CVE-2026-103500
Publication date 2 October 2026
Last updated 2 October 2026
Ubuntu priority
Description
An attacker could cause a heap buffer overflow by getting a user to open an email that is greater than or equal to 2GB in size. This vulnerability was fixed in Thunderbird 157, Thunderbird 140.17, and Thunderbird 153.4.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| thunderbird | 26.04 LTS resolute |
Needs evaluation
|
| 24.04 LTS noble |
Needs evaluation
|
|
| 22.04 LTS jammy |
Needs evaluation
|
References
Other references
- https://www.cve.org/CVERecord?id=CVE-2026-103500
- https://www.mozilla.org/en-US/security/advisories/mfsa2026-103/#CVE-2026-103500
- https://bugzilla.mozilla.org/show_bug.cgi?id=2070267
- https://www.mozilla.org/security/advisories/mfsa2026-101/
- https://www.mozilla.org/security/advisories/mfsa2026-102/
- https://www.mozilla.org/security/advisories/mfsa2026-103/