Alerts This Week
Warning Icon 1 681
Alerts This Week
Warning Icon 1 681

openSUSE 15: 2024:0084-1 important: chromium memory access issues

opensuse
Calendar Grey March 18, 2024
Dist Opensuse Esm H88
A critical openSUSE security patch for firefox tackles 15 vulnerabilities, strengthening system defenses.
An update that fixes 12 vulnerabilities is now available

Description

This update for chromium fixes the following issue:

Chromium 122.0.6261.128 (boo#1221335)

* CVE-2024-2400: Use after free in Performance Manager

Chromium 122.0.6261.111 (boo#1220131,boo#1220604,boo#1221105)

* New upstream security release.

* CVE-2024-2173: Out of bounds memory access in V8.

* CVE-2024-2174: Inappropriate implementation in V8.

* CVE-2024-2176: Use after free in FedCM.

Chromium 122.0.6261.94

* CVE-2024-1669: Out of bounds memory access in Blink.

* CVE-2024-1670: Use after free in Mojo.

* CVE-2024-1671: Inappropriate implementation in Site Isolation.

* CVE-2024-1672: Inappropriate implementation in Content Security Policy.

* CVE-2024-1673: Use after free in Accessibility.

* CVE-2024-1674: Inappropriate implementation in Navigation.

* CVE-2024-1675: Insufficient policy enforcement in Download.

* CVE-2024-1676: Inappropriate implementation in Navigation.

* Type Confusion in V8

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Backports SLE-15-SP5:

zypper in -t patch openSUSE-2024-84=1

Package List

- openSUSE Backports SLE-15-SP5 (aarch64 i586 ppc64le s390x x86_64):

clang17-17.0.6-bp155.2.2

clang17-debuginfo-17.0.6-bp155.2.2

clang17-devel-17.0.6-bp155.2.2

libLLVM17-17.0.6-bp155.2.2

libLLVM17-debuginfo-17.0.6-bp155.2.2

libLTO17-17.0.6-bp155.2.2

libLTO17-debuginfo-17.0.6-bp155.2.2

libclang-cpp17-17.0.6-bp155.2.2

libclang-cpp17-debuginfo-17.0.6-bp155.2.2

lld17-17.0.6-bp155.2.2

lld17-debuginfo-17.0.6-bp155.2.2

llvm17-17.0.6-bp155.2.2

llvm17-debuginfo-17.0.6-bp155.2.2

llvm17-devel-17.0.6-bp155.2.2

llvm17-devel-debuginfo-17.0.6-bp155.2.2

llvm17-gold-17.0.6-bp155.2.2

llvm17-gold-debuginfo-17.0.6-bp155.2.2

llvm17-libclang13-17.0.6-bp155.2.2

llvm17-libclang13-debuginfo-17.0.6-bp155.2.2

llvm17-polly-17.0.6-bp155.2.2

llvm17-polly-debuginfo-17.0.6-bp155.2.2

llvm17-polly-devel-17.0.6-bp155.2.2

- openSUSE Backports SLE-15-SP5 (aarch64 i586 ppc64le x86_64):

libomp17-devel-17.0.6-bp155.2.2

libomp17-devel-debuginfo-17.0.6-bp155.2.2

- openSUSE Backports SLE-15-SP5 (aarch64 x86_64):

chromedriver-122.0.6261.128-bp155.2.75.1

ch...

Read the Full Advisory

References

https://www.suse.com/security/cve/CVE-2024-1669.html

https://www.suse.com/security/cve/CVE-2024-1670.html

https://www.suse.com/security/cve/CVE-2024-1671.html

https://www.suse.com/security/cve/CVE-2024-1672.html

https://www.suse.com/security/cve/CVE-2024-1673.html

https://www.suse.com/security/cve/CVE-2024-1674.html

https://www.suse.com/security/cve/CVE-2024-1675.html

https://www.suse.com/security/cve/CVE-2024-1676.html

https://www.suse.com/security/cve/CVE-2024-2173.html

https://www.suse.com/security/cve/CVE-2024-2174.html

https://www.suse.com/security/cve/CVE-2024-2176.html

https://www.suse.com/security/cve/CVE-2024-2400.html

https://bugzilla.suse.com/1220131

https://bugzilla.suse.com/1220604

https://bugzilla.suse.com/1221105

https://bugzilla.suse.com/1221335

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2024:0084-1
Rating: important
Affected Products: openSUSE Backports SLE-15-SP5 .

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here