Gnoppix Security Announcement - 2026-08-23T15:38:03.099-04:00

GSA-6461-1: Critical Thunderbird Security Update

Multiple vulnerabilities in Thunderbird allow remote code execution. Gnoppix Security urges immediate upgrade to patched versions.

Who: All Thunderbird users on Gnoppix 24/25 (oldstable) and Gnoppix 26 (stable).
What: Security fixes for memory safety bugs.
Why: Potential attacker control without user interaction.

Affected Versions

  • Gnoppix 24/25 (oldstable) Thunderbird < 128.3.1
  • Gnoppix 26 (stable) Thunderbird < 128.3.1

Key Fixes

  • CVE-2025-7024: Out-of-bounds write leading to crash or code execution
  • CVE-2025-7025: Use-after-free in snews protocol
  • CVE-2025-7026: Memory safety bugs rated critical

Update immediately via the package manager or official channels.

Mitigation Steps

  • Apply patches: Upgrade to Thunderbird 128.3.1.
  • Verify integrity: Confirm checksums before installation.

No workarounds exist. Upgrade is mandatory. - Please update your systems.