Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
Update to 134.0.6998.88 High CVE-2025-1920: Type Confusion in V8 High CVE-2025-2135: Type Confusion in V8 Medium CVE-2025-2136: Use after free in Inspector Medium CVE-2025-2137: Out of bounds read in V8. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-6b9cbdbdff 2025-03-17 00:14:50.303261+00:00 -------------------------------------------------------------------------------- Name : chromium Product : Fedora 42 Version : 134.0.6998.88 Release : 3.fc42 URL : http://www.chromium.org/Home Summary : A WebKit (Blink) powered web browser that Google doesn't want you to use Description : Chromium is an open-source web browser, powered by WebKit (Blink). -------------------------------------------------------------------------------- Update Information: Update to 134.0.6998.88 High CVE-2025-1920: Type Confusion in V8 High CVE-2025-2135: Type Confusion in V8 Medium CVE-2025-2136: Use after free in Inspector Medium CVE-2025-2137: Out of bounds read in V8 -------------------------------------------------------------------------------- ChangeLog: * Fri Mar 14 2025 Than Ngo - 134.0.6998.88-3 - Fixed build errors on ppc64le * Thu Mar 13 2025 Fabio Valentini - 134.0.6998.88-2 - Rebuild for noopenh264 2.6.0 * Tue Mar 11 2025 Than Ngo - 134.0.6998.88 -1 - Update to 134.0.6998.88 * High CVE-2025-1920: Type Confusion in V8 * High CVE-2025-2135: Type Confusion in V8 * High CVE-TBD: Out of bounds write in GPU * Medium CVE-2025-2136: Use after free in Inspector * Medium CVE-2025-2137: Out of bounds read in V8 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-6b9cbdbdff' at the command line. For more information, refer to the dnf documentation availableat http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
An update that fixes 9 vulnerabilities is now available. . openSUSE Security Update: Security update for chromium ______________________________________________________________________________ Announcement ID: openSUSE-SU-2025:0084-1 Rating: important References: #1238575 Cross-References: CVE-2025-1914 CVE-2025-1915 CVE-2025-1916 CVE-2025-1917 CVE-2025-1918 CVE-2025-1919 CVE-2025-1921 CVE-2025-1922 CVE-2025-1923 Affected Products: openSUSE Backports SLE-15-SP6 ______________________________________________________________________________ An update that fixes 9 vulnerabilities is now available. Description: Chromium was updated to 134.0.6998.35 (stable release 2025-03-04) (boo#1238575): * CVE-2025-1914: Out of bounds read in V8 * CVE-2025-1915: Improper Limitation of a Pathname to a Restricted Directory in DevTools * CVE-2025-1916: Use after free in Profiles * CVE-2025-1917: Inappropriate Implementation in Browser UI * CVE-2025-1918: Out of bounds read in PDFium * CVE-2025-1919: Out of bounds read in Media * CVE-2025-1921: Inappropriate Implementation in Media Stream * CVE-2025-1922: Inappropriate Implementation in Selection * CVE-2025-1923: Inappropriate Implementation in Permission Prompts Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP6: zypper in -t patch openSUSE-2025-84=1 Package List: - openSUSE Backports SLE-15-SP6 (aarch64 x86_64): chromedriver-134.0.6998.35-bp156.2.90.1 chromium-134.0.6998.35-bp156.2.90.1 References: https://www.suse.com/security/cve/CVE-2025-1914.html https://www.suse.com/security/cve/CVE-2025-1915.html https://www.suse.com/security/cve/CVE-2025-1916.html https://www.suse.com/security/cve/CVE-2025-1917.html https://www.suse.com/security/cve/CVE-2025-1918.html https://www.suse.com/security/cve/CVE-2025-1919.html https://www.suse.com/security/cve/CVE-2025-1921.html https://www.suse.com/security/cve/CVE-2025-1922.html https://www.suse.com/security/cve/CVE-2025-1923.html https://bugzilla.suse.com/1238575 . Resolutions for 9 critical vulnerabilities in Chromium address buffer overflow errors and faulty functions. Upgrade your openSUSE immediately.. chromium update, openSUSE security, important patch, browser vulnerability, out of bounds read. . Severity: Important. LinuxSecurity.com Team
Update to 133.0.6943.98 CVE-2025-0995: Use after free in V8 CVE-2025-0996: Inappropriate implementation in Browser UI CVE-2025-0997: Use after free in Navigation CVE-2025-0998: Out of bounds memory access in V8. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-a87a6cd2a7 2025-02-16 01:27:58.390811+00:00 -------------------------------------------------------------------------------- Name : chromium Product : Fedora 40 Version : 133.0.6943.98 Release : 1.fc40 URL : http://www.chromium.org/Home Summary : A WebKit (Blink) powered web browser that Google doesn't want you to use Description : Chromium is an open-source web browser, powered by WebKit (Blink). -------------------------------------------------------------------------------- Update Information: Update to 133.0.6943.98 CVE-2025-0995: Use after free in V8 CVE-2025-0996: Inappropriate implementation in Browser UI CVE-2025-0997: Use after free in Navigation CVE-2025-0998: Out of bounds memory access in V8 -------------------------------------------------------------------------------- ChangeLog: * Thu Feb 13 2025 Than Ngo - 133.0.6943.98-1 - Update to 133.0.6943.98 * CVE-2025-0995: Use after free in V8 * CVE-2025-0996: Inappropriate implementation in Browser UI * CVE-2025-0997: Use after free in Navigation * CVE-2025-0998: Out of bounds memory access in V8 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-a87a6cd2a7' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
An update that fixes four vulnerabilities is now available. . openSUSE Security Update: Security update for chromium ______________________________________________________________________________ Announcement ID: openSUSE-SU-2025:0059-1 Rating: important References: #1237121 Cross-References: CVE-2025-0995 CVE-2025-0996 CVE-2025-0997 CVE-2025-0998 Affected Products: openSUSE Backports SLE-15-SP6 ______________________________________________________________________________ An update that fixes four vulnerabilities is now available. Description: This update for chromium fixes the following issues: Chromium 133.0.6943.98 (boo#1237121): - CVE-2025-0995: Use after free in V8 - CVE-2025-0996: Inappropriate implementation in Browser UI - CVE-2025-0997: Use after free in Navigation - CVE-2025-0998: Out of bounds memory access in V8 Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP6: zypper in -t patch openSUSE-2025-59=1 Package List: - openSUSE Backports SLE-15-SP6 (aarch64 x86_64): chromedriver-133.0.6943.98-bp156.2.81.2 chromium-133.0.6943.98-bp156.2.81.2 References: https://www.suse.com/security/cve/CVE-2025-0995.html https://www.suse.com/security/cve/CVE-2025-0996.html https://www.suse.com/security/cve/CVE-2025-0997.html https://www.suse.com/security/cve/CVE-2025-0998.html https://bugzilla.suse.com/show_bug.cgi?id=1237121 . Important update for openSUSE Chromium addresses several vulnerabilities and improves performance. Upgrade today!. openSUSE Security, Chromium Update, Important Patch. . Severity: Important. LinuxSecurity.com Team
update to 125.0.6422.76 * High CVE-2024-5157: Use after free in Scheduling * High CVE-2024-5158: Type Confusion in V8 * High CVE-2024-5159: Heap buffer overflow in ANGLE * High CVE-2024-5160: Heap buffer overflow in Dawn. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-87bb7ffab1 2024-05-24 01:03:40.444845 -------------------------------------------------------------------------------- Name : chromium Product : Fedora 39 Version : 125.0.6422.76 Release : 1.fc39 URL : http://www.chromium.org/Home Summary : A WebKit (Blink) powered web browser that Google doesn't want you to use Description : Chromium is an open-source web browser, powered by WebKit (Blink). -------------------------------------------------------------------------------- Update Information: update to 125.0.6422.76 * High CVE-2024-5157: Use after free in Scheduling * High CVE-2024-5158: Type Confusion in V8 * High CVE-2024-5159: Heap buffer overflow in ANGLE * High CVE-2024-5160: Heap buffer overflow in Dawn -------------------------------------------------------------------------------- ChangeLog: * Wed May 22 2024 Than Ngo - 125.0.6422.76-1 - fix bz#2282246, update to 125.0.6422.76 * High CVE-2024-5157: Use after free in Scheduling * High CVE-2024-5158: Type Confusion in V8 * High CVE-2024-5159: Heap buffer overflow in ANGLE * High CVE-2024-5160: Heap buffer overflow in Dawn - cleanup * Mon May 20 2024 Than Ngo - 125.0.6422.60-3 - remove unneeded BRs - workarounds for el7 build * Sun May 19 2024 Than Ngo - 125.0.6422.60-2 - fix build errors on el7 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2282246 - 125.0.6422.76 available, fixes multiple High CVES https://bugzilla.redhat.com/show_bug.cgi?id=2282246 -------------------------------------------------------------------------------- This update can beinstalled with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-87bb7ffab1' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
This update upgrades Thunderbird to version 102.11.0. * Mozilla: Browser prompts could have been obscured by popups (CVE-2023-32205) * Mozilla: Crash in RLBox Expat driver (CVE-2023-32206) * Mozilla: Potential permissions request bypass via clickjacking (CVE-2023-32207) * Mozilla: Memory safety bugs fixed in Firefox 113 and Firefox ESR 102.11 (CVE-2023-32215) * Mozilla: Content process cras [More...]. Synopsis: Important: thunderbird security update Advisory ID: SLSA-2023:3151-1 Issue Date: 2023-05-17 CVE Numbers: CVE-2023-32205 CVE-2023-32206 CVE-2023-32207 CVE-2023-32211 CVE-2023-32212 CVE-2023-32213 CVE-2023-32215 -- This update upgrades Thunderbird to version 102.11.0. Security Fix(es): * Mozilla: Browser prompts could have been obscured by popups (CVE-2023-32205) * Mozilla: Crash in RLBox Expat driver (CVE-2023-32206) * Mozilla: Potential permissions request bypass via clickjacking (CVE-2023-32207) * Mozilla: Memory safety bugs fixed in Firefox 113 and Firefox ESR 102.11 (CVE-2023-32215) * Mozilla: Content process crash due to invalid wasm code (CVE-2023-32211) * Mozilla: Potential spoof due to obscured address bar (CVE-2023-32212) * Mozilla: Potential memory corruption in FileReader::DoReadData() (CVE-2023-32213) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE -- SL7 x86_64 thunderbird-102.11.0-1.el7_9.x86_64.rpm thunderbird-debuginfo-102.11.0-1.el7_9.x86_64.rpm - Scientific Linux Development Team . Important Thunderbird patch for SL7.x x86_64 addresses multiple vulnerabilities, including data integrity flaws and privilege escalation.. Thunderbird Update, Mozilla Security, Scientific Linux Advisory, Browser Security Update. . Severity: Important. LinuxSecurity.com Team
Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code or spoofing. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3364-1
An update that fixes 6 vulnerabilities is now available. . openSUSE Security Update: Security update for chromium ______________________________________________________________________________ Announcement ID: openSUSE-SU-2022:10201-1 Rating: important References: #1205221 Cross-References: CVE-2022-3885 CVE-2022-3886 CVE-2022-3887 CVE-2022-3888 CVE-2022-3889 CVE-2022-3890 CVSS scores: CVE-2022-3885 (NVD) : 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVE-2022-3886 (NVD) : 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVE-2022-3887 (NVD) : 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVE-2022-3888 (NVD) : 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVE-2022-3889 (NVD) : 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVE-2022-3890 (NVD) : 9.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H Affected Products: openSUSE Backports SLE-15-SP3 openSUSE Backports SLE-15-SP4 ______________________________________________________________________________ An update that fixes 6 vulnerabilities is now available. Description: This update for chromium fixes the following issues: - Chromium 107.0.5304.110 (boo#1205221) * CVE-2022-3885: Use after free in V8 * CVE-2022-3886: Use after free in Speech Recognition * CVE-2022-3887: Use after free in Web Workers * CVE-2022-3888: Use after free in WebCodecs * CVE-2022-3889: Type Confusion in V8 * CVE-2022-3890: Heap buffer overflow in Crashpad Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP4: zypper in -t patch openSUSE-2022-10201=1 - openSUSE Backports SLE-15-SP3: zypperin -t patch openSUSE-2022-10201=1 Package List: - openSUSE Backports SLE-15-SP4 (aarch64 x86_64): chromedriver-107.0.5304.110-bp154.2.43.1 chromedriver-debuginfo-107.0.5304.110-bp154.2.43.1 chromium-107.0.5304.110-bp154.2.43.1 chromium-debuginfo-107.0.5304.110-bp154.2.43.1 - openSUSE Backports SLE-15-SP3 (aarch64 x86_64): chromedriver-107.0.5304.110-bp153.2.136.1 chromium-107.0.5304.110-bp153.2.136.1 References: https://www.suse.com/security/cve/CVE-2022-3885.html https://www.suse.com/security/cve/CVE-2022-3886.html https://www.suse.com/security/cve/CVE-2022-3887.html https://www.suse.com/security/cve/CVE-2022-3888.html https://www.suse.com/security/cve/CVE-2022-3889.html https://www.suse.com/security/cve/CVE-2022-3890.html https://bugzilla.suse.com/1205221 . The chromium update resolves several vital vulnerabilities in openSUSE. Ensure your system remains protected by applying the most recent patches and guidelines.. OpenSUSE Security Update, Chromium Security Fix, Heap Overflow Risk. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.