Skip to content
SUSE MozillaThunderbird Security Advisory 2026-0880

SUSE MozillaThunderbird Security Advisory 2026-0880

Linuxsecurity LinuxSecurity Advisories March 12, 2026

## This update for MozillaThunderbird fixes the following issues: Mozilla Thunderbird 140.8 MFSA 2026-17 (bsc#1258568): * CVE-2026-2757: Incorrect boundary conditions in the WebRTC: Audio/Video component * CVE-2026-2758: Use-after-free in the JavaScript: GC component * CVE-2026-2759: Incorrect boundary conditions in the Graphics: ImageLib component * CVE-2026-2760: Sandbox escape due to incorrect boundary conditions in the Graphics: WebRender component * CVE-2026-2761: Sandbox escape in the Graphics: WebRender component * CVE-2026-2762: Integer overflow in the JavaScript: Standard Library component * CVE-2026-2763: Use-after-free in the JavaScript Engine component * CVE-2026-2764: JIT miscompilation, use-after-free in the JavaScript Engine: JIT component Read the Full Advisory

## This update for MozillaThunderbird fixes the following issues: Mozilla Thunderbird 140.8 MFSA 2026-17 (bsc#1258568): * CVE-2026-2757: Incorrect boundary conditions in the WebRTC: Audio/Video component * CVE-2026-2758: Use-after-free in the JavaScript: GC component * CVE-2026-2759: Incorrect boundary conditions in the Graphics: ImageLib component * CVE-2026-2760: Sandbox escape due to incorrect boundary conditions in the Graphics: WebRender component * CVE-2026-2761: Sandbox escape in the Graphics: WebRender component * CVE-2026-2762: Integer overflow in the JavaScript: Standard Library component * CVE-2026-2763: Use-after-free in the JavaScript Engine component * CVE-2026-2764: JIT miscompilation, use-after-free in the JavaScript Engine: JIT component Read the Full Advisory

* bsc#1258568 Cross- * CVE-2026-2757 * CVE-2026-2758 * CVE-2026-2759 * CVE-2026-2760 * CVE-2026-2761 * CVE-2026-2762 * CVE-2026-2763 * CVE-2026-2764 * CVE-2026-2765 * CVE-2026-2766 * CVE-2026-2767 * CVE-2026-2768 * CVE-2026-2769 * CVE-2026-2770 * CVE-2026-2771 * CVE-2026-2772 * CVE-2026-2773 * CVE-2026-2774 * CVE-2026-2775 * CVE-2026-2776 * CVE-2026-2777 * CVE-2026-2778 * CVE-2026-2779 * CVE-2026-2780 * CVE-2026-2781 * CVE-2026-2782 * CVE-2026-2783 * CVE-2026-2784 * CVE-2026-2785 * CVE-2026-2786 * CVE-2026-2787 * CVE-2026-2788 * CVE-2026-2789 * CVE-2026-2790 * CVE-2026-2791 * CVE-2026-2792 * CVE-2026-2793 CVSS scores: * CVE-2026-2757 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-2757 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Read the Full Advisory

* CVE-2026-2757 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

* CVE-2026-2757 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Read the Full Advisory