Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Mageia: 2022-0211 Critical: Chromium Browser Security Issues Resolved

mageia
Calendar Grey May 28, 2022
Dist Mageia Esm H88
MGASA-2022-0212 upgrades the firefox-browser-stable package to address several security vulnerabilities and improve overall performance.
The chromium-browser-stable package has been updated to the 102.0.5005.61 version, fixing many bugs and 32 CVE

Summary

The chromium-browser-stable package has been updated to the 102.0.5005.61 version, fixing many bugs and 32 CVE. Some of them are listed below: CVE-2022-1853: Use after free in Indexed DB. CVE-2022-1854: Use after free in ANGLE. CVE-2022-1855: Use after free in Messaging. CVE-2022-1856: Use after free in User Education. CVE-2022-1857: Insufficient policy enforcement in File System API. CVE-2022-1858: Out of bounds read in DevTools. CVE-2022-1859: Use after free in Performance Manager. CVE-2022-1860: Use after free in UI Foundations. CVE-2022-1861: Use after free in Sharing. CVE-2022-1862: Inappropriate implementation in Extensions. CVE-2022-1863: Use after free in Tab Groups. CVE-2022-1864: Use after free in WebApp Installs. CVE-2022-1865: Use after free in Bookmarks. CVE-2022-1866: Use after free in Tablet Mode. CVE-2022-1867: Insufficient validation of untrusted input in Data Transfer. CVE-2022-1868: Inappropriate implementation in Extensions API. CVE-2022-1869: Type Confusion in V...

References

- https://bugs.mageia.org/show_bug.cgi?id=30470

- https://chromereleases.googleblog.com/2022/05/stable-channel-update-for-desktop_24.html

- https://blog.chromium.org/2022/04/chrome-102-window-controls-overlay-host.html

- https://www.cve.org/CVERecord?id=CVE-2022-1853

- https://www.cve.org/CVERecord?id=CVE-2022-1854

- https://www.cve.org/CVERecord?id=CVE-2022-1855

- https://www.cve.org/CVERecord?id=CVE-2022-1856

- https://www.cve.org/CVERecord?id=CVE-2022-1857

- https://www.cve.org/CVERecord?id=CVE-2022-1858

- https://www.cve.org/CVERecord?id=CVE-2022-1859

- https://www.cve.org/CVERecord?id=CVE-2022-1860

- https://www.cve.org/CVERecord?id=CVE-2022-1861

- https://www.cve.org/CVERecord?id=CVE-2022-1862

- https://www.cve.org/CVERecord?id=CVE-2022-1863

- https://www.cve.org/CVERecord?id=CVE-2022-1864

- https://www.cve.org/CVERecord?id=CVE-2022-1865

- https://www.cve.org/CVERecord?id=CVE-2022-1866

- https://www.cve.org/CVERecord?id=CVE-2022-1867

- https://www.cve.org/CVERecord?id=CVE-2022-1868

- https://www.cve.org/CVERecord?id=CVE-2022-1869

- https://www.cve.org/CVERecord?id=CVE-2022-1870

- https://www.cve.org/CVERecord?id=CVE-2022-1871

- https://www.cve.org/CVERecord?id=CVE-2022-1872

- https://www.cve.org/CVERecord?id=CVE-2022-1873

- https://www.cve.org/CVERecord?id=CVE-2022-1874

- https://www.cve.org/CVERecord?id=CVE-2022-1875

- https://www.cve.org/CVERecord?id=CVE-2022-1876

Resolution

SRPMS

- 8/core/chromium-browser-stable-102.0.5005.61-1.mga8

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 28 May 2022
URL: https://advisories.mageia.org/MGASA-2022-0211.html
Type: security
CVE: CVE-2022-1853, CVE-2022-1854, CVE-2022-1855, CVE-2022-1856, CVE-2022-1857, CVE-2022-1858, CVE-2022-1859, CVE-2022-1860, CVE-2022-1861, CVE-2022-1862, CVE-2022-1863, CVE-2022-1864, CVE-2022-1865, CVE-2022-1866, CVE-2022-1867, CVE-2022-1868, CVE-2022-1869, CVE-2022-1870, CVE-2022-1871, CVE-2022-1872, CVE-2022-1873, CVE-2022-1874, CVE-2022-1875, CVE-2022-1876

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here