- Add thunderbird-glibc-2.43.patch as source22 and apply it only
if glibc newer than 2.42 is installed in the build environment.
It serves to remove conflicting definitions and adapt the syscall
in accordance with glibc-2.43.
- Further tests have shown that the rule which llvm version should
be used, can be simplified: only on TW, Slowroll and Factory we
need to explicitly BuildRequire the llvm21 based packages, while
on all other (i.e. Leap) distribution versions we can stick with
the distro's default release of llvm.
- Mozilla Thunderbird 140.10.1 ESR
MFSA 2026-39 (bsc#1263110)
* CVE-2026-7320 (bmo#2027433)
Information disclosure due to incorrect boundary conditions
in the Audio/Video component
* CVE-2026-7321 (bmo#2029461)
Sandbox escape due to incorrect boundary conditions in the
WebRTC: Networking component
* CVE-2026-7322 (bmo#2021904, bmo#2022731, bmo#2027158,
bmo#2027733, bmo#2027973, bmo#2027976, bmo#2028231,
bmo#2028731, bmo#2028886, bmo#2029067, bmo#2029700,
bmo#2029724, bmo#2029806, bmo#2029814, bmo#2030108,
bmo#2030111, bmo#2031524, bmo#2031921, bmo#2032040)
Memory safety bugs fixed in Thunderbird ESR 140.10.1 and
Thunderbird 150.0.1
* CVE-2026-7323 (bmo#2028537, bmo#2029911, bmo#2031121,
bmo#2033602)
Memory safety bugs fixed in Thunderbird ESR 140.10.1 and
Thunderbird 150.0.1
OBS-URL: https://build.opensuse.org/request/show/1350963
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/MozillaThunderbird?expand=0&rev=386
Description
No description provided
Languages
Shell
96.6%
JavaScript
3.4%