thunderbird (1:153.2.0esr-1)
[PTS] [DDPO]
COMMITS: VCS has seen 1 commit since the debian/1%153.2.0esr-1 tag
- Git: https://salsa.debian.org/mozilla-team/thunderbird.git -b debian/sid
-
- Branch: debian/sid
- Path: debian/changelog
- Repo size: 21774336
- Browser: https://salsa.debian.org/mozilla-team/thunderbird/commits/debian/sid/
- Last scan: 2026-09-11 22:56:19+00
- Error: https://salsa.debian.org/api/v4/projects/mozilla-team%2Fthunderbird API request failed: 401 Unauthorized at /srv/qa.debian.org/data/vcswatch/vcswatch line 410.
- Next scan: 2026-09-19 02:36:00+00
- Debian changelog in Git:
thunderbird (1:153.2.0esr-1) unstable; urgency=medium
[ Carsten Schoenert ]
* [cb6c2c5] Merge tag 'debian/1%153.1.0esr-1' into debian/sid
* [3c5e98e] d/gbp.conf: Adjust upstream branch to new ESR cycle
* [628233d] New upstream version 153.2.0esr
Fixed CVE issues in upstream version 153.2 (MFSA 2026-88):
CVE-2026-84639: Uninitialized memory in MIME parsing
CVE-2026-84640: One byte overflow read in mail parser
CVE-2026-84641: Information disclosure due to malicious IMAP server
response
CVE-2026-84637: Calendar invitation attachments could launch local
executables
CVE-2026-84642: Allowed UNC hostnames for attachments interpreted as a
regular expression
CVE-2026-75874: Sandbox escape in the Remote Settings Client component
CVE-2026-84118: Use-after-free in the JavaScript: GC component
CVE-2026-84119: Sandbox escape due to use-after-free in the DOM:
Navigation component
CVE-2026-84120: Use-after-free in the Audio/Video component
CVE-2026-84121: Sandbox escape due to use-after-free in the DOM:
Security component
CVE-2026-84122: Use-after-free in the Audio/Video component
CVE-2026-84123: Privilege escalation due to use-after-free in the
Graphics: WebGPU component
CVE-2026-84124: Use-after-free in the DOM: Core & HTML component
CVE-2026-84125: Use-after-free in the DOM: Core & HTML component
CVE-2026-74952: Privilege escalation in the Application Update component
CVE-2026-84129: Site isolation issue in the DOM: Navigation component
CVE-2026-84130: Information disclosure in the Graphics: WebGPU component
CVE-2026-84131: Privilege escalation due to invalid pointer in the
Graphics component
CVE-2026-84132: Information disclosure in the Networking: HTTP component
CVE-2026-84133: Site isolation issue in the DOM: Push Subscriptions
component
CVE-2026-84134: Other issue in the Profile Backup component
CVE-2026-84136: Other issue in the DOM: Navigation component
CVE-2026-84137: Spoofing issue in the DOM: Core & HTML component
CVE-2026-84139: Clickjacking issue in the DOM: Events component
CVE-2026-84140: Site isolation issue in the DOM: Navigation component
CVE-2026-84141: Integer overflow in the Graphics: ImageLib component
CVE-2026-84143: Internally found bugs fixed in Thunderbird 155,
Thunderbird ESR 153.2 and Thunderbird ESR 140.15
CVE-2026-84144: Internally found bugs fixed in Thunderbird 155 and
Thunderbird ESR 153.2
CVE-2026-84145: Internally found bugs fixed in Thunderbird 155,
Thunderbird ESR 153.2 and Thunderbird ESR 140.15
(Closes: #1145329, #1128672, #1127710, #928178, #909281, #955380, #882218,
#900210, #914403, #917613, #949450, #880424, #883245, #961269, #949649)
-- Carsten Schoenert <c.schoenert@t-online.de> Tue, 01 Sep 2026 19:03:49 +0200
- This branch is 1 commit ahead of tag debian/1%153.2.0esr-1
- Git log:
commit 4340b21f1ecb0898d26219f1561747cabb0a9dac
Author: Christoph Goehre <chris@sigxcpu.org>
Date: Thu Sep 10 18:15:24 2026 -0400
d/control: re-Adding s390x architecture
It was building flawless in the last six uploads to experimental, so
just give it another chance.