Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

openSUSE: 2023:0124-1 Important: Chromium Security Fix Overview

opensuse
Calendar Grey June 9, 2023
Dist Opensuse Esm H88
A new security patch for Chromium addresses 14 vulnerabilities on openSUSE systems. Discover the essential updates and step-by-step installation guidelines.
An update that fixes 14 vulnerabilities is now available

Description

This update for chromium fixes the following issues:

- Chromium 114.0.5735.106 (boo#1212044):

* CVE-2023-3079: Type Confusion in V8

- Chromium 114.0.5735.90 (boo#1211843):

* CSS text-wrap: balance is available

* Cookies partitioned by top level site (CHIPS)

* New Popover API

- Security fixes:

* CVE-2023-2929: Out of bounds write in Swiftshader

* CVE-2023-2930: Use after free in Extensions

* CVE-2023-2931: Use after free in PDF

* CVE-2023-2932: Use after free in PDF

* CVE-2023-2933: Use after free in PDF

* CVE-2023-2934: Out of bounds memory access in Mojo

* CVE-2023-2935: Type Confusion in V8

* CVE-2023-2936: Type Confusion in V8

* CVE-2023-2937: Inappropriate implementation in Picture In Picture

* CVE-2023-2938: Inappropriate implementation in Picture In Picture

* CVE-2023-2939: Insufficient data validation in Installer

* CVE-2023-2940: Inappropriate implementation in Downloads

*...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Backports SLE-15-SP4:

zypper in -t patch openSUSE-2023-124=1

Package List

- openSUSE Backports SLE-15-SP4 (aarch64 x86_64):

chromedriver-114.0.5735.106-bp154.2.90.1

chromium-114.0.5735.106-bp154.2.90.1

References

https://www.suse.com/security/cve/CVE-2023-2929.html

https://www.suse.com/security/cve/CVE-2023-2930.html

https://www.suse.com/security/cve/CVE-2023-2931.html

https://www.suse.com/security/cve/CVE-2023-2932.html

https://www.suse.com/security/cve/CVE-2023-2933.html

https://www.suse.com/security/cve/CVE-2023-2934.html

https://www.suse.com/security/cve/CVE-2023-2935.html

https://www.suse.com/security/cve/CVE-2023-2936.html

https://www.suse.com/security/cve/CVE-2023-2937.html

https://www.suse.com/security/cve/CVE-2023-2938.html

https://www.suse.com/security/cve/CVE-2023-2939.html

https://www.suse.com/security/cve/CVE-2023-2940.html

https://www.suse.com/security/cve/CVE-2023-2941.html

https://www.suse.com/security/cve/CVE-2023-3079.html

https://bugzilla.suse.com/1211843

https://bugzilla.suse.com/1212044

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2023:0124-1
Rating: important
Affected Products: openSUSE Backports SLE-15-SP4 .

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here