MGASA-2024-0233 - Updated chromium-browser-stable packages fix security vulnerabilities

Publication date: 24 Jun 2024
URL: https://advisories.mageia.org/MGASA-2024-0233.html
Type: security
Affected Mageia releases: 9
CVE: CVE-2024-6100,
     CVE-2024-6101,
     CVE-2024-6102,
     CVE-2024-6103

High CVE-2024-6100: Type Confusion in V8. Reported by Seunghyun Lee
(@0x10n) participating in SSD Secure Disclosure's TyphoonPWN 2024 on
2024-06-04
High CVE-2024-6101: Inappropriate implementation in WebAssembly.
Reported by @ginggilBesel on 2024-05-31
High CVE-2024-6102: Out of bounds memory access in Dawn. Reported by
wgslfuzz on 2024-05-07
High CVE-2024-6103: Use after free in Dawn. Reported by wgslfuzz on
2024-06-04

References:
- https://bugs.mageia.org/show_bug.cgi?id=33321
- https://chromereleases.googleblog.com/2024/06/stable-channel-update-for-desktop_18.html
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-6100
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-6101
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-6102
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-6103

SRPMS:
- 9/tainted/chromium-browser-stable-126.0.6478.114-1.mga9.tainted

Mageia 2024-0233: chromium-browser-stable Security Advisory Updates

High CVE-2024-6100: Type Confusion in V8

Summary

High CVE-2024-6100: Type Confusion in V8. Reported by Seunghyun Lee (@0x10n) participating in SSD Secure Disclosure's TyphoonPWN 2024 on 2024-06-04 High CVE-2024-6101: Inappropriate implementation in WebAssembly. Reported by @ginggilBesel on 2024-05-31 High CVE-2024-6102: Out of bounds memory access in Dawn. Reported by wgslfuzz on 2024-05-07 High CVE-2024-6103: Use after free in Dawn. Reported by wgslfuzz on 2024-06-04

References

- https://bugs.mageia.org/show_bug.cgi?id=33321

- https://chromereleases.googleblog.com/2024/06/stable-channel-update-for-desktop_18.html

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-6100

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-6101

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-6102

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-6103

Resolution

MGASA-2024-0233 - Updated chromium-browser-stable packages fix security vulnerabilities

SRPMS

- 9/tainted/chromium-browser-stable-126.0.6478.114-1.mga9.tainted

Severity
Publication date: 24 Jun 2024
URL: https://advisories.mageia.org/MGASA-2024-0233.html
Type: security
CVE: CVE-2024-6100, CVE-2024-6101, CVE-2024-6102, CVE-2024-6103

Related News