-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 15 Sep 2026 18:07:30 -0400 Source: thunderbird Binary: thunderbird thunderbird-dbgsym Architecture: riscv64 Version: 1:140.16.0esr-1~deb13u1 Distribution: trixie-security Urgency: medium Maintainer: riscv64 Build Daemon (rv-osuosl-01) Changed-By: Christoph Goehre Description: thunderbird - mail/news client with RSS, chat and integrated spam filter suppor Changes: thunderbird (1:140.16.0esr-1~deb13u1) trixie-security; urgency=medium . * [fc5c7cf] New upstream version 140.16.0esr Fixed CVE issues in upstream version 140.16 (MFSA 2026-95): CVE-2026-92238: Ambiguous parsing of mail headers CVE-2026-92239: Buffer overrun in IMAP CVE-2026-92240: Out-of-bounds read in IMAP response parser CVE-2026-92005: Use-after-free in the Audio/Video: Web Codecs component CVE-2026-92006: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component CVE-2026-92007: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component CVE-2026-92008: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component CVE-2026-92009: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component CVE-2026-92010: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component CVE-2026-92011: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component CVE-2026-92012: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component CVE-2026-92013: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component CVE-2026-92014: Privilege escalation due to incorrect boundary conditions in the Graphics component CVE-2026-92015: Privilege escalation in the WebExtensions component CVE-2026-92016: Use-after-free in the Disability Access APIs component CVE-2026-92017: Privilege escalation in the DOM: Service Workers component CVE-2026-92018: Sandbox escape in the DOM: Core & HTML component CVE-2026-92019: Mitigation bypass in the Remote Settings Client component CVE-2026-92020: Privilege escalation due to incorrect boundary conditions in the Graphics: WebRender component CVE-2026-92021: Use-after-free in the JavaScript Engine: JIT component CVE-2026-92022: Use-after-free in the DOM: HTML Parser component CVE-2026-92023: Use-after-free in the XML component CVE-2026-92024: Use-after-free in the SVG component CVE-2026-92025: Use-after-free in the DOM: Navigation component CVE-2026-92026: Use-after-free in the Networking component CVE-2026-92027: Use-after-free in the DOM: Streams component CVE-2026-92028: Use-after-free in the DOM: Core & HTML component CVE-2026-92029: Use-after-free in the SVG component CVE-2026-92030: Mitigation bypass in the DOM: Copy & Paste and Drag & Drop component CVE-2026-92031: Information disclosure in the Graphics: ImageLib component CVE-2026-92032: Sandbox escape due to invalid pointer in the Graphics component Checksums-Sha1: 982a0205773ad0a502363178054eaccc5b0211d0 8611668 thunderbird-dbgsym_140.16.0esr-1~deb13u1_riscv64.deb 565d6124ebe70108a295852f02f39ebb26eb0db7 21404 thunderbird_140.16.0esr-1~deb13u1_riscv64-buildd.buildinfo 86388a818f867c6235abb6c7a5fcdde93b06d668 65881772 thunderbird_140.16.0esr-1~deb13u1_riscv64.deb Checksums-Sha256: 91b6d449a7a58a75f065738d7a10ba2be57d88992d57358bdace51d2d546cde7 8611668 thunderbird-dbgsym_140.16.0esr-1~deb13u1_riscv64.deb b7a41bb790871a9016ee84460ef1d316f5dfd202817360b309d422a7879414c9 21404 thunderbird_140.16.0esr-1~deb13u1_riscv64-buildd.buildinfo 41bfd604250ede908dc2c370b4fc2149b26b42876e6aa95ef4e5a12b3ed5eddd 65881772 thunderbird_140.16.0esr-1~deb13u1_riscv64.deb Files: c6876069f29394ba969c30cc97800eb0 8611668 debug optional thunderbird-dbgsym_140.16.0esr-1~deb13u1_riscv64.deb b319f0e2fc85b581be15373eaa5c5a38 21404 mail optional thunderbird_140.16.0esr-1~deb13u1_riscv64-buildd.buildinfo 845bd4e5928b9be0303337cffc5b0814 65881772 mail optional thunderbird_140.16.0esr-1~deb13u1_riscv64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE3smN1vgomTkXJcrkIhSPlPtgqxkFAmqqm8IACgkQIhSPlPtg qxlbUw/+OzCy2EgjSYrOg+umHfFkqBRwpFqFbgWZ01K6Ype2osOb8bICOZqDDZG4 GJ0Ex+J8yiHnXFLNGlt40ShzpRx4A2zQry5jnVWmpoGPYfp51iH5idKy41VaJTBK mEpx+4nfYNYkYwljIeS/2qGJnECldOXGLis1TeQdD6CsS4KhpzYUhJhMjaUm3pMC EhXUP9rAqu3pNnzABm2wnMacoCf9DxEQygLu9jeUcfoF/nAUVj0HOJ4+8Z9RE96I b4wO4Gw+kl2wJCEDLSnJBhdhTxK7rc4QqruTyRYfteiLboaJIOhAmLDd8yttbDhO coZ6qh4Mwb1fJOVWekqutf7Nz/agzaFSeB22g+d/R4lNUdSIeV0mh/6+oeLZX5+X rTlwFWjrF9lGp4MhK9RgooQZrw7TR4Q19uhOZwt2NlyIFeB7M1BWoP9JPXL1wOgW 8AvqsHsafJKaemk0o/v645yDcuf2dHJgrjKILBYw1V8fgKcDxMxG9BjV5w64YBSD giYGnuguDHg0ewK/NyQItEils6MJNvzylXd4KLMXGEEZMRwdtULVg62E9FpXGQpF dGIDZvr/WQYcbcJbF94OHGF1TOdDZ3T7icchKYtKczUNDM3KT8KWnh2rbqgcvJPu bJsSUHt7V/mNNfbRi4hryAjotAiEOwTrabUHbVtl9uzUcgLI8ZQ= =K7mi -----END PGP SIGNATURE-----