SB2026072304 - openEuler 24.03 LTS SP4 update for thunderbird



SB2026072304 - openEuler 24.03 LTS SP4 update for thunderbird

Published: July 23, 2026

Security Bulletin ID SB2026072304
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 2
Exploitation vector Remote access
Highest impact Denial of service

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 2 vulnerabilities.


1) Uncontrolled Memory Allocation (CVE-ID: CVE-2026-57962)

CWE-ID: CWE-789 - Uncontrolled Memory Allocation

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to uncontrolled memory allocation in the Thunderbird LDAP client when querying a malicious LDAP address-book server for autocomplete. A remote attacker can return arbitrarily large amounts of attacker-supplied data to cause a denial of service.


2) Cross-site scripting (CVE-ID: CVE-2026-57963)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote attacker to manipulate the chat user interface.

The vulnerability exists due to improper neutralization of HTML content in the chat message rendering component when processing HTML chat messages sent via Matrix or XMPP. A remote attacker can send a crafted HTML chat message containing styled content, phishing links, and CSS to manipulate the chat user interface.


Remediation

Install update from vendor's website.