-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Tue, 15 Sep 2026 18:07:30 -0400
Source: thunderbird
Binary: thunderbird thunderbird-dbgsym
Architecture: arm64
Version: 1:140.16.0esr-1~deb13u1
Distribution: trixie-security
Urgency: medium
Maintainer: arm64 Build Daemon (arm-ubc-06) <buildd_arm64-arm-ubc-06@buildd.debian.org>
Changed-By: Christoph Goehre <chris@sigxcpu.org>
Description:
 thunderbird - mail/news client with RSS, chat and integrated spam filter suppor
Changes:
 thunderbird (1:140.16.0esr-1~deb13u1) trixie-security; urgency=medium
 .
   * [fc5c7cf] New upstream version 140.16.0esr
     Fixed CVE issues in upstream version 140.16 (MFSA 2026-95):
     CVE-2026-92238: Ambiguous parsing of mail headers
     CVE-2026-92239: Buffer overrun in IMAP
     CVE-2026-92240: Out-of-bounds read in IMAP response parser
     CVE-2026-92005: Use-after-free in the Audio/Video: Web Codecs component
     CVE-2026-92006: Privilege escalation due to incorrect boundary conditions
                     in the Graphics: CanvasWebGL component
     CVE-2026-92007: Privilege escalation due to incorrect boundary conditions
                     in the Graphics: CanvasWebGL component
     CVE-2026-92008: Privilege escalation due to incorrect boundary conditions
                     in the Graphics: CanvasWebGL component
     CVE-2026-92009: Privilege escalation due to incorrect boundary conditions
                     in the Graphics: CanvasWebGL component
     CVE-2026-92010: Privilege escalation due to incorrect boundary conditions
                     in the Graphics: CanvasWebGL component
     CVE-2026-92011: Privilege escalation due to incorrect boundary conditions
                     in the Graphics: CanvasWebGL component
     CVE-2026-92012: Privilege escalation due to incorrect boundary conditions
                     in the Graphics: CanvasWebGL component
     CVE-2026-92013: Privilege escalation due to incorrect boundary conditions
                     in the Graphics: CanvasWebGL component
     CVE-2026-92014: Privilege escalation due to incorrect boundary conditions
                     in the Graphics component
     CVE-2026-92015: Privilege escalation in the WebExtensions component
     CVE-2026-92016: Use-after-free in the Disability Access APIs component
     CVE-2026-92017: Privilege escalation in the DOM: Service Workers component
     CVE-2026-92018: Sandbox escape in the DOM: Core & HTML component
     CVE-2026-92019: Mitigation bypass in the Remote Settings Client component
     CVE-2026-92020: Privilege escalation due to incorrect boundary conditions
                     in the Graphics: WebRender component
     CVE-2026-92021: Use-after-free in the JavaScript Engine: JIT component
     CVE-2026-92022: Use-after-free in the DOM: HTML Parser component
     CVE-2026-92023: Use-after-free in the XML component
     CVE-2026-92024: Use-after-free in the SVG component
     CVE-2026-92025: Use-after-free in the DOM: Navigation component
     CVE-2026-92026: Use-after-free in the Networking component
     CVE-2026-92027: Use-after-free in the DOM: Streams component
     CVE-2026-92028: Use-after-free in the DOM: Core & HTML component
     CVE-2026-92029: Use-after-free in the SVG component
     CVE-2026-92030: Mitigation bypass in the DOM: Copy & Paste and Drag & Drop
                     component
     CVE-2026-92031: Information disclosure in the Graphics: ImageLib component
     CVE-2026-92032: Sandbox escape due to invalid pointer in the Graphics
                     component
Checksums-Sha1:
 9004775450a0eb31e669de8e5de422cf99038389 524713784 thunderbird-dbgsym_140.16.0esr-1~deb13u1_arm64.deb
 b4d0c6dfa305f65de6f183e68084d26328387e18 21496 thunderbird_140.16.0esr-1~deb13u1_arm64-buildd.buildinfo
 516cba8d992d55821699e4eb320d5e7dc1572128 62478136 thunderbird_140.16.0esr-1~deb13u1_arm64.deb
Checksums-Sha256:
 5327eb19cc195544f92361948cee4f629b2a0a2fa55ce1b1ea08aa8336d8e174 524713784 thunderbird-dbgsym_140.16.0esr-1~deb13u1_arm64.deb
 c7b6fccc9b0c13188a668bd49dbfd49531fd1b3cc9f483fbae83c0e32e0c7ba8 21496 thunderbird_140.16.0esr-1~deb13u1_arm64-buildd.buildinfo
 41eab614d69ea9d2fa77888bbbe2796c386acf0d5f88b37bf5d0fa6633ff4dc1 62478136 thunderbird_140.16.0esr-1~deb13u1_arm64.deb
Files:
 6af93bab09a6ab64062a05467b60b95e 524713784 debug optional thunderbird-dbgsym_140.16.0esr-1~deb13u1_arm64.deb
 6d859f08939287b65aed4b045b097793 21496 mail optional thunderbird_140.16.0esr-1~deb13u1_arm64-buildd.buildinfo
 6e0d6852db0a24f4ec52d82ad8add66b 62478136 mail optional thunderbird_140.16.0esr-1~deb13u1_arm64.deb

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEBOUsBrtd5lcy6oRfutMAkCxKbL0FAmqp5nQACgkQutMAkCxK
bL0ROhAAoedAwZyu1h3TVPyFPE+o3iFPX8EbZpGLe1Yc0Ksxa1t3bCbjso4bJkFN
DePB9Qf7/Xh9Kv4M8z91mXUlt/TJzCBj4rAkXPPd0Q8ZHdzqrgB/h/QQDV7T0UDf
bmjtOF66CAoCZRDQxwRsJc5nhuWv1v3VsWhfBCFipdbyPLCSbzOYQkK9A3ax2xVE
JL6w2sa3JVR6CB8q+2DZM5zP78OQLKTnHl7FRWJl8UR8OxATvw2VVfTl9H2nLAAJ
zacuK24J3a3yoNcx9fa6PJ6OE5OUa1/pQhRu41FzvzSSwL5ehfKrK4J9Tv5w8BSW
Bc+uVF/jMb50L7rEFr/2v1HCpCeUbtoaFTyFXGhUzjDQOU2PuqYSn6GPQrioPLL8
Ll+Sdpq4EbDOdzD9jX7ef7eP0Gn4HYRxeFW4KGGy6xrO9O0f98eFPL2YiRvMWA50
hh8MEftfEvU6lJTxCV8EyPoxsUMomrINPms+utR2vnynFzNIq3GDjk1+acxYoYDa
gjiyVXMbKgBJr4lEcH5ObbfrvnFX+IuiUe69NDmtvscjx83rHTTpXTvC+sYWeYUl
Lpa91iLfEi8ysWKVz3lgG/8o+t8vpq8LBdat2Tlwd+qUCAmbqTzxNki7Q0EgvHaB
BbABkrTBQR56eXI8Zhk2Bb4EdFl5OrZto4QXSqfaiT5cR9BOxXM=
=Wbkj
-----END PGP SIGNATURE-----
