GSA-6461-1: Critical Thunderbird Security Update
Multiple vulnerabilities in Thunderbird allow remote code execution. Gnoppix Security urges immediate upgrade to patched versions.
Who: All Thunderbird users on Gnoppix 24/25 (oldstable) and Gnoppix 26 (stable).
What: Security fixes for memory safety bugs.
Why: Potential attacker control without user interaction.
Affected Versions
- Gnoppix 24/25 (oldstable) Thunderbird < 128.3.1
- Gnoppix 26 (stable) Thunderbird < 128.3.1
Key Fixes
- CVE-2025-7024: Out-of-bounds write leading to crash or code execution
- CVE-2025-7025: Use-after-free in snews protocol
- CVE-2025-7026: Memory safety bugs rated critical
Update immediately via the package manager or official channels.
Mitigation Steps
- Apply patches: Upgrade to Thunderbird 128.3.1.
- Verify integrity: Confirm checksums before installation.
No workarounds exist. Upgrade is mandatory. - Please update your systems.