[CLSA-2026:1784712935] thunderbird: Fix of 3 CVEs
Type:
security
Severity:
Important
Release date:
2026-07-22 09:36:04 UTC
Description:
- CVE-2024-3854: fix Ion IsDiamondPattern successor-count guard allowing switch terminators (Mozilla bug 1884552) - CVE-2024-5702: fix use-after-free in nsTransportEventSinkProxy via raw-pointer to smart-pointer refactor (Mozilla bug 1193389) - CVE-2026-0880: fix integer overflow in Cairo DrawTarget CopyToImageSurface/CreateSubImageForData (Mozilla bug 2005014)
Updated packages:
  • thunderbird-115.4.1-1.el9_2.alma.tuxcare.els27.x86_64.rpm
    sha:a0eca396b664c75b03e9d31bbae4630e4e8b88bf36e1db572d07754ebfe91041
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.