Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Fedora 38: FEDORA-2024-b7h3401cde critical: firefox memory overflow issues

fedora
Calendar Grey January 7, 2024
Dist Fedora Esm H88
Launch of Chromium version 120.0.6099.201 addressing critical memory management and use-after-free security flaws.
update to 120.0.6099.199 - CVE-2023-6879 aom: heap-buffer-overflow on frame size change - CVE-2023-7104 sqlite: heap-buffer-overflow at sessionfuzz - CVE-2024-0222: Use after free...

Summary

Chromium is an open-source web browser, powered by WebKit (Blink).

Update Information:

update to 120.0.6099.199 - CVE-2023-6879 aom: heap-buffer-overflow on frame size change - CVE-2023-7104 sqlite: heap-buffer-overflow at sessionfuzz - CVE-2024-0222: Use after free in ANGLE - CVE-2024-0223: Heap buffer overflow in ANGLE - CVE-2024-0224: Use after free in WebAudio - CVE-2024-0225: Use after free in WebGPU

Change Log

* Thu Jan 4 2024 Than Ngo - 120.0.6099.199-1 - new gn update, drop workaround for broken gn on epel 8/9 - update to 120.0.6099.199 * CVE-2024-0222: Use after free in ANGLE * CVE-2024-0223: Heap buffer overflow in ANGLE * CVE-2024-0224: Use after free in WebAudio * CVE-2024-0225: Use after free in WebGPU

References

Fedora Update Notification FEDORA-2024-a6c2300bca 2024-01-07 00:41:24.072036 Name : chromium Product : Fedora 38 Version : 120.0.6099.199 Release : 1.fc38 URL : https://www.chromium.org/Home/ Summary : A WebKit (Blink) powered web browser that Google doesn't want you to use Description : Chromium is an open-source web browser, powered by WebKit (Blink).

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-a6c2300bca' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html

Severity
critical
Lowest
Low
Medium
High
Critical

Name: chromium
Product: Fedora 38
Version: 120.0.6099.199
Release: 1.fc38
Summary: A WebKit (Blink) powered web browser that Google doesn't want you to use

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here