openSUSE Security Update: Security update for chromium

Announcement ID:    openSUSE-SU-2021:1339-1
Rating:             important
References:         #1190765 #1191166 #1191204 
Cross-References:   CVE-2021-37956 CVE-2021-37957 CVE-2021-37958
                    CVE-2021-37959 CVE-2021-37960 CVE-2021-37961
                    CVE-2021-37962 CVE-2021-37963 CVE-2021-37964
                    CVE-2021-37965 CVE-2021-37966 CVE-2021-37967
                    CVE-2021-37968 CVE-2021-37969 CVE-2021-37970
                    CVE-2021-37971 CVE-2021-37972 CVE-2021-37973
                    CVE-2021-37974 CVE-2021-37975 CVE-2021-37976
Affected Products:
                    openSUSE Backports SLE-15-SP3

   An update that fixes 21 vulnerabilities is now available.


   This update for chromium fixes the following issues:

   Chromium 94.0.4606.54 (boo#1190765):

   * CVE-2021-37956: Use after free in Offline use
   * CVE-2021-37957: Use after free in WebGPU
   * CVE-2021-37958: Inappropriate implementation in Navigation
   * CVE-2021-37959: Use after free in Task Manager
   * CVE-2021-37960: Inappropriate implementation in Blink graphics
   * CVE-2021-37961: Use after free in Tab Strip
   * CVE-2021-37962: Use after free in Performance Manager
   * CVE-2021-37963: Side-channel information leakage in DevTools
   * CVE-2021-37964: Inappropriate implementation in ChromeOS Networking
   * CVE-2021-37965: Inappropriate implementation in Background Fetch API
   * CVE-2021-37966: Inappropriate implementation in Compositing
   * CVE-2021-37967: Inappropriate implementation in Background Fetch API
   * CVE-2021-37968: Inappropriate implementation in Background Fetch API
   * CVE-2021-37969: Inappropriate implementation in Google Updater
   * CVE-2021-37970: Use after free in File System API
   * CVE-2021-37971: Incorrect security UI in Web Browser UI
   * CVE-2021-37972: Out of bounds read in libjpeg-turbo

   Chromium 94.0.4606.61 (boo#1191166):

   * CVE-2021-37973: Use after free in Portals

   Chromium 94.0.4606.71 (boo#1191204):

   * CVE-2021-37974 : Use after free in Safe Browsing
   * CVE-2021-37975 : Use after free in V8
   * CVE-2021-37976 : Information leak in core

Patch Instructions:

   To install this openSUSE Security Update use the SUSE recommended installation methods
   like YaST online_update or "zypper patch".

   Alternatively you can run the command listed for your product:

   - openSUSE Backports SLE-15-SP3:

      zypper in -t patch openSUSE-2021-1339=1

Package List:

   - openSUSE Backports SLE-15-SP3 (aarch64 x86_64):