Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

SUSE MozillaThunderbird Important Memory Safety Fix Advisory 2026-2271-1

suse
Calendar Grey June 5, 2026
Dist Suse Esm H88
Update for Mozilla Thunderbird addresses critical memory safety and use-after-free issues with important severity.
An update that solves 23 vulnerabilities can now be installed.

Summary

## This update for MozillaThunderbird fixes the following issues * Updated to Mozilla Thunderbird 140.11 (bsc#1265212) MFSA 2026-44: * CVE-2026-8090: Use-after-free in the DOM: Networking component. * CVE-2026-8092: Memory safety bugs fixed in Thunderbird ESR 140.10.2 and Thunderbird 150.0.2. * CVE-2026-8094: Other issue in the WebRTC component. MFSA 2026-51: * CVE-2026-8388: Incorrect boundary conditions in the JavaScript Engine: JIT component. * CVE-2026-8391: Other issue in the JavaScript Engine component. * CVE-2026-8401: Sandbox escape in the Profile Backup component. * CVE-2026-8946: Incorrect boundary conditions in the Audio/Video: Web Codecs component. * CVE-2026-8947: Use-after-free in the DOM: Bindings (WebIDL) component.

References

* bsc#1265212

Cross-

* CVE-2026-8090

* CVE-2026-8092

* CVE-2026-8094

* CVE-2026-8388

* CVE-2026-8391

* CVE-2026-8401

* CVE-2026-8946

* CVE-2026-8947

* CVE-2026-8949

* CVE-2026-8950

* CVE-2026-8953

* CVE-2026-8954

* CVE-2026-8955

* CVE-2026-8956

* CVE-2026-8957

* CVE-2026-8958

* CVE-2026-8959

* CVE-2026-8961

* CVE-2026-8962

* CVE-2026-8968

* CVE-2026-8970

* CVE-2026-8974

* CVE-2026-8975

CVSS scores:

* CVE-2026-8090 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

* CVE-2026-8090 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

* CVE-2026-8092 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

* CVE-2026-8092 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

* CVE-2026-8094 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2026:2271-1
Release Date: 2026-06-05T06:37:08Z
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here