Red Hat Security Advisory: thunderbird security update
Multiple security vulnerabilities affecting Mozilla Thunderbird have been addressed in a Red Hat security advisory for Red Hat Enterprise Linux 9.4 Extended Update Support. These include memory safety bugs, use-after-free, JIT miscompilation, sandbox escape, privilege escalation, and same-origin policy bypass issues. The fixes are included in Thunderbird ESR 140.6 and Thunderbird 146 versions. The advisory rates the update as important and provides updated packages to remediate these issues.
AI Analysis
Technical Summary
The Red Hat security advisory RHSA-2026:0004 addresses multiple vulnerabilities in Mozilla Thunderbird, including use-after-free in the WebRTC signaling component (CVE-2025-14321), memory safety bugs (CVE-2025-14333), JIT miscompilation issues in the JavaScript engine (CVE-2025-14324, CVE-2025-14325, CVE-2025-14330), sandbox escape via incorrect boundary conditions in the CanvasWebGL graphics component (CVE-2025-14322), privilege escalation in the Netmonitor and DOM Notifications components (CVE-2025-14323, CVE-2025-14328, CVE-2025-14329), and same-origin policy bypass in request handling (CVE-2025-14331). These vulnerabilities are fixed in Thunderbird ESR 140.6 and Thunderbird 146. The advisory applies to Red Hat Enterprise Linux 9.4 Extended Update Support and related variants. No CVSS scores are provided in the advisory, but the overall severity is rated as important by Red Hat.
Potential Impact
Successful exploitation of these vulnerabilities could lead to memory corruption, use-after-free conditions, sandbox escapes, privilege escalation, and bypass of same-origin policy protections within Thunderbird. This may allow attackers to execute arbitrary code, escalate privileges, or bypass security restrictions in the affected mail client. The advisory does not report known exploits in the wild at this time.
Mitigation Recommendations
Red Hat has released updated Thunderbird packages (version 140.6.0-1.el9_4) for Red Hat Enterprise Linux 9.4 Extended Update Support and related variants that address these vulnerabilities. Users should apply these official updates promptly to remediate the security issues. For detailed update instructions, refer to the Red Hat article at https://access.redhat.com/articles/11258. No additional mitigation steps are indicated by the vendor advisory.
Red Hat Security Advisory: thunderbird security update
Description
Multiple security vulnerabilities affecting Mozilla Thunderbird have been addressed in a Red Hat security advisory for Red Hat Enterprise Linux 9.4 Extended Update Support. These include memory safety bugs, use-after-free, JIT miscompilation, sandbox escape, privilege escalation, and same-origin policy bypass issues. The fixes are included in Thunderbird ESR 140.6 and Thunderbird 146 versions. The advisory rates the update as important and provides updated packages to remediate these issues.
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Red Hat security advisory RHSA-2026:0004 addresses multiple vulnerabilities in Mozilla Thunderbird, including use-after-free in the WebRTC signaling component (CVE-2025-14321), memory safety bugs (CVE-2025-14333), JIT miscompilation issues in the JavaScript engine (CVE-2025-14324, CVE-2025-14325, CVE-2025-14330), sandbox escape via incorrect boundary conditions in the CanvasWebGL graphics component (CVE-2025-14322), privilege escalation in the Netmonitor and DOM Notifications components (CVE-2025-14323, CVE-2025-14328, CVE-2025-14329), and same-origin policy bypass in request handling (CVE-2025-14331). These vulnerabilities are fixed in Thunderbird ESR 140.6 and Thunderbird 146. The advisory applies to Red Hat Enterprise Linux 9.4 Extended Update Support and related variants. No CVSS scores are provided in the advisory, but the overall severity is rated as important by Red Hat.
Potential Impact
Successful exploitation of these vulnerabilities could lead to memory corruption, use-after-free conditions, sandbox escapes, privilege escalation, and bypass of same-origin policy protections within Thunderbird. This may allow attackers to execute arbitrary code, escalate privileges, or bypass security restrictions in the affected mail client. The advisory does not report known exploits in the wild at this time.
Mitigation Recommendations
Red Hat has released updated Thunderbird packages (version 140.6.0-1.el9_4) for Red Hat Enterprise Linux 9.4 Extended Update Support and related variants that address these vulnerabilities. Users should apply these official updates promptly to remediate the security issues. For detailed update instructions, refer to the Red Hat article at https://access.redhat.com/articles/11258. No additional mitigation steps are indicated by the vendor advisory.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:0004
- Cve Count
- 10
- Additional Cves
- ["CVE-2025-14322","CVE-2025-14323","CVE-2025-14324","CVE-2025-14325","CVE-2025-14328","CVE-2025-14329","CVE-2025-14330","CVE-2025-14331","CVE-2025-14333"]
Threat ID: 6a4049df27e9c79719831b4a
Added to database: 06/27/2026, 22:08:31 UTC
Last enriched: 06/27/2026, 22:27:16 UTC
Last updated: 09/10/2026, 19:36:49 UTC
Views: 21
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.