AlmaLinux 9.2 [TuxCare] Security Update: thunderbird Multiple Vulnerabilities (ALMALINUX9.2:CLSA-2026:1785560172)

critical Nessus Plugin ID 360088

Synopsis

The AlmaLinux host is missing one or more security updates.

Description

The AlmaLinux 9.2 host has a package installed that is affected by multiple vulnerabilities as referenced in the TuxCare ALMALINUX9.2:CLSA-2026:1785560172 advisory.

- Certificate OCSP revocation status was not checked when verifying S/Mime signatures. Mail signed with a revoked certificate would be displayed as having a valid signature. Thunderbird versions from 68 to 102.7.0 were affected by this bug. This vulnerability affects Thunderbird < 102.7.1. (CVE-2023-0430)

- If a MIME email combines OpenPGP and OpenPGP MIME data in a certain way Thunderbird repeatedly attempts to process and display the message, which could cause Thunderbird's user interface to lock up and no longer respond to the user's actions. An attacker could send a crafted message with this structure to attempt a DoS attack. This vulnerability affects Thunderbird < 102.8. (CVE-2023-0616)

- Unexpected data returned from the Safe Browsing API could have led to memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 102.10 and Firefox ESR < 102.10.
(CVE-2023-1945)

- Due to the Firefox GTK wrapper code's use of text/plain for drag data and GTK treating all text/plain MIMEs containing file URLs as being dragged a website could arbitrarily read a file via a call to `DataTransfer.setData`. This vulnerability affects Firefox < 109, Firefox ESR < 102.7, and Thunderbird < 102.7. (CVE-2023-23598)

- When importing a SPKI RSA public key as ECDSA P-256, the key would be handled incorrectly causing the tab to crash. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.
(CVE-2023-25742)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected thunderbird package based on the guidance in TuxCare advisory ALMALINUX9.2:CLSA-2026:1785560172.

See Also

https://cve.tuxcare.com/els/releases/CLSA-2026:1785560172

http://www.nessus.org/u?89e6800e

Plugin Details

Severity: Critical

ID: 360088

File Name: tuxcare_alma_linux_9.2_CLSA-2026-1785560172.nasl

Version: 1.1

Type: Local

Published: 10/1/2026

Updated: 10/1/2026

Supported Sensors: Nessus Agent, Continuous Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

Risk Information

VPR

Risk Factor: High

Score: 7.6

Percentile: 98.37

Vendor

Vendor Severity: Critical

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2026-4710

CVSS v3

Risk Factor: Critical

Base Score: 10

Temporal Score: 9

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

CVSS Score Source: CVE-2026-4692

Vulnerability Information

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/AlmaLinux/release, Host/AlmaLinux/rpm-list, Host/OS/extended-third-party

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 8/1/2026

Vulnerability Publication Date: 8/31/2022

Reference Information

CVE: CVE-2022-3032, CVE-2023-0430, CVE-2023-0547, CVE-2023-0616, CVE-2023-1945, CVE-2023-23598, CVE-2023-23599, CVE-2023-23601, CVE-2023-23602, CVE-2023-25728, CVE-2023-25730, CVE-2023-25737, CVE-2023-25742, CVE-2023-25751, CVE-2023-25752, CVE-2023-28164, CVE-2023-29533, CVE-2023-29535, CVE-2023-29536, CVE-2023-29539, CVE-2023-29548, CVE-2023-32206, CVE-2023-32211, CVE-2023-37207, CVE-2023-4573, CVE-2023-4574, CVE-2023-4575, CVE-2023-4577, CVE-2023-4578, CVE-2023-4580, CVE-2023-4581, CVE-2023-50761, CVE-2023-50762, CVE-2023-5169, CVE-2023-5171, CVE-2023-5724, CVE-2023-5725, CVE-2023-5732, CVE-2023-6204, CVE-2023-6205, CVE-2023-6206, CVE-2023-6207, CVE-2023-6208, CVE-2023-6209, CVE-2023-6212, CVE-2023-6856, CVE-2023-6857, CVE-2023-6859, CVE-2023-6860, CVE-2023-6862, CVE-2023-6863, CVE-2023-6864, CVE-2024-0746, CVE-2024-0750, CVE-2024-0751, CVE-2024-10458, CVE-2024-10459, CVE-2024-10460, CVE-2024-10461, CVE-2024-10462, CVE-2024-10463, CVE-2024-10464, CVE-2024-10465, CVE-2024-10466, CVE-2024-10467, CVE-2024-10468, CVE-2024-11159, CVE-2024-11692, CVE-2024-11693, CVE-2024-11694, CVE-2024-11695, CVE-2024-11696, CVE-2024-11697, CVE-2024-11700, CVE-2024-11701, CVE-2024-11702, CVE-2024-11704, CVE-2024-11705, CVE-2024-11706, CVE-2024-11708, CVE-2024-1546, CVE-2024-1547, CVE-2024-1548, CVE-2024-1549, CVE-2024-1550, CVE-2024-1551, CVE-2024-1553, CVE-2024-2608, CVE-2024-2609, CVE-2024-2610, CVE-2024-2611, CVE-2024-2612, CVE-2024-2614, CVE-2024-2616, CVE-2024-3302, CVE-2024-3852, CVE-2024-3857, CVE-2024-3859, CVE-2024-3861, CVE-2024-3864, CVE-2024-4767, CVE-2024-4768, CVE-2024-4769, CVE-2024-4770, CVE-2024-4777, CVE-2024-5688, CVE-2024-5690, CVE-2024-5691, CVE-2024-5693, CVE-2024-5696, CVE-2024-5700, CVE-2024-6600, CVE-2024-6601, CVE-2024-6602, CVE-2024-6603, CVE-2024-6604, CVE-2024-6606, CVE-2024-6607, CVE-2024-6608, CVE-2024-6609, CVE-2024-6610, CVE-2024-6611, CVE-2024-6612, CVE-2024-6613, CVE-2024-6614, CVE-2024-7518, CVE-2024-7521, CVE-2024-7522, CVE-2024-7525, CVE-2024-7526, CVE-2024-7527, CVE-2024-7529, CVE-2024-7652, CVE-2024-8394, CVE-2024-9392, CVE-2024-9393, CVE-2024-9394, CVE-2024-9396, CVE-2024-9397, CVE-2024-9398, CVE-2024-9399, CVE-2024-9400, CVE-2024-9401, CVE-2025-0237, CVE-2025-0238, CVE-2025-0239, CVE-2025-0240, CVE-2025-0241, CVE-2025-0242, CVE-2025-0247, CVE-2025-0510, CVE-2025-1009, CVE-2025-1010, CVE-2025-1012, CVE-2025-1013, CVE-2025-1014, CVE-2025-1015, CVE-2025-1016, CVE-2025-1018, CVE-2025-1019, CVE-2025-10527, CVE-2025-10528, CVE-2025-10529, CVE-2025-10532, CVE-2025-10533, CVE-2025-10536, CVE-2025-11708, CVE-2025-11709, CVE-2025-11710, CVE-2025-11711, CVE-2025-11712, CVE-2025-11713, CVE-2025-11714, CVE-2025-14322, CVE-2025-14323, CVE-2025-14328, CVE-2025-14329, CVE-2025-14331, CVE-2025-1931, CVE-2025-1932, CVE-2025-1933, CVE-2025-1934, CVE-2025-1935, CVE-2025-1936, CVE-2025-1937, CVE-2025-1938, CVE-2025-1942, CVE-2025-26695, CVE-2025-26696, CVE-2025-3028, CVE-2025-3029, CVE-2025-3030, CVE-2025-3031, CVE-2025-3032, CVE-2025-3033, CVE-2025-5262, CVE-2025-5986, CVE-2025-8027, CVE-2025-8028, CVE-2025-8029, CVE-2025-8030, CVE-2025-8031, CVE-2025-8032, CVE-2025-8033, CVE-2025-8034, CVE-2025-8035, CVE-2025-8036, CVE-2025-8037, CVE-2025-9179, CVE-2025-9180, CVE-2025-9181, CVE-2025-9182, CVE-2025-9184, CVE-2025-9185, CVE-2026-0818, CVE-2026-0879, CVE-2026-0882, CVE-2026-0883, CVE-2026-0884, CVE-2026-0885, CVE-2026-0886, CVE-2026-0887, CVE-2026-0890, CVE-2026-12289, CVE-2026-12305, CVE-2026-12306, CVE-2026-12309, CVE-2026-12324, CVE-2026-2447, CVE-2026-2769, CVE-2026-2772, CVE-2026-2773, CVE-2026-2774, CVE-2026-2779, CVE-2026-2782, CVE-2026-2786, CVE-2026-2787, CVE-2026-2788, CVE-2026-2789, CVE-2026-2790, CVE-2026-3889, CVE-2026-4371, CVE-2026-4692, CVE-2026-4694, CVE-2026-4710, CVE-2026-4718, CVE-2026-4721, CVE-2026-5731, CVE-2026-8090, CVE-2026-8091, CVE-2026-8092, CVE-2026-8094

CLSA: 2026:1785560172