Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Fedora 37 FEDORA-2023-1b99669138 Critical: Chromium Use After Free

fedora
Calendar Grey June 27, 2023
Dist Fedora Esm H88
Important announcement for Fedora 37 concerning various vulnerabilities in the Chromium web browser. Please update to version 114.0.5735.133 immediately.
Update to 114.0.5735.133

Summary

Chromium is an open-source web browser, powered by WebKit (Blink).

Update to 114.0.5735.133. Fixes the following security issues: CVE-2023-3214,

CVE-2023-3215, CVE-2023-3215, CVE-2023-3217,

* Wed Jun 14 2023 Than Ngo - 114.0.5735.133-1

- update to 114.0.5735.133

- Enable AllowQt feature flag

- Fix Qt deps

- Fix Qt logical scale factor

[ 1 ] Bug #2214814 - CVE-2023-3214 chromium-browser: Use after free in Autofill payments

https://bugzilla.redhat.com/show_bug.cgi?id=2214814

[ 2 ] Bug #2214815 - CVE-2023-3215 chromium-browser: Use after free in WebRTC

https://bugzilla.redhat.com/show_bug.cgi?id=2214815

[ 3 ] Bug #2214816 - CVE-2023-3216 chromium-browser: Type Confusion in V8

https://bugzilla.redhat.com/show_bug.cgi?id=2214816

[ 4 ] Bug #2214817 - CVE-2023-3217 chromium-browser: Use after free in WebXR

https://bugzilla.redhat.com/show_bug.cgi?id=2214817

su -c 'dnf upgrade --advisory FEDORA-2023-1b99669138' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Do not reply to spam, report it:

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 37
Version: 114.0.5735.133
Release: 1.fc37
Summary: A WebKit (Blink) powered web browser that Google doesn't want you to use

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here