Memory safety bugs fixed in Thunderbird ESR 140.10.1 and Thunderbird 150.0.1
Published Apr 28, 2026
8.8
HIGHCVSS 3.1
EPSS 0.47%
Description
Memory safety bugs present in Thunderbird ESR 140.10.0 and Thunderbird 150.0.0. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150.0.1, Firefox ESR 140.10.1, Firefox ESR 115.35.1, Thunderbird 150.0.1, and Thunderbird 140.10.1.
Affected products
No data.
- < 115.35.1
- < 150.0.1
- ≥ 128.0 · < 140.10.1
- < 140.10.1
- < 150.0.1
No data.
Red Hat Enterprise Linux 10
firefox-0:140.10.1-1.el10_2
Fixed · RHSA-2026:19157
Red Hat Enterprise Linux 10
thunderbird-0:140.10.1-1.el10_2
Fixed · RHSA-2026:19153
Red Hat Enterprise Linux 10.0 Extended Update Support
firefox-0:140.10.1-1.el10_0
Fixed · RHSA-2026:22408
Red Hat Enterprise Linux 10.0 Extended Update Support
thunderbird-0:140.10.1-1.el10_0
Fixed · RHSA-2026:24719
Red Hat Enterprise Linux 7 Extended Lifecycle Support
firefox-0:140.10.1-1.el7_9
Fixed · RHSA-2026:22708
Red Hat Enterprise Linux 8
firefox-0:140.10.1-1.el8_10
Fixed · RHSA-2026:19588
Red Hat Enterprise Linux 8
thunderbird-0:140.10.1-1.el8_10
Fixed · RHSA-2026:20586
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
firefox-0:140.10.1-1.el8_4
Fixed · RHSA-2026:22712
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
thunderbird-0:140.10.1-1.el8_4
Fixed · RHSA-2026:24718
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On
firefox-0:140.10.1-1.el8_4
Fixed · RHSA-2026:22712
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On
thunderbird-0:140.10.1-1.el8_4
Fixed · RHSA-2026:24718
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
firefox-0:140.10.1-1.el8_6
Fixed · RHSA-2026:24345
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
thunderbird-0:140.10.1-1.el8_6
Fixed · RHSA-2026:25014
Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On
firefox-0:140.10.1-1.el8_6
Fixed · RHSA-2026:24345
Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On
thunderbird-0:140.10.1-1.el8_6
Fixed · RHSA-2026:25014
Red Hat Enterprise Linux 8.8 Telecommunications Update Service
firefox-0:140.10.1-1.el8_8
Fixed · RHSA-2026:22847
Red Hat Enterprise Linux 8.8 Telecommunications Update Service
thunderbird-0:140.10.1-1.el8_8
Fixed · RHSA-2026:24717
Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
firefox-0:140.10.1-1.el8_8
Fixed · RHSA-2026:22847
Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
thunderbird-0:140.10.1-1.el8_8
Fixed · RHSA-2026:24717
Red Hat Enterprise Linux 9
firefox-0:140.10.1-1.el9_8
Fixed · RHSA-2026:19370
Red Hat Enterprise Linux 9
thunderbird-0:140.10.1-1.el9_8
Fixed · RHSA-2026:19348
Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions
firefox-0:140.10.1-1.el9_0
Fixed · RHSA-2026:21743
Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions
firefox-0:140.10.1-1.el9_2
Fixed · RHSA-2026:22410
Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions
thunderbird-0:140.10.1-1.el9_2
Fixed · RHSA-2026:24844
Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions
firefox-0:140.10.1-1.el9_4
Fixed · RHSA-2026:22324
Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions
thunderbird-0:140.10.1-1.el9_4
Fixed · RHSA-2026:24846
Red Hat Enterprise Linux 9.6 Extended Update Support
firefox-0:140.10.1-1.el9_6
Fixed · RHSA-2026:22409
Red Hat Enterprise Linux 9.6 Extended Update Support
thunderbird-0:140.10.1-1.el9_6
Fixed · RHSA-2026:24721
Red Hat Enterprise Linux 10
rhel10/firefox-flatpak
Affected
Red Hat Enterprise Linux 10
rhel10/thunderbird-flatpak
Affected
Red Hat Enterprise Linux 6
firefox
Out of support scope
Red Hat Enterprise Linux 6
thunderbird
Out of support scope
Red Hat Enterprise Linux 7
thunderbird
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | firefox-0:140.10.1-1.el10_2 | Fixed | RHSA-2026:19157 |
| Red Hat Enterprise Linux 10 | thunderbird-0:140.10.1-1.el10_2 | Fixed | RHSA-2026:19153 |
| Red Hat Enterprise Linux 10.0 Extended Update Support | firefox-0:140.10.1-1.el10_0 | Fixed | RHSA-2026:22408 |
| Red Hat Enterprise Linux 10.0 Extended Update Support | thunderbird-0:140.10.1-1.el10_0 | Fixed | RHSA-2026:24719 |
| Red Hat Enterprise Linux 7 Extended Lifecycle Support | firefox-0:140.10.1-1.el7_9 | Fixed | RHSA-2026:22708 |
| Red Hat Enterprise Linux 8 | firefox-0:140.10.1-1.el8_10 | Fixed | RHSA-2026:19588 |
| Red Hat Enterprise Linux 8 | thunderbird-0:140.10.1-1.el8_10 | Fixed | RHSA-2026:20586 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | firefox-0:140.10.1-1.el8_4 | Fixed | RHSA-2026:22712 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | thunderbird-0:140.10.1-1.el8_4 | Fixed | RHSA-2026:24718 |
| Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On | firefox-0:140.10.1-1.el8_4 | Fixed | RHSA-2026:22712 |
| Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On | thunderbird-0:140.10.1-1.el8_4 | Fixed | RHSA-2026:24718 |
| Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | firefox-0:140.10.1-1.el8_6 | Fixed | RHSA-2026:24345 |
| Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | thunderbird-0:140.10.1-1.el8_6 | Fixed | RHSA-2026:25014 |
| Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On | firefox-0:140.10.1-1.el8_6 | Fixed | RHSA-2026:24345 |
| Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On | thunderbird-0:140.10.1-1.el8_6 | Fixed | RHSA-2026:25014 |
| Red Hat Enterprise Linux 8.8 Telecommunications Update Service | firefox-0:140.10.1-1.el8_8 | Fixed | RHSA-2026:22847 |
| Red Hat Enterprise Linux 8.8 Telecommunications Update Service | thunderbird-0:140.10.1-1.el8_8 | Fixed | RHSA-2026:24717 |
| Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions | firefox-0:140.10.1-1.el8_8 | Fixed | RHSA-2026:22847 |
| Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions | thunderbird-0:140.10.1-1.el8_8 | Fixed | RHSA-2026:24717 |
| Red Hat Enterprise Linux 9 | firefox-0:140.10.1-1.el9_8 | Fixed | RHSA-2026:19370 |
| Red Hat Enterprise Linux 9 | thunderbird-0:140.10.1-1.el9_8 | Fixed | RHSA-2026:19348 |
| Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions | firefox-0:140.10.1-1.el9_0 | Fixed | RHSA-2026:21743 |
| Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | firefox-0:140.10.1-1.el9_2 | Fixed | RHSA-2026:22410 |
| Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | thunderbird-0:140.10.1-1.el9_2 | Fixed | RHSA-2026:24844 |
| Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions | firefox-0:140.10.1-1.el9_4 | Fixed | RHSA-2026:22324 |
| Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions | thunderbird-0:140.10.1-1.el9_4 | Fixed | RHSA-2026:24846 |
| Red Hat Enterprise Linux 9.6 Extended Update Support | firefox-0:140.10.1-1.el9_6 | Fixed | RHSA-2026:22409 |
| Red Hat Enterprise Linux 9.6 Extended Update Support | thunderbird-0:140.10.1-1.el9_6 | Fixed | RHSA-2026:24721 |
| Red Hat Enterprise Linux 10 | rhel10/firefox-flatpak | Affected | n/a |
| Red Hat Enterprise Linux 10 | rhel10/thunderbird-flatpak | Affected | n/a |
| Red Hat Enterprise Linux 6 | firefox | Out of support scope | n/a |
| Red Hat Enterprise Linux 6 | thunderbird | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | thunderbird | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory.
References (36)
- https://access.redhat.com/errata/RHSA-2026:19153
- https://access.redhat.com/errata/RHSA-2026:19157
- https://access.redhat.com/errata/RHSA-2026:19348
- https://access.redhat.com/errata/RHSA-2026:19370
- https://access.redhat.com/errata/RHSA-2026:19588
- https://access.redhat.com/errata/RHSA-2026:20586
- https://access.redhat.com/errata/RHSA-2026:21743
- https://access.redhat.com/errata/RHSA-2026:22324
- https://access.redhat.com/errata/RHSA-2026:22408
- https://access.redhat.com/errata/RHSA-2026:22409
- https://access.redhat.com/errata/RHSA-2026:22410
- https://access.redhat.com/errata/RHSA-2026:22708
- https://access.redhat.com/errata/RHSA-2026:22712
- https://access.redhat.com/errata/RHSA-2026:22847
- https://access.redhat.com/errata/RHSA-2026:24345
- https://access.redhat.com/errata/RHSA-2026:24717
- https://access.redhat.com/errata/RHSA-2026:24718
- https://access.redhat.com/errata/RHSA-2026:24719
- https://access.redhat.com/errata/RHSA-2026:24721
- https://access.redhat.com/errata/RHSA-2026:24844
- https://access.redhat.com/errata/RHSA-2026:24846
- https://access.redhat.com/errata/RHSA-2026:25014
- https://access.redhat.com/security/cve/CVE-2026-7322 Vendor Advisory
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2021904%2C2022731%2C2027158%2C2027733%2C2027973%2C2027976%2C2028231%2C2028731%2C2028886%2C2029067%2C2029700%2C2029724%2C2029806%2C2029814%2C2030108%2C2030111%2C2031524%2C2031921%2C2032040 Broken Link
- https://bugzilla.redhat.com/show_bug.cgi?id=2463484 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-26059 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-7322
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-7322.json
- https://www.cve.org/CVERecord?id=CVE-2026-7322
- https://www.mozilla.org/security/advisories/mfsa2026-35/ Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2026-36/ Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2026-36/#CVE-2026-7322
- https://www.mozilla.org/security/advisories/mfsa2026-37/ Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2026-38/ Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2026-39/ Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2026-39/#CVE-2026-7322
Change history (0)
No recorded changes yet.