We believe that the bug you reported is fixed in the latest version of
thunderbird, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 949649@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Carsten Schoenert <c.schoenert@t-online.de> (supplier of updated thunderbird package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Tue, 01 Sep 2026 19:03:49 +0200
Source: thunderbird
Architecture: source
Version: 1:153.2.0esr-1
Distribution: unstable
Urgency: medium
Maintainer: Carsten Schoenert <c.schoenert@t-online.de>
Changed-By: Carsten Schoenert <c.schoenert@t-online.de>
Closes: 880424 882218 883245 900210 909281 914403 917613 928178 949450 949649 955380 961269 1127710 1128672 1145329
Changes:
thunderbird (1:153.2.0esr-1) unstable; urgency=medium
.
[ Carsten Schoenert ]
* [cb6c2c5] Merge tag 'debian/1%153.1.0esr-1' into debian/sid
* [3c5e98e] d/gbp.conf: Adjust upstream branch to new ESR cycle
* [628233d] New upstream version 153.2.0esr
Fixed CVE issues in upstream version 153.2 (MFSA 2026-88):
CVE-2026-84639: Uninitialized memory in MIME parsing
CVE-2026-84640: One byte overflow read in mail parser
CVE-2026-84641: Information disclosure due to malicious IMAP server
response
CVE-2026-84637: Calendar invitation attachments could launch local
executables
CVE-2026-84642: Allowed UNC hostnames for attachments interpreted as a
regular expression
CVE-2026-75874: Sandbox escape in the Remote Settings Client component
CVE-2026-84118: Use-after-free in the JavaScript: GC component
CVE-2026-84119: Sandbox escape due to use-after-free in the DOM:
Navigation component
CVE-2026-84120: Use-after-free in the Audio/Video component
CVE-2026-84121: Sandbox escape due to use-after-free in the DOM:
Security component
CVE-2026-84122: Use-after-free in the Audio/Video component
CVE-2026-84123: Privilege escalation due to use-after-free in the
Graphics: WebGPU component
CVE-2026-84124: Use-after-free in the DOM: Core & HTML component
CVE-2026-84125: Use-after-free in the DOM: Core & HTML component
CVE-2026-74952: Privilege escalation in the Application Update component
CVE-2026-84129: Site isolation issue in the DOM: Navigation component
CVE-2026-84130: Information disclosure in the Graphics: WebGPU component
CVE-2026-84131: Privilege escalation due to invalid pointer in the
Graphics component
CVE-2026-84132: Information disclosure in the Networking: HTTP component
CVE-2026-84133: Site isolation issue in the DOM: Push Subscriptions
component
CVE-2026-84134: Other issue in the Profile Backup component
CVE-2026-84136: Other issue in the DOM: Navigation component
CVE-2026-84137: Spoofing issue in the DOM: Core & HTML component
CVE-2026-84139: Clickjacking issue in the DOM: Events component
CVE-2026-84140: Site isolation issue in the DOM: Navigation component
CVE-2026-84141: Integer overflow in the Graphics: ImageLib component
CVE-2026-84143: Internally found bugs fixed in Thunderbird 155,
Thunderbird ESR 153.2 and Thunderbird ESR 140.15
CVE-2026-84144: Internally found bugs fixed in Thunderbird 155 and
Thunderbird ESR 153.2
CVE-2026-84145: Internally found bugs fixed in Thunderbird 155,
Thunderbird ESR 153.2 and Thunderbird ESR 140.15
(Closes: #1145329, #1128672, #1127710, #928178, #909281, #955380, #882218,
#900210, #914403, #917613, #949450, #880424, #883245, #961269, #949649)
Checksums-Sha1:
bac4eb72b9649c816760856964d09c076e38faf5 8422 thunderbird_153.2.0esr-1.dsc
fe79aa4defdc8020c7a02c6df6bb7b563f36adfb 12815688 thunderbird_153.2.0esr.orig-thunderbird-l10n.tar.xz
233dca2b586cd5c74b64334dce706f1e3ca00b80 904710156 thunderbird_153.2.0esr.orig.tar.xz
b7cdeda74917b707b255c13b708b09157c5e7db8 556104 thunderbird_153.2.0esr-1.debian.tar.xz
791e62c718ff9918ea5877797a45c0d22738ea38 41146 thunderbird_153.2.0esr-1_amd64.buildinfo
Checksums-Sha256:
d77eab67b96ee31524426926ef06a4e48ac3b2415ea96d1a7f2128e77ca99ad0 8422 thunderbird_153.2.0esr-1.dsc
c33e07a872d250687088a407ce054593f6b0c2f5683e9af8f6632cdeb9700553 12815688 thunderbird_153.2.0esr.orig-thunderbird-l10n.tar.xz
79c01aa5b07f3464d43cc96300141b678a2685c861b9bcc6890e9e6d088f1aeb 904710156 thunderbird_153.2.0esr.orig.tar.xz
533a8015c15e833508f91e121182c5426af50c22ab56a0f1081c0fdda20f39e9 556104 thunderbird_153.2.0esr-1.debian.tar.xz
f241204d92ccbacd2171d1e9f151875e6211f07ba8339177364a68d98cca2f95 41146 thunderbird_153.2.0esr-1_amd64.buildinfo
Files:
ed3769dd9d71c325b0279905fdb13bb5 8422 mail optional thunderbird_153.2.0esr-1.dsc
86caafe71439920cf8a6654c990c9fa2 12815688 mail optional thunderbird_153.2.0esr.orig-thunderbird-l10n.tar.xz
b2c0d7f65a9cd572aa2a1f30644775cc 904710156 mail optional thunderbird_153.2.0esr.orig.tar.xz
2ef3d8fe96862cfda6fcee8e46c50a71 556104 mail optional thunderbird_153.2.0esr-1.debian.tar.xz
dfc69d6380f67a4b97137b4f7fe5d71b 41146 mail optional thunderbird_153.2.0esr-1_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEtw38bxNP7PwBHmKqgwFgFCUdHbAFAmqYPuMACgkQgwFgFCUd
HbDucw//V9bDtLsvpm/xw02HRxdA7FPVmYjP9k4oWIf634i82Cu+o8UHksHNYfip
qCMpgrwR+LXPDfnF/UZeW8AaMvX69C3Be2b33TB/7Cgjo9kIJI0/4IhKhp0CJiwn
jjtRkyVNLDDDYMNJU4pbkQR/PDlyjG2N/RSqfylR/iC1KUO70D6XkIAkw6AoUEoP
1s+Ly52fdF6SSvLRwcTQtt/k7xKRILVIda+uDey/LAz40TszDTbwbSrY+/tkWBtW
5aLA+eE6YR/aKxlW7+rUj1IhaW0FzlAEbUCrl2li5l0oSw4JqqPGmYSUuQyfJXI1
V8eytDOU5tl8uYGb1ixlYB5nmbRrT815bBw0Fddw5rR+7j9QD/QlSRfOHgP+ppm5
bWfyiPaI0mCUTm5trv6ECl3BZC4/rpWAmn80ucxfJoocqlEl+mALDV5DCz0sSU4p
ErQ8zZYHZfgfiZbwSi2jElhUwWvAD8r0AmsZSxaZJEjRQeq+DGj56kK0+mnpIMQ1
hzWr1OBr+Tt2FZw4n94GAZ077U8SFlGTQSMTdk+vaT6wypuWY2TtJqiPW2uk8B1v
2HZd5KIBFdYgiChNyZEa1RpfCX+xhjXIdE6jc1yhpZ8rmwHLVVzY4nfaUCoXm70E
OcNnneYzELnz8mbI3NXZ9iyjPXAMdyskdSijmOgPMlC7pNh0pks=
=sQE4
-----END PGP SIGNATURE-----