Bug 34155 - Thunderbird 128.9
Summary: Thunderbird 128.9
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 9
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA9-64-OK
Keywords: advisory, validated_update
Depends on: 34153
Blocks:
  Show dependency treegraph
 
Reported: 2025-04-02 09:16 CEST by Nicolas Salguero
Modified: 2025-04-05 20:47 CEST (History)
6 users (show)

See Also:
Source RPM: thunderbird, thunderbird-l10n
CVE: CVE-2025-3028, CVE-2025-3029, CVE-2025-3030
Status comment:


Attachments

Description Nicolas Salguero 2025-04-02 09:16:59 CEST
Mozilla has released Thunderbird 128.9 on April 1:
https://www.thunderbird.net/en-US/thunderbird/128.9.0esr/releasenotes/

Security issues fixed:
https://www.mozilla.org/en-US/security/advisories/mfsa2025-24/
Nicolas Salguero 2025-04-02 09:17:37 CEST

CVE: (none) => CVE-2025-3028, CVE-2025-3029, CVE-2025-3030
Whiteboard: (none) => MGA9TOO
Source RPM: (none) => thunderbird, thunderbird-l10n
Depends on: (none) => 34153

Comment 1 Nicolas Salguero 2025-04-02 14:25:25 CEST
Suggested advisory:
========================

The updated packages fix a security vulnerability:

Use-after-free triggered by XSLTProcessor. (CVE-2025-3028)

URL Bar Spoofing via non-BMP Unicode characters. (CVE-2025-3029)

Memory safety bugs fixed in Firefox 137, Thunderbird 137, Firefox ESR 128.9, and Thunderbird 128.9. (CVE-2025-3030)

References:
https://www.thunderbird.net/en-US/thunderbird/128.9.0esr/releasenotes/
https://www.mozilla.org/en-US/security/advisories/mfsa2025-24/
========================

Updated packages in core/updates_testing:
========================
thunderbird-128.9.0-1.mga9
thunderbird-af-128.9.0-1.mga9
thunderbird-ar-128.9.0-1.mga9
thunderbird-ast-128.9.0-1.mga9
thunderbird-be-128.9.0-1.mga9
thunderbird-bg-128.9.0-1.mga9
thunderbird-br-128.9.0-1.mga9
thunderbird-ca-128.9.0-1.mga9
thunderbird-cs-128.9.0-1.mga9
thunderbird-cy-128.9.0-1.mga9
thunderbird-da-128.9.0-1.mga9
thunderbird-de-128.9.0-1.mga9
thunderbird-dsb-128.9.0-1.mga9
thunderbird-el-128.9.0-1.mga9
thunderbird-en_CA-128.9.0-1.mga9
thunderbird-en_GB-128.9.0-1.mga9
thunderbird-en_US-128.9.0-1.mga9
thunderbird-es_AR-128.9.0-1.mga9
thunderbird-es_ES-128.9.0-1.mga9
thunderbird-es_MX-128.9.0-1.mga9
thunderbird-et-128.9.0-1.mga9
thunderbird-eu-128.9.0-1.mga9
thunderbird-fi-128.9.0-1.mga9
thunderbird-fr-128.9.0-1.mga9
thunderbird-fy_NL-128.9.0-1.mga9
thunderbird-ga_IE-128.9.0-1.mga9
thunderbird-gd-128.9.0-1.mga9
thunderbird-gl-128.9.0-1.mga9
thunderbird-he-128.9.0-1.mga9
thunderbird-hr-128.9.0-1.mga9
thunderbird-hsb-128.9.0-1.mga9
thunderbird-hu-128.9.0-1.mga9
thunderbird-hy_AM-128.9.0-1.mga9
thunderbird-id-128.9.0-1.mga9
thunderbird-is-128.9.0-1.mga9
thunderbird-it-128.9.0-1.mga9
thunderbird-ja-128.9.0-1.mga9
thunderbird-ka-128.9.0-1.mga9
thunderbird-kab-128.9.0-1.mga9
thunderbird-kk-128.9.0-1.mga9
thunderbird-ko-128.9.0-1.mga9
thunderbird-lt-128.9.0-1.mga9
thunderbird-lv-128.9.0-1.mga9
thunderbird-ms-128.9.0-1.mga9
thunderbird-nb_NO-128.9.0-1.mga9
thunderbird-nl-128.9.0-1.mga9
thunderbird-nn_NO-128.9.0-1.mga9
thunderbird-pa_IN-128.9.0-1.mga9
thunderbird-pl-128.9.0-1.mga9
thunderbird-pt_BR-128.9.0-1.mga9
thunderbird-pt_PT-128.9.0-1.mga9
thunderbird-ro-128.9.0-1.mga9
thunderbird-ru-128.9.0-1.mga9
thunderbird-sk-128.9.0-1.mga9
thunderbird-sl-128.9.0-1.mga9
thunderbird-sq-128.9.0-1.mga9
thunderbird-sr-128.9.0-1.mga9
thunderbird-sv_SE-128.9.0-1.mga9
thunderbird-th-128.9.0-1.mga9
thunderbird-tr-128.9.0-1.mga9
thunderbird-uk-128.9.0-1.mga9
thunderbird-uz-128.9.0-1.mga9
thunderbird-vi-128.9.0-1.mga9
thunderbird-zh_CN-128.9.0-1.mga9
thunderbird-zh_TW-128.9.0-1.mga9

from SRPMS:
thunderbird-128.9.0-1.mga9.src.rpm
thunderbird-l10n-128.9.0-1.mga9.src.rpm

Version: Cauldron => 9
Assignee: bugsquad => qa-bugs
Whiteboard: MGA9TOO => (none)
Status: NEW => ASSIGNED

Comment 2 Jose Manuel López 2025-04-02 17:00:56 CEST
Hi, installed in Mageia9 x86_64 no issues for the moment.

I have created a new account with sync calendars and contacts. 

Works fine for me.

Greetings!

CC: (none) => Joselp

katnatek 2025-04-02 17:47:24 CEST

Keywords: (none) => advisory

Comment 3 Morgan Leijström 2025-04-04 19:53:28 CEST
OK mga9-64 on my workstation svarten

Plasma X11, Swedish locale
Intel Core i7 870, GPU: AMD Navi 24 Radeon RX 6400

$ thunderbird --version
Thunderbird 128.9.0esr

Repeated tests like I use to perform:

Closed Thunderbird, data backup, updated, started:
Thunderbird just keep working OK:
Opened tabs restored
Settings and local mail kept
IMAP (offline, IMAP to synk to server)
SMTP
Sent and received mail with inline png and attached pdf
Viewed attached pdf in Thunderbird, and printed to network printer.

I do not use calendar nor tasks or filters.

CC: (none) => fri

Comment 4 Len Lawrence 2025-04-04 21:46:11 CEST
mga9, x64

Installed and relaunched without complaint.  All data preserved including a loaded attachment.  Checked SMTP server settings.  Messages coming in regularly over several hours.  Tried the Search tool, which returned dozens of hits in milliseconds in a long scrollable list.

On this occasion, having neglected to make an up-to-date backup of Local Folders, it was a relief to see that all data had been retained.  No need to worry about new profile.

Definitely OK here.

CC: (none) => tarazed25

Comment 5 Herman Viaene 2025-04-05 11:48:47 CEST
MGA9-64 Plasma Wayland on Compaq H000SB.
No installation issues.
Send and receive mails without and with attachment works OK. Googel calender nicely synchronizes. Good enough for me.

CC: (none) => herman.viaene

Comment 6 Morgan Leijström 2025-04-05 18:42:22 CEST
Do we need 32 bit tests too?

Whiteboard: (none) => MGA9-64-OK

Comment 7 Thomas Andrews 2025-04-05 19:21:26 CEST
MGA9-64 Plasma, on two machines. 

Using it for a few days now. One machine, my main production install was completely OK. 

The other is OK for email, but when first installed all the Usenet history was wiped out. Newsgroup subscriptions were still there, but no downloaded headers and (of course) no information on which posts had been read/unread. It's never happened before, was only on the one install, and operation has been normal since, so I believe it was some kind of outside aberration, not related to the update.

CC: (none) => andrewsfarm

Comment 8 Thomas Andrews 2025-04-05 19:46:26 CEST
We have validated on just 64-bit tests before, several times, so I think it will be enough this time, too.

Validating.

CC: (none) => sysadmin-bugs
Keywords: (none) => validated_update

Comment 9 Mageia Robot 2025-04-05 20:47:55 CEST
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2025-0126.html

Resolution: (none) => FIXED
Status: ASSIGNED => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.