Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Fedora 39: Chromium Buffer Overflow Vulnerabilities Critical Update

fedora
Calendar Grey February 23, 2024
Dist Fedora Esm H88
Important announcement for Fedora 39: chromium fixes numerous vulnerabilities, notably several relating to out-of-bounds memory issues.
update to 122.0.6261.57 High CVE-2024-1669: Out of bounds memory access in Blink High CVE-2024-1670: Use after free in Mojo Medium CVE-2024-1671: Inappropriate implementation in Si...

Summary

Chromium is an open-source web browser, powered by WebKit (Blink).

Update Information:

update to 122.0.6261.57 High CVE-2024-1669: Out of bounds memory access in Blink High CVE-2024-1670: Use after free in Mojo Medium CVE-2024-1671: Inappropriate implementation in Site Isolation Medium CVE-2024-1672: Inappropriate implementation in Content Security Policy Medium CVE-2024-1673: Use after free in Accessibility Medium CVE-2024-1674: Inappropriate implementation in Navigation Medium CVE-2024-1675: Insufficient policy enforcement in Download Low CVE-2024-1676: Inappropriate implementation in Navigation

Change Log

* Wed Feb 21 2024 Than Ngo - 122.0.6261.57-1 - update to 122.0.6261.57 * High CVE-2024-1669: Out of bounds memory access in Blink * High CVE-2024-1670: Use after free in Mojo * Medium CVE-2024-1671: Inappropriate implementation in Site Isolation * Medium CVE-2024-1672: Inappropriate implementation in Content Security Policy * Medium CVE-2024-1673: Use after free in Accessibility * Medium CVE-2024-1674: Inappropriate implementation in Navigation * Medium CVE-2024-1675: Insufficient policy enforcement in Download * Low CVE-2024-1676: Inappropriate implementation in Navigation. * Sun Feb 18 2024 Than Ngo - 122.0.6261.39-1 - update to 122.0.6261.39

References


[ 1 ] Bug #2257887 - CVE-2024-0232 chromium: sqlite: use-after-free bug in jsonParseAddNodeArray [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2257887 [ 2 ] Bug #2265255 - CVE-2024-1669 CVE-2024-1670 CVE-2024-1671 CVE-2024-1672 CVE-2024-1673 CVE-2024-1674 CVE-2024-1675 CVE-2024-1676 chromium: various flaws [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2265255

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-4adf990562' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html

Severity
critical
Lowest
Low
Medium
High
Critical

Name: chromium
Product: Fedora 39
Version: 122.0.6261.57
Release: 1.fc39
Summary: A WebKit (Blink) powered web browser that Google doesn't want you to use

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here