-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Tue, 15 Sep 2026 18:07:30 -0400
Source: thunderbird
Binary: thunderbird thunderbird-dbgsym
Architecture: i386
Version: 1:140.16.0esr-1~deb13u1
Distribution: trixie-security
Urgency: medium
Maintainer: all / amd64 / i386 Build Daemon (x86-grnet-03) <buildd_amd64-x86-grnet-03@buildd.debian.org>
Changed-By: Christoph Goehre <chris@sigxcpu.org>
Description:
 thunderbird - mail/news client with RSS, chat and integrated spam filter suppor
Changes:
 thunderbird (1:140.16.0esr-1~deb13u1) trixie-security; urgency=medium
 .
   * [fc5c7cf] New upstream version 140.16.0esr
     Fixed CVE issues in upstream version 140.16 (MFSA 2026-95):
     CVE-2026-92238: Ambiguous parsing of mail headers
     CVE-2026-92239: Buffer overrun in IMAP
     CVE-2026-92240: Out-of-bounds read in IMAP response parser
     CVE-2026-92005: Use-after-free in the Audio/Video: Web Codecs component
     CVE-2026-92006: Privilege escalation due to incorrect boundary conditions
                     in the Graphics: CanvasWebGL component
     CVE-2026-92007: Privilege escalation due to incorrect boundary conditions
                     in the Graphics: CanvasWebGL component
     CVE-2026-92008: Privilege escalation due to incorrect boundary conditions
                     in the Graphics: CanvasWebGL component
     CVE-2026-92009: Privilege escalation due to incorrect boundary conditions
                     in the Graphics: CanvasWebGL component
     CVE-2026-92010: Privilege escalation due to incorrect boundary conditions
                     in the Graphics: CanvasWebGL component
     CVE-2026-92011: Privilege escalation due to incorrect boundary conditions
                     in the Graphics: CanvasWebGL component
     CVE-2026-92012: Privilege escalation due to incorrect boundary conditions
                     in the Graphics: CanvasWebGL component
     CVE-2026-92013: Privilege escalation due to incorrect boundary conditions
                     in the Graphics: CanvasWebGL component
     CVE-2026-92014: Privilege escalation due to incorrect boundary conditions
                     in the Graphics component
     CVE-2026-92015: Privilege escalation in the WebExtensions component
     CVE-2026-92016: Use-after-free in the Disability Access APIs component
     CVE-2026-92017: Privilege escalation in the DOM: Service Workers component
     CVE-2026-92018: Sandbox escape in the DOM: Core & HTML component
     CVE-2026-92019: Mitigation bypass in the Remote Settings Client component
     CVE-2026-92020: Privilege escalation due to incorrect boundary conditions
                     in the Graphics: WebRender component
     CVE-2026-92021: Use-after-free in the JavaScript Engine: JIT component
     CVE-2026-92022: Use-after-free in the DOM: HTML Parser component
     CVE-2026-92023: Use-after-free in the XML component
     CVE-2026-92024: Use-after-free in the SVG component
     CVE-2026-92025: Use-after-free in the DOM: Navigation component
     CVE-2026-92026: Use-after-free in the Networking component
     CVE-2026-92027: Use-after-free in the DOM: Streams component
     CVE-2026-92028: Use-after-free in the DOM: Core & HTML component
     CVE-2026-92029: Use-after-free in the SVG component
     CVE-2026-92030: Mitigation bypass in the DOM: Copy & Paste and Drag & Drop
                     component
     CVE-2026-92031: Information disclosure in the Graphics: ImageLib component
     CVE-2026-92032: Sandbox escape due to invalid pointer in the Graphics
                     component
Checksums-Sha1:
 25ee9bb781b6d25438f2737f5e8cddb527c4f8df 8631184 thunderbird-dbgsym_140.16.0esr-1~deb13u1_i386.deb
 18c0d3b3fa16bf13547eaaebc32ffeb1f231f8b6 21353 thunderbird_140.16.0esr-1~deb13u1_i386-buildd.buildinfo
 255928255520cb74db41743393b230538ec1fef3 74285440 thunderbird_140.16.0esr-1~deb13u1_i386.deb
Checksums-Sha256:
 52659fb592a0008821b4159445e42bfd34b3778deea2c6e0e841e644979095ff 8631184 thunderbird-dbgsym_140.16.0esr-1~deb13u1_i386.deb
 4cd9f2a960b8f4cf54c10e401d39133cb14e0dfe23c2f1c4e490465e161b711e 21353 thunderbird_140.16.0esr-1~deb13u1_i386-buildd.buildinfo
 ed9a28391105010e604beb5b22fa07e28a91d7f7c1fe0ed1a0d4eae9f52e4295 74285440 thunderbird_140.16.0esr-1~deb13u1_i386.deb
Files:
 38a92e20009d69ed00090735341b8881 8631184 debug optional thunderbird-dbgsym_140.16.0esr-1~deb13u1_i386.deb
 4f621a294e69440c9ac47a835787e1f8 21353 mail optional thunderbird_140.16.0esr-1~deb13u1_i386-buildd.buildinfo
 c1b1aef81e76b79ad05dfe90c11e958a 74285440 mail optional thunderbird_140.16.0esr-1~deb13u1_i386.deb

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEE5ZI1lXv5WjhHIVjsN8Ugyu9dQiQFAmqp7vsACgkQN8Ugyu9d
QiQI9Q//bHAms7G1v9OHBhmbn+i8AcqfruvyyjmPX9CfKQa4sqNhGmVKD54MhZuN
4usSOFp9yC7RMF5lM4iuO4R6vwZyGLvprhnKGkZRLkERbUwmM8PHFMKU3YUgWLh/
VN+ZWRclmOI3KddehcIHwT87Wzh5SImDOOT8eWMzXpaJh0a7gviIY5vlWvwu3/iL
y012iMI0I8wu2Jau7lA0RsVEpVI5D15mp0aiQO20fgTAgSiHM42Gb2fwrS8wYIqJ
+MSxS7CGxDyEZ+4o31X6jLlTeC4BnAESqXbqmXochrZqpTP9Z8AvZ/nOn0sK2VsI
khBwB81Y2N0vLU4UANBk9goq0LJZVNoAGpGhF0k88bDeM8vyoB/e+/9MqYp3lc19
DCRJwn0B/UAGGG7SuazLXkJ2wsVRi35m2u71XWowMwhGkm9XQqNroiPONnZvBHt0
leRd3llnfXovcuNGqQ6cE+m0hSsaBgfjWB9S4kLvIKJ6tOR2rq6ycwUuKPAdd7fD
nCoBpdv3eIsjfFvOVj9DFTZ3TUgit953/enT4wW0Poigccxe9IhECnWEivm75ICg
/AzNtiCdSfz6N99PxKfD7e8Izzkg92Bu9J8wTrICmMLn41qscjmd/OuSGfRnleoq
9TsEafrCgNVvyPGLXN9Xva9oxpI6mkdU09tp34KJ4e3eGdP1SGo=
=qjav
-----END PGP SIGNATURE-----
