Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Fedora 42 Chromium Critical Heap Overflow Type Confusion CVE-2026-1861

fedora
Calendar Grey February 12, 2026
Dist Fedora Esm H88
Update for Chromium on Fedora 42 addresses critical heap overflow and type confusion, requiring immediate attention.
Update to 144.0.7559.132 * CVE-2026-1861: Heap buffer overflow in libvpx * CVE-2026-1862: Type Confusion in V8

Summary

Chromium is an open-source web browser, powered by WebKit (Blink).

Update Information:

Update to 144.0.7559.132 * CVE-2026-1861: Heap buffer overflow in libvpx * CVE-2026-1862: Type Confusion in V8

Change Log

* Thu Feb 5 2026 Than Ngo - 144.0.7559.132-1 - Update to 144.0.7559.132 * CVE-2026-1861: Heap buffer overflow in libvpx * CVE-2026-1862: Type Confusion in V8 - Add BR on esbuild - Disable devtool bundle - Update scripts for downloading the source

References


[ 1 ] Bug #2436627 - CVE-2026-1861 chromium: Chromium: Arbitrary code execution via crafted HTML page [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2436627 [ 2 ] Bug #2436628 - CVE-2026-1861 chromium: Chromium: Arbitrary code execution via crafted HTML page [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2436628 [ 3 ] Bug #2436629 - CVE-2026-1862 chromium: Chromium: Remote heap corruption via crafted HTML page [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2436629 [ 4 ] Bug #2436630 - CVE-2026-1862 chromium: Chromium: Remote heap corruption via crafted HTML page [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2436630

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-e900558e56' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
critical
Lowest
Low
Medium
High
Critical

Name: chromium
Product: Fedora 42
Version: 144.0.7559.132
Release: 1.fc42
Summary: A WebKit (Blink) powered web browser that Google doesn't want you to use

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here