[CLSA-2026:1779136540] thunderbird: Fix of 2 CVEs
Type:
security
Severity:
Moderate
Release date:
2026-05-18 20:35:44 UTC
Description:
- CVE-2024-0747: Document::Open inheriting CSP from a different window - CVE-2025-5268: Memory safety bugs (gfxFont mHasSpaceFeatures atomicity, PresShell event-handler UAF, wasm uncheckedReadValType missing types)
Updated packages:
  • thunderbird-115.4.1-1.el9_2.alma.tuxcare.els1.x86_64.rpm
    sha:f2eb20b2e8b86eaa0d11c6da00079c7eb2fd73f4f56ea686121a9033ad8e5332
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.