Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

openSUSE: 2024:0204-1 Important Update For Chromium Security Issues

opensuse
Calendar Grey July 18, 2024
Dist Opensuse Esm H88
Important openSUSE security patch resolves major problems in Chromium, addressing a series of vulnerabilities.
An update that fixes 26 vulnerabilities is now available

Description

This update for chromium fixes the following issues:

Chromium 126.0.6478.126 (boo#1226504, boo#1226205, boo#1226933)

* CVE-2024-6290: Use after free in Dawn

* CVE-2024-6291: Use after free in Swiftshader

* CVE-2024-6292: Use after free in Dawn

* CVE-2024-6293: Use after free in Dawn

* CVE-2024-6100: Type Confusion in V8

* CVE-2024-6101: Inappropriate implementation in WebAssembly

* CVE-2024-6102: Out of bounds memory access in Dawn

* CVE-2024-6103: Use after free in Dawn

* CVE-2024-5830: Type Confusion in V8

* CVE-2024-5831: Use after free in Dawn

* CVE-2024-5832: Use after free in Dawn

* CVE-2024-5833: Type Confusion in V8

* CVE-2024-5834: Inappropriate implementation in Dawn

* CVE-2024-5835: Heap buffer overflow in Tab Groups

* CVE-2024-5836: Inappropriate Implementation in DevTools

* CVE-2024-5837: Type Confusion in V8

* CVE-2024-5838: Type Confusion in V8

* CVE-2024-5839:...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Backports SLE-15-SP5:

zypper in -t patch openSUSE-2024-204=1

Package List

- openSUSE Backports SLE-15-SP5 (aarch64 x86_64):

chromedriver-126.0.6478.126-bp155.2.94.1

chromium-126.0.6478.126-bp155.2.94.1

References

https://www.suse.com/security/cve/CVE-2024-5830.html

https://www.suse.com/security/cve/CVE-2024-5831.html

https://www.suse.com/security/cve/CVE-2024-5832.html

https://www.suse.com/security/cve/CVE-2024-5833.html

https://www.suse.com/security/cve/CVE-2024-5834.html

https://www.suse.com/security/cve/CVE-2024-5835.html

https://www.suse.com/security/cve/CVE-2024-5836.html

https://www.suse.com/security/cve/CVE-2024-5837.html

https://www.suse.com/security/cve/CVE-2024-5838.html

https://www.suse.com/security/cve/CVE-2024-5839.html

https://www.suse.com/security/cve/CVE-2024-5840.html

https://www.suse.com/security/cve/CVE-2024-5841.html

https://www.suse.com/security/cve/CVE-2024-5842.html

https://www.suse.com/security/cve/CVE-2024-5843.html

https://www.suse.com/security/cve/CVE-2024-5844.html

https://www.suse.com/security/cve/CVE-2024-5845.html

https://www.suse.com/security/cve/CVE-2024-5846.html

https://www.suse.com/security/cve/CVE-2024-5847.html

https://www.suse.com/security/cve/CVE-2024-6100.html

https://www....

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2024:0204-1
Rating: important
Affected Products: openSUSE Backports SLE-15-SP5 .

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here