MGASA-2021-0565 - Updated chromium-browser-stable packages fix security vulnerabilities

Publication date: 19 Dec 2021
URL: https://advisories.mageia.org/MGASA-2021-0565.html
Type: security
Affected Mageia releases: 8
CVE: CVE-2021-4098,
     CVE-2021-4099,
     CVE-2021-4100,
     CVE-2021-4101,
     CVE-2021-4102

Updated chromium-browser-stable packages fix security vulnerabilities.

The chromium-browser-stable package has been updated to 96.0.4664.110
version that fixes multiples security vulnerabilities.  One of these CVEs
is known to be actively exploited.

Insufficient data validation in Mojo. (CVE-2021-4098)

Use after free in Swiftshader. (CVE-2021-4099)

Object lifecycle issue in ANGLE. (CVE-2021-4100)

Heap buffer overflow in Swiftshader. (CVE-2021-4101)

Use after free in V8. (CVE-2021-4102)

References:
- https://bugs.mageia.org/show_bug.cgi?id=29765
- https://chromereleases.googleblog.com/2021/12/stable-channel-update-for-desktop_13.html
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-4098
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-4099
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-4100
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-4101
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-4102

SRPMS:
- 8/core/chromium-browser-stable-96.0.4664.110-1.mga8

Mageia 2021-0565: chromium-browser-stable security update

Updated chromium-browser-stable packages fix security vulnerabilities

Summary

Updated chromium-browser-stable packages fix security vulnerabilities.
The chromium-browser-stable package has been updated to 96.0.4664.110 version that fixes multiples security vulnerabilities. One of these CVEs is known to be actively exploited.
Insufficient data validation in Mojo. (CVE-2021-4098)
Use after free in Swiftshader. (CVE-2021-4099)
Object lifecycle issue in ANGLE. (CVE-2021-4100)
Heap buffer overflow in Swiftshader. (CVE-2021-4101)
Use after free in V8. (CVE-2021-4102)

References

- https://bugs.mageia.org/show_bug.cgi?id=29765

- https://chromereleases.googleblog.com/2021/12/stable-channel-update-for-desktop_13.html

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-4098

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-4099

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-4100

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-4101

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-4102

Resolution

MGASA-2021-0565 - Updated chromium-browser-stable packages fix security vulnerabilities

SRPMS

- 8/core/chromium-browser-stable-96.0.4664.110-1.mga8

Severity
Publication date: 19 Dec 2021
URL: https://advisories.mageia.org/MGASA-2021-0565.html
Type: security
CVE: CVE-2021-4098, CVE-2021-4099, CVE-2021-4100, CVE-2021-4101, CVE-2021-4102

Related News