-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 15 Sep 2026 18:07:30 -0400 Source: thunderbird Binary: thunderbird thunderbird-dbgsym Architecture: ppc64el Version: 1:140.16.0esr-1~deb13u1 Distribution: trixie-security Urgency: medium Maintainer: ppc64el Build Daemon (ppc64el-conova-02) Changed-By: Christoph Goehre Description: thunderbird - mail/news client with RSS, chat and integrated spam filter suppor Changes: thunderbird (1:140.16.0esr-1~deb13u1) trixie-security; urgency=medium . * [fc5c7cf] New upstream version 140.16.0esr Fixed CVE issues in upstream version 140.16 (MFSA 2026-95): CVE-2026-92238: Ambiguous parsing of mail headers CVE-2026-92239: Buffer overrun in IMAP CVE-2026-92240: Out-of-bounds read in IMAP response parser CVE-2026-92005: Use-after-free in the Audio/Video: Web Codecs component CVE-2026-92006: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component CVE-2026-92007: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component CVE-2026-92008: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component CVE-2026-92009: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component CVE-2026-92010: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component CVE-2026-92011: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component CVE-2026-92012: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component CVE-2026-92013: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component CVE-2026-92014: Privilege escalation due to incorrect boundary conditions in the Graphics component CVE-2026-92015: Privilege escalation in the WebExtensions component CVE-2026-92016: Use-after-free in the Disability Access APIs component CVE-2026-92017: Privilege escalation in the DOM: Service Workers component CVE-2026-92018: Sandbox escape in the DOM: Core & HTML component CVE-2026-92019: Mitigation bypass in the Remote Settings Client component CVE-2026-92020: Privilege escalation due to incorrect boundary conditions in the Graphics: WebRender component CVE-2026-92021: Use-after-free in the JavaScript Engine: JIT component CVE-2026-92022: Use-after-free in the DOM: HTML Parser component CVE-2026-92023: Use-after-free in the XML component CVE-2026-92024: Use-after-free in the SVG component CVE-2026-92025: Use-after-free in the DOM: Navigation component CVE-2026-92026: Use-after-free in the Networking component CVE-2026-92027: Use-after-free in the DOM: Streams component CVE-2026-92028: Use-after-free in the DOM: Core & HTML component CVE-2026-92029: Use-after-free in the SVG component CVE-2026-92030: Mitigation bypass in the DOM: Copy & Paste and Drag & Drop component CVE-2026-92031: Information disclosure in the Graphics: ImageLib component CVE-2026-92032: Sandbox escape due to invalid pointer in the Graphics component Checksums-Sha1: 7f3ec283f59d1a7a8e05805c75666e9e155e7bee 491548352 thunderbird-dbgsym_140.16.0esr-1~deb13u1_ppc64el.deb 912a86bf400dd8d40fd076b89cba70cf7589fa94 21409 thunderbird_140.16.0esr-1~deb13u1_ppc64el-buildd.buildinfo eca2ffc11b7d67cd5334514f01969ffd961e0db9 65123672 thunderbird_140.16.0esr-1~deb13u1_ppc64el.deb Checksums-Sha256: 4768d2b9e33d05695660ed38ebe4d4e25370b97e49bc9ab3a788e81856cb8d04 491548352 thunderbird-dbgsym_140.16.0esr-1~deb13u1_ppc64el.deb 0cbce982c491af9741ac9df7281ed95829861bb1450e214720c60744f52c2567 21409 thunderbird_140.16.0esr-1~deb13u1_ppc64el-buildd.buildinfo cb6985d53975966046ebcd987d0b05c25bc4a8b6f300375bc2651beecf8b020f 65123672 thunderbird_140.16.0esr-1~deb13u1_ppc64el.deb Files: 64aea05ef917c360b1cd56332f55d575 491548352 debug optional thunderbird-dbgsym_140.16.0esr-1~deb13u1_ppc64el.deb bdc013963e2b0a01441ae34af5830311 21409 mail optional thunderbird_140.16.0esr-1~deb13u1_ppc64el-buildd.buildinfo d148661ca18947d0e7e6790416644790 65123672 mail optional thunderbird_140.16.0esr-1~deb13u1_ppc64el.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEySUEQfg5pZeb/U372FRWNm40e2YFAmqqG58ACgkQ2FRWNm40 e2bwxhAAo4A2SltWOBVyERGNSgKk4heCPVoKRCD1mNLHLjHuOEont60nBlVI0RgL QP5xJqE5Zlc419mv7aWHca0+yK67Kxe901K14gF3pXY57MulzOignWabdFeoupZZ dEfyv28AuT0/KDBQUe7+38RWFDqhauJ44C5vMg5WbafVhRHnl1i/CkVgtx+mx8Vv A8V7GESsYMy6eAbqnobLVnggJ93dcnarp8BUCqADTtx3jg1bcXW6hfzE8qKxKHCL zaYwJvY4dypHNMfTB+lH3r0xkSx8lnip2+3oyoRc9aiibrOo922EbmUmuz1UjbAp oJ3ZVTniProLTXcwa3X8xrMNJHgjAYedsniXlwi9JogphGQjqmPXMG+SkEhBI05E rsAQTdzlESSaqkNJ6zUaAihxBLQrlvJpMAeXktAgJ1AHomrHuy1SzdEN8luCAJMM X7sqDIIn1VcarARJk1wRYMEZGzNBOP4u3ZzGybdhlwUZKpmuYvRtensmHryz3KOY 8RYhj6cTGUnalASTemuk3YPBOuVwcsODEnjCm3PKX11x1jQx3IggR49GY882ISSz 4BjrsAC1IIfeeNmb76ZM6w6sWO+GeTRPCYzbhd60gN/Yn1GfCpU1TqW7DFMLBx1s +iERRmdAxy2S6grVnW9zdeo6j08mcnVPBQ0+/Ke9VJo0P9wEgXk= =j/VL -----END PGP SIGNATURE-----