Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

openSUSE: Chromium Heap Overflows and Info Leak Advisory 2025:0388-1

opensuse
Calendar Grey October 6, 2025
Dist Opensuse Esm H88
Update for chromium fixes 12 important issues including heap overflows and information leak vulnerabilities.
An update that fixes 12 vulnerabilities is now available.

Description

This update for chromium fixes the following issues:

- Chromium 141.0.7390.54 (stable released 2025-09-30) (boo#1250780)

* CVE-2025-11205: Heap buffer overflow in WebGPU

* CVE-2025-11206: Heap buffer overflow in Video

* CVE-2025-11207: Side-channel information leakage in Storage

* CVE-2025-11208: Inappropriate implementation in Media

* CVE-2025-11209: Inappropriate implementation in Omnibox

* CVE-2025-11210: Side-channel information leakage in Tab

* CVE-2025-11211: Out of bounds read in Media

* CVE-2025-11212: Inappropriate implementation in Media

* CVE-2025-11213: Inappropriate implementation in Omnibox

* CVE-2025-11215: Off by one error in V8

* CVE-2025-11216: Inappropriate implementation in Storage

* CVE-2025-11219: Use after free in V8

* Various fixes from internal audits, fuzzing and other initiatives

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Backports SLE-15-SP6:

zypper in -t patch openSUSE-2025-388=1

Package List

- openSUSE Backports SLE-15-SP6 (aarch64 ppc64le x86_64):

chromedriver-141.0.7390.54-bp156.2.176.1

chromium-141.0.7390.54-bp156.2.176.1

References

https://www.suse.com/security/cve/CVE-2025-11205.html

https://www.suse.com/security/cve/CVE-2025-11206.html

https://www.suse.com/security/cve/CVE-2025-11207.html

https://www.suse.com/security/cve/CVE-2025-11208.html

https://www.suse.com/security/cve/CVE-2025-11209.html

https://www.suse.com/security/cve/CVE-2025-11210.html

https://www.suse.com/security/cve/CVE-2025-11211.html

https://www.suse.com/security/cve/CVE-2025-11212.html

https://www.suse.com/security/cve/CVE-2025-11213.html

https://www.suse.com/security/cve/CVE-2025-11215.html

https://www.suse.com/security/cve/CVE-2025-11216.html

https://www.suse.com/security/cve/CVE-2025-11219.html

https://bugzilla.suse.com/1250780

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2025:0388-1
Rating: important
Affected Products: openSUSE Backports SLE-15-SP6

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here