Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Fedora 42: CEF Critical Integer Overflow and WebRTC Fixes 2025-828bc3d3f5

fedora
Calendar Grey July 22, 2025
Dist Fedora Esm H88
A recent patch for CEF has been launched for Fedora 42, tackling vital integer overflow vulnerabilities and WebRTC complications.
Update to cef-138.0.25+g251e1c1/chromium138.0.7204.157 (rhbz#2380429) Update to cef-138.0.21+g54811fe (rhbz#2379500)

Summary

CEF is an embeddable build of Chromium, powered by WebKit (Blink).

Update Information:

Update to cef-138.0.25+g251e1c1/chromium138.0.7204.157 (rhbz#2380429) Update to cef-138.0.21+g54811fe (rhbz#2379500)

Change Log

* Thu Jul 17 2025 Asahi Lina - 138.0.25^chromium138.0.7204.157-1 - Update to cef-138.0.25+g251e1c1 (rhbz#2380429) * Thu Jul 17 2025 Than Ngo - 138.0.21^chromium138.0.7204.157-1 - Update to 138.0.7204.157 - * CVE-2025-7656: Integer overflow in V8 - * CVE-2025-7657: Use after free in WebRTC - * CVE-2025-6558: Incorrect validation of untrusted input in ANGLE and GPU * Sat Jul 12 2025 Asahi Lina - 138.0.21^chromium138.0.7204.100-1 - Update to cef-138.0.21+g54811fe (rhbz#2379500) - Add cherry-pick.sh convenience script * Sat Jul 12 2025 Than Ngo - 138.0.15^chromium138.0.7204.100-1 - Update to 138.0.7204.100

References


[ 1 ] Bug #2379500 - cef-138.0.21 is available https://bugzilla.redhat.com/show_bug.cgi?id=2379500 [ 2 ] Bug #2380429 - cef-138.0.25 is available https://bugzilla.redhat.com/show_bug.cgi?id=2380429

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-828bc3d3f5' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
critical
Lowest
Low
Medium
High
Critical

Name: cef
Product: Fedora 42
Version: 138.0.25^chromium138.0.7204.157
Release: 1.fc42
Summary: Chromium Embedded Framework

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here