Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

Fedora 38: FEDORA-2023-5b46676afa high: chromium use after free

fedora
Calendar Grey November 26, 2023
Dist Fedora Esm H88
Fedora package update alert for Chromium resolves CVE-2023-5997 and CVE-2023-6112, featuring significant bug fixes.
update to 119.0.6045.159, upstream security release - High CVE-2023-5997, use after free in Garbage Collection - High CVE-2023-6112, use after free in Navigation ---- Fix bz#2240...

Summary

Chromium is an open-source web browser, powered by WebKit (Blink).

Update Information:

update to 119.0.6045.159, upstream security release - High CVE-2023-5997, use after free in Garbage Collection - High CVE-2023-6112, use after free in Navigation ---- Fix bz#2240127, audio/video decode issue in chromium

Change Log

* Sun Nov 19 2023 Than Ngo - 119.0.6045.159-2 - fix ffmpeg conflicts * Wed Nov 15 2023 Than Ngo - 119.0.6045.159-1 - update to 119.0.6045.159, upstream security release High CVE-2023-5997, use after free in Garbage Collection High CVE-2023-6112, use after free in Navigation - add Requires/Conflicts for ABI break in fmpeg-free 6.0.1 - drop first_dts patch, reintroduce first_dts patch in ffmpeg-free-6.0.1 - fixed python3 syntaxWarning: invalid escape sequenc - skip clang's patches for epel8 that now gets clang-16 update * Mon Nov 13 2023 Than Ngo - 119.0.6045.123-2 - fixed bz#2240127, Some h.264 mp4s do not play

References


[ 1 ] Bug #2240127 - Some h.264 mp4s do not play on fedora chromium, while they do on other chromium packages (i.e. rpm build from source, flatpak) https://bugzilla.redhat.com/show_bug.cgi?id=2240127

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-5b46676afa' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html

Name: chromium
Product: Fedora 38
Version: 119.0.6045.159
Release: 2.fc38
Summary: A WebKit (Blink) powered web browser that Google doesn't want you to use

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here