Uncontrolled Memory Allocation in Mozilla Thunderbird - CVE-2026-57962
Published: July 22, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled memory allocation in the Thunderbird LDAP client when querying a malicious LDAP address-book server for autocomplete. A remote attacker can return arbitrarily large amounts of attacker-supplied data to cause a denial of service.
Affected software
Debian Linux
openEuler
thunderbird
thunderbird-debuginfo
thunderbird-debugsource
thunderbird-librnp-rnp
thunderbird-wayland
thunderbird (Debian package)
How to mitigate CVE-2026-57962
thunderbird - update to 140.12.1-1
thunderbird-debuginfo - update to 140.12.1-1
thunderbird-debugsource - update to 140.12.1-1
thunderbird-librnp-rnp - update to 140.12.1-1
thunderbird-wayland - update to 140.12.1-1
thunderbird (Debian package) - update to 1:140.13.0esr-2~deb13u1