Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

Fedora 40: FEDORA-2024-4d2d73ab31 High: Chromium Buffer Flaws

fedora
Calendar Grey April 19, 2024
Dist Fedora Esm H88
The latest Fedora 40 patches for Chromium tackle several critical vulnerabilities, including significant issues such as buffer overrun and out-of-bounds access errors.
update to 123.0.6312.122 * High CVE-2024-3157: Out of bounds write in Compositing * High CVE-2024-3516: Heap buffer overflow in ANGLE * High CVE-2024-3515: Use after free in Daw...

Summary

Chromium is an open-source web browser, powered by WebKit (Blink).

Update Information:

update to 123.0.6312.122 * High CVE-2024-3157: Out of bounds write in Compositing * High CVE-2024-3516: Heap buffer overflow in ANGLE * High CVE-2024-3515: Use after free in Dawn update to 123.0.6312.105 High CVE-2024-3156: Inappropriate implementation in V8 High CVE-2024-3158: Use after free in Bookmarks High CVE-2024-3159: Out of bounds memory access in V8

Change Log

* Thu Apr 11 2024 Than Ngo - 123.0.6312.122-1 - update to 123.0.6312.122 * High CVE-2024-3157: Out of bounds write in Compositing * High CVE-2024-3516: Heap buffer overflow in ANGLE * High CVE-2024-3515: Use after free in Dawn * Wed Apr 3 2024 Than Ngo - 123.0.6312.105-1 - update to 123.0.6312.105 * High CVE-2024-3156: Inappropriate implementation in V8 * High CVE-2024-3158: Use after free in Bookmarks * High CVE-2024-3159: Out of bounds memory access in V8

References


[ 1 ] Bug #2274472 - CVE-2024-3157 CVE-2024-3515 CVE-2024-3516 chromium: various flaws [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2274472

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-4d2d73ab31' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Name: chromium
Product: Fedora 40
Version: 123.0.6312.122
Release: 1.fc40
Summary: A WebKit (Blink) powered web browser that Google doesn't want you to use

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here