[CLSA-2026:1779579653] thunderbird: Fix of 4 CVEs
Type:
security
Severity:
Critical
Release date:
2026-05-25 07:35:52 UTC
Description:
- CVE-2024-0742: assertion failure in nsPresContext::UserInputEventsAllowed (Document::SetIsInitialDocument sticky-bit) - CVE-2025-2830: path traversal via malformed attachment filename in multipart message (directory guard in MimePart._fetchAttachment + mimedrft.cpp) - CVE-2025-3909: predictable tempfile path enables JavaScript execution from attachment opened in file:/// context (per-PID tempdir, 0o700) - CVE-2025-3932: tracking links in attachments bypass remote-content blocking (scheme allowlist + FeedMsg http(s) carve-out in AttachmentInfo.isEmpty)
Updated packages:
  • thunderbird-115.4.1-1.el9_2.alma.tuxcare.els3.x86_64.rpm
    sha:23698637255e25a43ea9201816498ee8a5c13ea63e609cbfd3c9dded82b895d9
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.