Debian 10880 Published by

Debian Long Term Support teams have released urgent security patches for both Thunderbird and ImageMagick to address critical flaws in their software suites. Attackers could exploit the Thunderbird vulnerabilities to execute arbitrary code on any affected Debian GNU/Linux 11 (Bullseye) LTS machine. The ImageMagick update tackles a different set of problems entirely, including symlink races, information leaks, and denial of service threats that impact Debian GNU/Linux 9 (Stretch) ELTS environments.

[DLA 4549-1] thunderbird security update
ELA-1696-1 imagemagick security update




[SECURITY] [DLA 4549-1] thunderbird security update


- -------------------------------------------------------------------------
Debian LTS Advisory DLA-4549-1 debian-lts@lists.debian.org
https://www.debian.org/lts/security/ Emilio Pozuelo Monfort
April 26, 2026 https://wiki.debian.org/LTS
- -------------------------------------------------------------------------

Package : thunderbird
Version : 1:140.10.0esr-1~deb11u1
CVE ID : CVE-2026-6746 CVE-2026-6747 CVE-2026-6748 CVE-2026-6749
CVE-2026-6750 CVE-2026-6751 CVE-2026-6752 CVE-2026-6753
CVE-2026-6754 CVE-2026-6757 CVE-2026-6761 CVE-2026-6762
CVE-2026-6763 CVE-2026-6764 CVE-2026-6765 CVE-2026-6766
CVE-2026-6767 CVE-2026-6769 CVE-2026-6770 CVE-2026-6771
CVE-2026-6772 CVE-2026-6776 CVE-2026-6785 CVE-2026-6786

Multiple security issues were discovered in Thunderbird, which could
result in the execution of arbitrary code.

For Debian 11 bullseye, these problems have been fixed in version
1:140.10.0esr-1~deb11u1.

We recommend that you upgrade your thunderbird packages.

For the detailed security status of thunderbird please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/thunderbird

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS



ELA-1696-1 imagemagick security update (by )


Package : imagemagick


Version : 8:6.9.7.4+dfsg-11+deb9u27 (stretch)


Related CVEs :

CVE-2026-25985

CVE-2026-26284

CVE-2026-26983

CVE-2026-28494

CVE-2026-28686

CVE-2026-28687

CVE-2026-28688

CVE-2026-28689

CVE-2026-28690

CVE-2026-28691

CVE-2026-28692

CVE-2026-28693

CVE-2026-30883

CVE-2026-30936

CVE-2026-30937

CVE-2026-31853

CVE-2026-32259

CVE-2026-32636

CVE-2026-33535

CVE-2026-33536



Multiple security vulnerabilities were discovered in imagemagick,
a software suite used for editing and manipulating digital images, which
could lead to symlink races, information leaks, denial of service
and potentially arbitrary code execution.


ELA-1696-1 imagemagick security update (by )