Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

Debian Linux: Unrestricted File Access

DEBIAN-CVE-2026-8956
Summary

A security flaw in Debian Linux can allow unauthorized users to access and modify sensitive files. This affects Debian Linux systems and can compromise system integrity. To protect your system, ensure you have the latest updates installed and consider implementing additional security measures.

What to do
  • Update debian firefox-esr to version 140.11.0esr-1~deb11u1.
  • Update debian firefox-esr to version 140.11.0esr-1~deb12u1.
  • Update debian firefox-esr to version 140.11.0esr-1~deb13u1.
  • Update debian thunderbird to version 1:140.11.0esr-1~deb12u1.
  • Update debian thunderbird to version 1:140.11.0esr-1~deb13u1.
Affected software
Ecosystem VendorProductAffected versions
Debian:11 debian firefox-esr < 140.11.0esr-1~deb11u1
Fix: upgrade to 140.11.0esr-1~deb11u1
Debian:12 debian firefox-esr < 140.11.0esr-1~deb12u1
Fix: upgrade to 140.11.0esr-1~deb12u1
Debian:13 debian firefox-esr < 140.11.0esr-1~deb13u1
Fix: upgrade to 140.11.0esr-1~deb13u1
Debian:14 debian firefox-esr All versions
Debian:11 debian thunderbird All versions
Debian:12 debian thunderbird < 1:140.11.0esr-1~deb12u1
Fix: upgrade to 1:140.11.0esr-1~deb12u1
Debian:13 debian thunderbird < 1:140.11.0esr-1~deb13u1
Fix: upgrade to 1:140.11.0esr-1~deb13u1
Debian:14 debian thunderbird All versions
Original title
Integer overflow in the Networking: JAR component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.
Original description
Integer overflow in the Networking: JAR component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.
Published: 19 May 2026 · Updated: 21 May 2026 · First seen: 19 May 2026