicious IMAP server response
  • CVE-2026-84637 Calendar invitation attachments could launch local executables
  • CVE-2026-84642 Allowed UNC hostnames for attachments interpreted as a regular expression
  • CVE-2026-75874 Sandbox escape in the Remote Settings Client component
  • CVE-2026-84118 Use-after-free in the JavaScript: GC component
  • CVE-2026-84119 Sandbox escape due to use-after-free in the DOM: Navigation component
  • CVE-2026-84120 Use-after-free in the Audio/Video component
  • CVE-2026-84121 Sandbox escape due to use-after-free in the DOM: Security component
  • CVE-2026-84122 Use-after-free in the Audio/Video component
  • CVE-2026-84123 Privilege escalation due to use-after-free in the Graphics: WebGPU component
  • CVE-2026-84124 Use-after-free in the DOM: Core & HTML component
  • CVE-2026-84125 Use-after-free in the DOM: Core & HTML component
  • CVE-2026-74952 Privilege escalation in the Application Update component
  • CVE-2026-84129 Site isolation issue in the DOM: Navigation component
  • CVE-2026-84130 Information disclosure in the Graphics: WebGPU component
  • CVE-2026-84131 Privilege escalation due to invalid pointer in the Graphics component
  • CVE-2026-84132 Information disclosure in the Networking: HTTP component
  • CVE-2026-84133 Site isolation issue in the DOM: Push Subscriptions component
  • CVE-2026-84134 Other issue in the Profile Backup component
  • CVE-2026-84136 Other issue in the DOM: Navigation component
  • CVE-2026-84137 Spoofing issue in the DOM: Core & HTML component
  • CVE-2026-84139 Clickjacking issue in the DOM: Events component
  • CVE-2026-84140 Site isolation issue in the DOM: Navigation component
  • CVE-2026-84141 Integer overflow in the Graphics: ImageLib component
  • CVE-2026-84143 Internally found bugs fixed in Thunderbird 155, Thunderbird ESR 153.2 and Thunderbird ESR 140.15
  • CVE-2026-84144 Internally found bugs fixed in Thunderbird 155 and Thunderbird ESR 153.2
  • CVE-2026-84145 Internally found bugs fixed in Thunderbird 155, Thunderbird ESR 153.2 and Thunderbird ESR 140.15
  • Mozilla Thunderbird 153.1.1

    • fixed: Thunderbird upgrade disabled composition toolbar
    • fixed: Draft was not preserved when encrypted message send failed
    • fixed: Account Hub prompted for calendar credentials after successful login
    • fixed: Thunderbird crash fixes
    • fixed: Folder compaction showed incorrect disk space recovery estimates
    • fixed: Thunderbird failed to launch GPU process
  • Mozilla Thunderbird 153.1

    • fixed: Autoscroll icon was missing directional arrows in scrollable messages
    • fixed: Security fixes MFSA 2026-80 (bsc#1274867):
    • CVE-2026-74934 Site isolation issue in the Graphics: CanvasWebGL component
    • CVE-2026-74935 Privilege escalation in the DOM: Networking component
    • CVE-2026-74936 Use-after-free in the JavaScript: WebAssembly component
    • CVE-2026-74937 Use-after-free in the JavaScript: GC component
    • CVE-2026-74938 Mitigation bypass in the JavaScript: GC component
    • CVE-2026-74939 Privilege escalation in the DOM: Navigation component
    • CVE-2026-74940 Use-after-free in the Graphics: Text component
    • CVE-2026-74941 Privilege escalation in the Graphics: CanvasWebGL component
    • CVE-2026-74942 Privilege escalation in the Remote Settings Client component
    • CVE-2026-74943 Use-after-free in the Graphics: ImageLib component
    • CVE-2026-74944 Use-after-free in the DOM: Core & HTML component
    • CVE-2026-74945 Information disclosure in the Graphics: Text component
    • CVE-2026-74946 Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component
    • CVE-2026-74947 Privilege escalation due to invalid pointer in the Graphics component
    • CVE-2026-74948 Information disclosure in the Graphics component
    • CVE-2026-74949 Privilege escalation due to use-after-free in the Graphics: Canvas2D component
    • CVE-2026-74950 Privilege escalation in the Downloads API component
    • CVE-2026-74953 Privilege escalation in the Networking: Cookies component
    • CVE-2026-74954 Information disclosure due to side-channel in the Storage: Cache API component
    • CVE-2026-74955 Privilege escalation in the Request Handling component
    • CVE-2026-74956 Same-origin policy bypass in the DOM: Service Workers component
    • CVE-2026-74957 Mitigation bypass in the Safe Browsing component
    • CVE-2026-74958 Information disclosure in the WebRTC component
    • CVE-2026-74959 Mitigation bypass in the Storage: Cache API component
    • CVE-2026-74960 Site isolation issue in the WebExtensions component
    • CVE-2026-74961 Side-channel in the Web Audio component
    • CVE-2026-74962 Site isolation issue in the Networking: Cookies component
    • CVE-2026-74963 Same-origin policy bypass in the Networking: Cookies component
    • CVE-2026-74964 Integer overflow in the Graphics component
    • CVE-2026-74965 Privilege escalation in the Shell Integration component
    • CVE-2026-74966 Information disclosure in the Form Autofill component
    • CVE-2026-74967 Same-origin policy bypass in the Audio/Video: Playback component
    • CVE-2026-74968 Site isolation issue in the Graphics: WebRender component
    • CVE-2026-74969 Use-after-free in the Layout: Text and Fonts component
    • CVE-2026-74970 Site isolation issue in the Graphics component
    • CVE-2026-74971 Information disclosure in the DOM: UI Events & Focus Handling component
    • CVE-2026-74972 Information disclosure in the DOM: Push Subscriptions component
    • CVE-2026-74973 Race condition, use-after-free in the Graphics component
    • CVE-2026-74974 Same-origin policy bypass in the Graphics: ImageLib component
    • CVE-2026-74976 JIT miscompilation in the JavaScript Engine: JIT component
    • CVE-2026-74977 Integer overflow in the Graphics component
    • CVE-2026-74978 Clickjacking issue in the Widget component
    • CVE-2026-74979 Mitigation bypass in the Add-ons Manager component
    • CVE-2026-74981 Site isolation issue in the Audio/Video: Web Codecs component
    • CVE-2026-74982 Denial-of-service in the Widget component
    • CVE-2026-74983 Mitigation bypass in the Data Loss Prevention component
    • CVE-2026-74984 Race condition in the JavaScript Engine component
    • CVE-2026-74985 Privilege escalation in the Enterprise Policies component
    • CVE-2026-74986 Site isolation issue in the CSS Parsing and Computation component
    • CVE-2026-74987 Internally found bugs fixed in Thunderbird ESR 140.14, Thunderbird ESR 153.1 and Thunderbird 154
    • CVE-2026-74988 Internally found bugs fixed in Thunderbird ESR 153.1 and Thunderbird 154
    • CVE-2026-74990 Internally found bugs fixed in Thunderbird ESR 140.14, Thunderbird ESR 153.1 and Thunderbird 154
  • Mozilla Thunderbird 153.0.3

    • fixed: Dragging attachments from Local Folders to the desktop failed on Windows
    • fixed: IMAP tags did not sync automatically across clients
    • fixed: DisablePasswordReveal policy failed to prevent revealing saved passwords
    • fixed: Thunderbird could crash when saving a sent Exchange message
  • Mozilla Thunderbird 153.0.2

    • changed: Restored previous Yahoo sign-in flow to improve login reliability
    • fixed: Edit Calendar dialog opened without a window title
    • fixed: Thunderbird could crash when going offline with active IMAP connection
  • Mozilla Thunderbird 153.0.1

    • changed: There are no Thunderbird changes requiring release notes in this release
  • Mozilla Thunderbird 153

    MFSA 2026-71 (bsc#1271649):

    • new: Visual signatures can be added to PDF attachments opened in Thunderbird
    • new: 'Copy Message Link' and 'Copy News Link' added to header pane 'More actions'
    • new: Accessiblity is improved in various tree views
    • new: Added 'Archive' action to mail notifications
    • new: Add 'Show Full Path' folder pane option for compact view modes
    • new: Unified folders now display account color indicator with account name tooltip
    • new: Folder copy enabled within mail server accounts and local folders
    • new: 'Reset Folder Order' option added to folder pane to reset custom folder sorting
    • new: Add `mail.useLocalizedFolderNames' to toggle special folder name localization
    • new: 'Favorites' added as destination for 'Move To' and 'File' buttons
    • new: Composer now shows a warning if user's configured OpenPGP key expires soon
    • new: Enabled configuration of preferred OpenPGP keyserver via the UI
    • new: Add mail.openpgp.load_untested_gpgme_version to load untested GPGME version
    • new: Added support for generating Unobtrusive Signatures (OpenPGP)
    • new: Implemented option to show only messages without any tag
    • new: Message body search enabled for OpenPGP and S/MIME encrypted messages
    • new: SecurityDevices enabled in enterprise policies
    • new: Enable support for DNS over HTTPS
    • new: OAuth login for mail accounts now opens in default web browser
    • new: Thundermail services can now be used without installing an add-on
    • new: OAuth responses now verify issuer fields and reject missing required issuers
    • new: Enable the 'Sign in with Thundermail' button in Account Hub
    • new: Account hub is opened on the first run of Thunderbird
    • new: Account Hub email manual config option added
    • new: Enable Thundermail OAuth sign-in with account auto- configuration
    • new: Address book cards can be copied to the clipboard as vCard
    • new: Enable exporting selected address book cards
    • new: Custom Accent Color can be chosen in Appearance Settings
    • new: Enable support for Microsoft Exchange via Exchange Web Services
    • new: Calendar month/multiweek views are now scrollable with touch screen
    • new: Tasks can be sorted by created or modified date
    • new: PDF pages can be reorganized directly in the PDF viewer
    • changed: 'Copy Message Location' removed from mail context menu
    • changed: Read folders are now removed from Unread Folders view
    • changed: Special folders are now localized based on a restricted set of names
    • changed: OpenPGP public key no longer attached by default in signed-only messages
    • changed: Address books are now created in Account Hub
    • changed: Yahoo, AT&T, AOL accounts migrated to OAuth 2.0 with PKCE for improved security
    • changed: GMail OAuth updated to use PKCE
    • changed: Skype has been retired and therefore dropped from Address book IM selection
    • changed: Removed pref default_supports_diskspace.{HOST}
    • changed: Removed pref default_offline_support_level.{HOST}
    • changed: Removed Odnoklassniki chat setup and directed users to XMPP configuration
    • changed: Use of the string 'Junk' has been replaced with 'Spam'
    • changed: Updated about:rights to replace local with hosted url
    • changed: Stop shipping 32-bit Linux x86 binaries
    • changed: 'Hide completed tasks' now also hides cancelled tasks
    • changed: Stop shipping 32-bit Linux x86 binaries
    • fixed: Thunderbird could crash when parsing message state
    • fixed: The English string for the Angry emoji was incorrectly named as the Yell emoji
    • fixed: Notification sounds did not respect operating system's do-not-disturb mode
    • fixed: Non-English localized Thunderbird created English special folders on first start
    • fixed: Copying text from some error alerts was not possible
    • fixed: Fastmail CalDAV app password access failed due to forced OAuth regression
    • fixed: Thunderbird could crash in server subscription logic
    • fixed: Could not distinguish folders with same name in 'Recent Destinations' and 'Favorites'
    • fixed: Donation banner stole focus when Thunderbird was running in the background
    • fixed: Unknown command-line arguments passed to Thunderbird did not print warning
    • fixed: Thunderbird could crash when processing new incoming messages
    • fixed: Spam messages triggered new mail notifications before being moved to Spam folder
    • fixed: Web pages with bad certificates displayed as blank
    • fixed: Memory leak after opening New Window from folder pane context menu
    • fixed: Importing a vCard only displayed VCF files in the file picker
    • fixed: Calendar view tabs were not properly keyboard accessible
    • fixed: Ctrl+S did not save PDF attachments opened in Thunderbird tabs
    • fixed: TLS errors incorrectly reported all unknown failures as untrusted certificates
    • fixed: Thunderbird could crash when copying an empty list of messages
    • fixed: Incorrect roaming data directory caused regression on Windows and macOS
    • fixed: Changing to new drafts folder and then back did not correctly restore the folder
    • fixed: Message headers were re-downloaded at every startup
    • fixed: Old IMAP profile migration deleted INBOX and other mailbox files
    • fixed: 'Search Messages...' dialog could not be opened outside the email tab
    • fixed: Option did not exist to create new address book under File -> New
    • fixed: Newly created folder was missing under 'Recent' when moving a message
    • fixed: Could not compose new message if the folder pane was empty
    • fixed: 'Delete' was missing from context menu when multiple IMAP folders were selected
    • fixed: Compacting multiple folders failed and did not compact
    • fixed: Shift-click for 'Edit' button in drafts header view did not work
    • fixed: 'Replace All' in Compose did not update plain text until dialog closed
    • fixed: Status bar messages displayed unlocalized folder names or IMAP mailbox names
    • fixed: Saved email filenames were not not always cross- platform safe
    • fixed: Space bar did not scroll in PDF attachments opened from emails
    • fixed: Folder location widget used non-localised name
    • fixed: Empty confirmation dialog when more messages opened in tabs than mailnews.open_tab_warning
    • fixed: Removing tags from IMAP messages could fail and tags reappeared after refresh
    • fixed: Toggling dark message mode did not restore focus and scroll position
    • fixed: 'Show remote content' did not display remote content for EML message
    • fixed: Emoji sequences were not properly handled in subject lines
    • fixed: 'Delete' button in unified toolbar could delete attachments instead of message
    • fixed: 'Repair text encoding' could duplicate recipient and attachments
    • fixed: Some IMAP emails showed current time instead of correct received date
    • fixed: Deleting a single message in folder using 'Group by Sort' failed after CTRL+A
    • fixed: New newsgroups were not added in alphabetical order by default
    • fixed: Sorting by threads only brought threads with unread top messages to the top
    • fixed: News message marked read after NNTP error prevented retrieval from server
    • fixed: 'Recent destinations' submenu was not sorted by time of modification
    • fixed: Account column could display incorrect account name
    • fixed: 'Tag' submenu of mail context menu could be populated incorrectly
    • fixed: Unified archive subfolders could show wrong names and no messages
    • fixed: Moving saved search/virtual folder under IMAP could fail
    • fixed: New Folder dialog allowed invalid folder creation without a selected parent folder
    • fixed: New/unread messages in collapsed thread were not obvious enough
    • fixed: Pressing Delete on Trash folder could remove it without confirmation
    • fixed: Renaming of a 'unified folder' created a duplicate
    • fixed: Clicking on a folder in the folder pane did not always open folder
    • fixed: Messages nested deeper than 255 levels disappeared from threading view
    • fixed: Performing Delete followed by Undo on thread parent message could corrupt view
    • fixed: Single messages still appeared collapsible after thread members were deleted
    • fixed: Updated threads remained misordered until folder refresh or resort
    • fixed: Global search failed to display inaccessible messages found in local folders
    • fixed: Numeric subfolders were sorted alphabetically instead of naturally
    • fixed: Virtual folder folder-picker showed unlabeled IM account as selectable folder
    • fixed: Some folders showed new mail count prior to receiving mail
    • fixed: Menu Bar -> View contained duplicate accelerator keys
    • fixed: Unified toolbar Spam button did not switch to 'Not Spam' when spam message selected
    • fixed: Warning was not logged if mail.openpgp.alias_rules_file file did not exist
    • fixed: Not all headers were signed when creating digitally signed OpenPGP email
    • fixed: When configuring external GnuPG, user was not promted to import public key
    • fixed: 'Open and Show' for OpenPGP-signed message (.eml) did not work
    • fixed: Invalidly signed unencrypted emails were indicated as worse than unsigned ones
    • fixed: Reason for revoked certificate was not shown
    • fixed: Apple Mail OpenPGP emails failed to decrypt due to hidden recipient key ID
    • fixed: OpenPGP import of public key with experimental packets failed with unclear error
    • fixed: Opening messages with OpenPGP keys was slow and blocked the UI for large keyrings
    • fixed: OpenPGP key refresh failed when fingerprint lookup returned multiple results
    • fixed: Encrypted Gmail CSE emails with outer opaque S/MIME were not readable
    • fixed: Invalid S/MIME encryption certificate caused misleading send errors
    • fixed: 'Search Messages' search did not finish due to unparsable local folders
    • fixed: Search results showed older irrelevant emails before newer exact matches
    • fixed: Filter search on Body missed draft messages containing German umlauts
    • fixed: Esc cleared quick filter pin after changing folder
    • fixed: Thunderbird could crash during local message search
    • fixed: Replying could fail with mailnews.reply_quoting_selection.multi_word set false
    • fixed: Drag-drop of unselected contact inserted wrong or no email address
    • fixed: Changing identity in compose window caused modified draft not to be saved
    • fixed: Shift-click 'Compose Message To' on 'mailto' link did not open in plain text
    • fixed: Reply with selected text lost formatting for HTML messages containing </pre>
    • fixed: Multipart/related attachments were not preserved when editing or forwarding
    • fixed: Forwarded malformed MIME email had empty body and extra attachment
    • fixed: Message compose window was removed from Task Bar after saving as draft or template
    • fixed: Dragging email address between compose windows failed to add recipients
    • fixed: Thunderbird could crash when using Find and Replace All
    • fixed: Compose with PDF attachments opened PDFs instead of creating a new email
    • fixed: Multiple saves while using 'Options' -> 'Send a Copy' resulted in multiple copies
    • fixed: Search for 'Attachment' in Settings menu did not find 'Files and Attachments'
    • fixed: Add-on account creation did not work with Account Hub
    • fixed: Owl install did not show link to website in Account Hub
    • fixed: Username field did not appear in Account Hub when exchange authentication failed
    • fixed: Account Hub advanced config setup did not include default outgoing config
    • fixed: Disabled inputs could be toggled in Account Hub address book
    • fixed: Users could not disable spinning overlay in Account Hub for email
    • fixed: Account Hub local address book creation could continue with blank name
    • fixed: Account Hub email success messages were not always accurate about config source
    • fixed: Calendar/address book sections were shown in Account Hub when there were none
    • fixed: New password-based Exchange accounts failed to save passwords in login manager
    • fixed: Account hub showed connection security instead of actual authentication method
    • fixed: New identity dialog lacked reply-matching and end-to- end encryption settings
    • fixed: Thunderbird could fail to shut down cleanly during active OAuth requests
    • fixed: Account Hub kept OAuth selected after changing to hostname without OAuth support
    • fixed: Account Hub autodetect wrongly prompted for a password when auth was unavailable
    • fixed: Interrupted external OAuth2 setup required restarting Thunderbird
    • fixed: The default account could be reset after restart if uninitialized
    • fixed: Virtual folders did not update correctly for filtered POP3 messages
    • fixed: 'Copy Message to' action in a newsgroup filter did not work
    • fixed: Thunderbird could crash while importing mail thread
    • fixed: Thunderbird did not clearly fail when importing profile from a bad source
    • fixed: Thunderbird could not import profile located at the top level of zip file
    • fixed: 'Any Number' was unavailable in address book search with 'Match all of the following'
    • fixed: Contact not found in Advanced Address Book Search if phone number had a period
    • fixed: Thunderbird did not display contact photos in WebP format from CardDAV servers
    • fixed: Opening a vCard (.vcf) from file manager or CLI did not work in some cases
    • fixed: Redirected CardDAV URLs resolved relative URLs against the wrong host
    • fixed: Installations from Microsoft Store did not open when clicking 'mailto:' links
    • fixed: Windows new message notification click did not bring Thunderbird to foreground
    • fixed: Microsoft Store installs did not open when clicking 'news://' link or .eml file
    • fixed: Using thunderbird -compose with double quotes made last email address invalid
    • fixed: Clicking the backspace icon in the quick filter field cleared the input field
    • fixed: Subfolder kept stale accessibility unread count after unread messages were deleted
    • fixed: Moving virtual folder within maildir based IMAP or local folder could fail
    • fixed: Thunderbird could crash when completing folder copy/move
    • fixed: 'Edit as New Message' and inline 'Forward' not possible with PGP-signed messages
    • fixed: Various MIME improvements
    • fixed: Forwarding some Apple Mail messages incorrectly attached inline text as a file
    • fixed: Thunderbird could crash when marking all messages as read
    • fixed: Auto-compaction could corrupt database and cause crashes during syncs
    • fixed: 'news:' URIs without specific server had incorrect format displayed in status bar
    • fixed: 'Mark' -> 'All Read' affected newsgroup messages that had not been fetched yet
    • fixed: Thunderbird could not reconnect to newsgroups after connection loss until restarted
    • fixed: Sending a newsgroup post appeared successful when it had actually failed
    • fixed: Saving a new draft retained superceded version
    • fixed: Thunderbird hung when auto-checking multiple accounts for new messages
    • fixed: Spam not checked with mail.server.default.check_all_folders_for_new on
    • fixed: Startup could be slow with large number of folders not using subscriptions
    • fixed: Saved search in unified folder resulted in server error
    • fixed: Thunderbird did not report refused POP3 connection
    • fixed: Remove message body retention policy was not functional
    • fixed: POP3 could stop downloading mail until restart
    • fixed: With auto-mark-read disabled, large mail still marked as read during load delay
    • fixed: IMAP 'Show only subscribed folders' could not be changed without restart
    • fixed: POP3 deadlocked when server went silent without closing socket
    • fixed: Thunderbird could crash when mail folder was renamed or moved
    • fixed: NNTP server with invalid TLS certificate could not be added to certificate exceptions
    • fixed: Cancelled message send could not be retried and hung with SMTP timeout errors
    • fixed: Corrupted NNTP account data caused excessive memory use and startup crash
    • fixed: Multiple selected IMAP folders could not be moved or deleted together
    • fixed: Non-Latin IMAP keywords were lowercased and encoded incorrectly as MUTF-7
    • fixed: Message tags were lost when moving folder from local folder to IMAP folder
    • fixed: Removing a chat account threw an exception and failed to clear the UI
    • fixed: Enterprise policy use not indicated in about:preferences with link to about:policies
    • fixed: Language field in settings was empty after restart in Troubleshoot Mode
    • fixed: Primary Password policy was detected but not enforced for saved account passwords
    • fixed: Archived RSS feed messages were sent to the archive folder of default identity
    • fixed: Broken feed icon could prevent updating of feeds
    • fixed: Task reminders could fail for tasks without end dates or with shifted due dates
    • fixed: Calendar did not alert user for connection issues
    • fixed: Copying one recurring event occurrence failed to set the date when pasted
    • fixed: Could not copy an event in multiweek or month view by drag-and-drop
    • fixed: Duplicate attendees were added to invitations instead of being filtered out
    • fixed: Calendar discovery with certificate error displayed multiple exceptions
    • fixed: It was not possible to create date-only all-day tasks
    • fixed: Task percentage complete was not preserved separately from status in tooltips
    • fixed: Calendar invites were incorrectly marked processed after calendar sync completed
    • fixed: ICS event comments were not displayed in Thunderbird event details
    • fixed: Dismissed Gmail calendar reminder did nothing and item stayed visible
    • fixed: iCal imports misread unknown timezones as GMT, creating events at wrong times
    • fixed: Could not export local calendar as HTML
    • fixed: Cancelled filter edit dialog closed the message filter dialog
    • fixed: Visual and UX improvements
    • CVE-2026-14899 Off-by-one out of bounds read in MIME header parser for forwarding
    • CVE-2026-16349 Same-origin policy bypass in the DOM: Navigation component
    • CVE-2026-16350 Incorrect boundary conditions in the Audio/Video: cubeb component
    • CVE-2026-16362 Use-after-free in the WebRTC: Audio/Video component
    • CVE-2026-16351 Sandbox escape due to use-after-free in the DOM: Navigation component
    • CVE-2026-16352 Sandbox escape due to use-after-free in the Disability Access APIs component
    • CVE-2026-16363 JIT miscompilation in the JavaScript: WebAssembly component
    • CVE-2026-16364 Incorrect boundary conditions in the Audio/Video: Playback component
    • CVE-2026-16365 Privilege escalation in the DOM: Workers component
    • CVE-2026-16366 Privilege escalation in the DOM: Navigation component
    • CVE-2026-16353 Invalid pointer in the DOM: Bindings (WebIDL) component
    • CVE-2026-16354 Information disclosure in the Graphics: ImageLib component
    • CVE-2026-16367 Sandbox escape due to invalid pointer in the Disability Access APIs component
    • CVE-2026-16368 Incorrect boundary conditions in the JavaScript: WebAssembly component
    • CVE-2026-16369 Integer overflow in the JavaScript: WebAssembly component
    • CVE-2026-16355 JIT miscompilation in the JavaScript Engine: JIT component
    • CVE-2026-16356 Sandbox escape due to use-after-free in the Disability Access APIs component
    • CVE-2026-16357 Incorrect boundary conditions in the Graphics component
    • CVE-2026-16370 Mitigation bypass in the DOM: Networking component
    • CVE-2026-16371 Privilege escalation in the DOM: Navigation component
    • CVE-2026-16372 Privilege escalation in the DOM: Content Processes component
    • CVE-2026-16374 Information disclosure in the Framework component in DevTools
    • CVE-2026-16375 Site isolation issue in the Networking: HTTP component
    • CVE-2026-16376 Denial-of-service in the Graphics: WebGPU component
    • CVE-2026-16377 Mitigation bypass in the PDF Viewer component
    • CVE-2026-16378 Other issue in the DOM: Copy & Paste and Drag & Drop component
    • CVE-2026-16379 Privilege escalation in the DOM: Content Processes component
    • CVE-2026-16358 Site isolation issue in the Graphics: WebRender component
    • CVE-2026-16380 Mitigation bypass in the Networking component
    • CVE-2026-16381 Same-origin policy bypass in the Networking: DNS component
    • CVE-2026-16382 Mitigation bypass in the DOM: Service Workers component
    • CVE-2026-16383 Mitigation bypass in the DOM: Networking component
    • CVE-2026-16384 Information disclosure due to uninitialized memory in the Graphics: WebGPU component
    • CVE-2026-16385 Information disclosure due to uninitialized memory in the Graphics: WebGPU component
    • CVE-2026-16386 Information disclosure due to uninitialized memory in the Graphics: WebGPU component
    • CVE-2026-16387 Site isolation issue in the Networking component
    • CVE-2026-16388 Sandbox escape in the DOM: Networking component
    • CVE-2026-16389 Incorrect boundary conditions, integer overflow in the Libraries component in NSS
    • CVE-2026-16390 Mitigation bypass in the Enterprise Policies component
    • CVE-2026-16391 Information disclosure in the Storage: IndexedDB component
    • CVE-2026-16392 JIT miscompilation in the JavaScript Engine: JIT component
    • CVE-2026-16393 Incorrect boundary conditions in the Graphics: WebGPU component
    • CVE-2026-16359 Incorrect boundary conditions in the Audio/Video: GMP component
    • CVE-2026-16394 Mitigation bypass in the DOM: Security component
    • CVE-2026-16395 Integer overflow in the Audio/Video component
    • CVE-2026-16396 Privilege escalation in WebExtensions
    • CVE-2026-16398 Site isolation issue in the Graphics component
    • CVE-2026-16399 Site isolation issue in the DOM: Navigation component
    • CVE-2026-16400 Information disclosure in the DOM: Security component
    • CVE-2026-16401 Privilege escalation in the Data Loss Prevention component
    • CVE-2026-16402 Integer overflow in the Graphics: ImageLib component
    • CVE-2026-16403 Spoofing issue in the Address Bar component
    • CVE-2026-16405 Information disclosure in the Networking: WebSockets component
    • CVE-2026-16406 Mitigation bypass in the Networking component
    • CVE-2026-16407 Mitigation bypass in the DOM: Service Workers component
    • CVE-2026-16408 Integer overflow in the Audio/Video: Playback component
    • CVE-2026-16409 Invalid pointer in the Security: PSM component
    • CVE-2026-16410 JIT miscompilation in the JavaScript Engine: JIT component
    • CVE-2026-16411 Memory safety bugs fixed in Thunderbird 153
    • CVE-2026-16412 Memory safety bugs fixed in Thunderbird ESR 140.13 and Thunderbird 153
    • CVE-2026-16360 Memory safety bugs fixed in Thunderbird ESR 140.13 and Thunderbird 153
References

Affected packages

SUSE:Linux Enterprise Module for Package Hub 15 SP7
MozillaThunderbird

Package

Name
MozillaThunderbird
Purl
pkg:rpm/suse/MozillaThunderbird&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
153.2.0-150400.13.3.1

Ecosystem specific

{
    "binaries":  [
        {
            "MozillaThunderbird":  "153.2.0-150400.13.3.1",
            "MozillaThunderbird-translations-common":  "153.2.0-150400.13.3.1",
            "MozillaThunderbird-translations-other":  "153.2.0-150400.13.3.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4268-1.json"
SUSE:Linux Enterprise Workstation Extension 15 SP7
MozillaThunderbird

Package

Name
MozillaThunderbird
Purl
pkg:rpm/suse/MozillaThunderbird&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2015%20SP7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
153.2.0-150400.13.3.1

Ecosystem specific

{
    "binaries":  [
        {
            "MozillaThunderbird":  "153.2.0-150400.13.3.1",
            "MozillaThunderbird-translations-common":  "153.2.0-150400.13.3.1",
            "MozillaThunderbird-translations-other":  "153.2.0-150400.13.3.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4268-1.json"