Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Fedora 40: FEDORA-2024-85531c965e Critical Type Confusion Threat

fedora
Calendar Grey March 29, 2024
Dist Fedora Esm H88
Important enhancement for Fedora's Firefox tackles various vulnerabilities, prioritizing user protection.
update to 123.0.6312.86 Critical CVE-2024-2883: Use after free in ANGLE High CVE-2024-2885: Use after free in Dawn High CVE-2024-2886: Use after free in WebCodecs High CVE-2024-288...

Summary

Chromium is an open-source web browser, powered by WebKit (Blink).

Update Information:

update to 123.0.6312.86 Critical CVE-2024-2883: Use after free in ANGLE High CVE-2024-2885: Use after free in Dawn High CVE-2024-2886: Use after free in WebCodecs High CVE-2024-2887: Type Confusion in WebAssembly chromium bugfix update

Change Log

* Wed Mar 27 2024 Than Ngo - 123.0.6312.86-2 - update to 123.0.6312.86 * Critical CVE-2024-2883: Use after free in ANGLE * High CVE-2024-2885: Use after free in Daw * High CVE-2024-2886: Use after free in WebCodecs * High CVE-2024-2887: Type Confusion in WebAssembly * Sat Mar 23 2024 Than Ngo - 123.0.6312.58-2 - fixed bz#2269768 - enable build ppc64le package for F40 - fixed bz#2270321 - VAAPI flags in chromium.conf are out of date - fixed bz#2271183 - disable screen ai service

References


[ 1 ] Bug #2269768 - Build for ppc64le https://bugzilla.redhat.com/show_bug.cgi?id=2269768 [ 2 ] Bug #2270321 - VAAPI flags in chromium.conf are out of date https://bugzilla.redhat.com/show_bug.cgi?id=2270321 [ 3 ] Bug #2271183 - chromium: downloads non-free component libchromescreenai.so without asking https://bugzilla.redhat.com/show_bug.cgi?id=2271183

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-85531c965e' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html

Severity
critical
Lowest
Low
Medium
High
Critical

Name: chromium
Product: Fedora 40
Version: 123.0.6312.86
Release: 1.fc40
Summary: A WebKit (Blink) powered web browser that Google doesn't want you to use

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here