Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Fedora 39: FEDORA-2024-4e0ea1c22e High: Chromium Multiple Issues

fedora
Calendar Grey June 2, 2024
Dist Fedora Esm H88
Fedora 39 Chromium update addresses several critical CVEs impacting WebRTC and Media Sessions; necessary patches are now available.
update to 125.0.6422.141 High CVE-2024-5493: Heap buffer overflow in WebRTC High CVE-2024-5494: Use after free in Dawn High CVE-2024-5495: Use after free in Dawn High CVE-2024-5496...

Summary

Chromium is an open-source web browser, powered by WebKit (Blink).

Update Information:

update to 125.0.6422.141 High CVE-2024-5493: Heap buffer overflow in WebRTC High CVE-2024-5494: Use after free in Dawn High CVE-2024-5495: Use after free in Dawn High CVE-2024-5496: Use after free in Media Session High CVE-2024-5497: Out of bounds memory access in Keyboard Inputs High CVE-2024-5498: Use after free in Presentation API High CVE-2024-5499: Out of bounds write in Streams API

Change Log

* Fri May 31 2024 Than Ngo - 125.0.6422.141-1 - update to 125.0.6422.141 * High CVE-2024-5493: Heap buffer overflow in WebRTC * High CVE-2024-5494: Use after free in Dawn * High CVE-2024-5495: Use after free in Dawn * High CVE-2024-5496: Use after free in Media Session * High CVE-2024-5497: Out of bounds memory access in Keyboard Inputs * High CVE-2024-5498: Use after free in Presentation API * High CVE-2024-5499: Out of bounds write in Streams API - fixed rhbz#2264332 - Chromium is unable to send/receive video on MS Teams - cleanup chromium.conf * Wed May 29 2024 Than Ngo - 125.0.6422.112-3 - build against noopenh264 * Tue May 28 2024 Than Ngo - 125.0.6422.112-2 - Workaround for build error on pp64le

References


[ 1 ] Bug #2264332 - Chromium is unable to send/receive video on MS Teams https://bugzilla.redhat.com/show_bug.cgi?id=2264332

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-4e0ea1c22e' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Name: chromium
Product: Fedora 39
Version: 125.0.6422.141
Release: 1.fc39
Summary: A WebKit (Blink) powered web browser that Google doesn't want you to use

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here