Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

Fedora 40: 2025-609ed3aaa7 critical: chromium use after free

fedora
Calendar Grey April 5, 2025
Dist Fedora Esm H88
Critical update for Fedora 40 chromium resolves multiple security concerns and addresses various vulnerabilities.
Update to 135.0.7049.52 High CVE-2025-3066: Use after free in Navigations Medium CVE-2025-3067: Inappropriate implementation in Custom Tabs Medium CVE-2025-3068: Inappropriate impl...

Summary

Chromium is an open-source web browser, powered by WebKit (Blink).

Update Information:

Update to 135.0.7049.52 High CVE-2025-3066: Use after free in Navigations Medium CVE-2025-3067: Inappropriate implementation in Custom Tabs Medium CVE-2025-3068: Inappropriate implementation in Intents Medium CVE-2025-3069: Inappropriate implementation in Extensions Medium CVE-2025-3070: Insufficient validation of untrusted input in Extensions Low CVE-2025-3071: Inappropriate implementation in Navigations Low CVE-2025-3072: Inappropriate implementation in Custom Tabs Low CVE-2025-3073: Inappropriate implementation in Autofill Low CVE-2025-3074: Inappropriate implementation in Downloads

Change Log

* Wed Apr 2 2025 Jan Grulich - 135.0.7049.52-2 - Add CFI suppressions for inline PipeWire functions * Tue Apr 1 2025 Than Ngo - 135.0.7049.52-1 - Update to 135.0.7049.52 * Fri Mar 28 2025 Than Ngo - 135.0.7049.41-1 - Update to 135.0.7049.41

References


[ 1 ] Bug #2356787 - CVE-2025-3066 chromium: Use after free in Navigations [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2356787 [ 2 ] Bug #2356788 - CVE-2025-3066 chromium: Use after free in Navigations [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2356788 [ 3 ] Bug #2356789 - CVE-2025-3068 chromium: Inappropriate implementation in Intents [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2356789 [ 4 ] Bug #2356790 - CVE-2025-3068 chromium: Inappropriate implementation in Intents [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2356790 [ 5 ] Bug #2356792 - CVE-2025-3072 chromium: Inappropriate implementation in Custom Tabs [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2356792 [ 6 ] Bug #2356793 - CVE-2025-3072 chromium: Inappropriate implementation in Custom Tabs [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2356793 [ 7 ] Bug #2356794 - CVE-2025-3073 chromi...

Read the Full Advisory

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-609ed3aaa7' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
critical
Lowest
Low
Medium
High
Critical

Name: chromium
Product: Fedora 40
Version: 135.0.7049.52
Release: 2.fc40
Summary: A WebKit (Blink) powered web browser that Google doesn't want you to use

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here