Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

Fedora 39 Advisory: Critical Chromium Buffer Overflow Issues Identified

fedora
Calendar Grey June 14, 2024
Dist Fedora Esm H88
Fedora 39 has released a pivotal update for Chromium, which resolves several critical vulnerabilities, featuring issues like type confusion and heap buffer overflow exploits.
update to 126.0.6478.55 High CVE-2024-5830: Type Confusion in V8 High CVE-2024-5831: Use after free in Dawn High CVE-2024-5832: Use after free in Dawn High CVE-2024-5833: Type Conf...

Summary

Chromium is an open-source web browser, powered by WebKit (Blink).

Update Information:

update to 126.0.6478.55 High CVE-2024-5830: Type Confusion in V8 High CVE-2024-5831: Use after free in Dawn High CVE-2024-5832: Use after free in Dawn High CVE-2024-5833: Type Confusion in V8 High CVE-2024-5834: Inappropriate implementation in Dawn High CVE-2024-5835: Heap buffer overflow in Tab Groups High CVE-2024-5836: Inappropriate Implementation in DevTools High CVE-2024-5837: Type Confusion in V8 High CVE-2024-5838: Type Confusion in V8 Medium CVE-2024-5839: Inappropriate Implementation in Memory Allocator Medium CVE-2024-5840: Policy Bypass in CORS Medium CVE-2024-5841: Use after free in V8 Medium CVE-2024-5842: Use after free in Browser UI Medium CVE-2024-5843: Inappropriate implementation in Downloads Medium CVE-2024-5844: Heap buffer overflow in Tab Strip Medium CVE-2024-5845: Use after free in Audio Medium CVE-2024-5846: Use after free in PDFium Medium CVE-2024-5847: Use after free in PDFium

Change Log

* Wed Jun 12 2024 Than Ngo - 126.0.6478.55-1 - update to 126.0.6478.55 * High CVE-2024-5830: Type Confusion in V8 * High CVE-2024-5831: Use after free in Dawn * High CVE-2024-5832: Use after free in Dawn * High CVE-2024-5833: Type Confusion in V8 * High CVE-2024-5834: Inappropriate implementation in Dawn * High CVE-2024-5835: Heap buffer overflow in Tab Groups * High CVE-2024-5836: Inappropriate Implementation in DevTools * High CVE-2024-5837: Type Confusion in V8 * High CVE-2024-5838: Type Confusion in V8 * Medium CVE-2024-5839: Inappropriate Implementation in Memory Allocator * Medium CVE-2024-5840: Policy Bypass in CORS * Medium CVE-2024-5841: Use after free in V8 * Medium CVE-2024-5842: Use after free in Browser UI * Medium CVE-2024-5843: Inappropriate implementation in Downloads * Medium CVE-2024-5844: Heap buffer overflow in Tab Strip * Medium CVE-2024-5845: Use after free in Audio * Medium CVE-2024-5846: Use after free in PDFium * Medium CVE-2024-5847: Use after free in PDFium

References


[ 1 ] Bug #2291363 - 126.0.6478.54 is available, fixing 21 CVEs https://bugzilla.redhat.com/show_bug.cgi?id=2291363

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-86e4115138' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
critical
Lowest
Low
Medium
High
Critical

Name: chromium
Product: Fedora 39
Version: 126.0.6478.55
Release: 1.fc39
Summary: A WebKit (Blink) powered web browser that Google doesn't want you to use

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here