The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2025-4098 http://linux.oracle.com/errata/ELSA-2025-4098.html The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: x86_64: libxslt-1.1.28-6.0.3.el7.i686.rpm libxslt-1.1.28-6.0.3.el7.x86_64.rpm libxslt-devel-1.1.28-6.0.3.el7.i686.rpm libxslt-devel-1.1.28-6.0.3.el7.x86_64.rpm libxslt-python-1.1.28-6.0.3.el7.x86_64.rpm SRPMS: http://oss.oracle.com/ol7/SRPMS-updates//libxslt-1.1.28-6.0.3.el7.src.rpm Related CVEs: CVE-2024-55549 CVE-2025-24855 Description of changes: [1.1.28-6.0.3] - Fix CVE-2024-55549 issue due to memory leak [Orabug: 37795485] - Fix CVE-2025-24855 issue due to use after free. _______________________________________________ El-errata mailing list
Update to 135.0.7049.95 CVE-2025-3619: Heap buffer overflow in Codecs CVE-2025-3620: Use after free in USB. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-fb323a2b22 2025-04-21 01:51:16.445103+00:00 -------------------------------------------------------------------------------- Name : chromium Product : Fedora 42 Version : 135.0.7049.95 Release : 1.fc42 URL : http://www.chromium.org/Home Summary : A WebKit (Blink) powered web browser that Google doesn't want you to use Description : Chromium is an open-source web browser, powered by WebKit (Blink). -------------------------------------------------------------------------------- Update Information: Update to 135.0.7049.95 CVE-2025-3619: Heap buffer overflow in Codecs CVE-2025-3620: Use after free in USB -------------------------------------------------------------------------------- ChangeLog: * Wed Apr 16 2025 Than Ngo - 135.0.7049.95-1 - Update to 135.0.7049.95 * CVE-2025-3619: Heap buffer overflow in Codecs * CVE-2025-3620: Use after free in USB -------------------------------------------------------------------------------- References: [ 1 ] Bug #2360898 - CVE-2025-3620 chromium: Use after free in USB [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2360898 [ 2 ] Bug #2360899 - CVE-2025-3620 chromium: Use after free in USB [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2360899 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-fb323a2b22' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
update to 123.0.6312.122 * High CVE-2024-3157: Out of bounds write in Compositing * High CVE-2024-3516: Heap buffer overflow in ANGLE * High CVE-2024-3515: Use after free in Dawn . -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-f94660c56d 2024-04-14 03:07:59.493280 -------------------------------------------------------------------------------- Name : chromium Product : Fedora 38 Version : 123.0.6312.122 Release : 1.fc38 URL : https://www.chromium.org/Home/ Summary : A WebKit (Blink) powered web browser that Google doesn't want you to use Description : Chromium is an open-source web browser, powered by WebKit (Blink). -------------------------------------------------------------------------------- Update Information: update to 123.0.6312.122 * High CVE-2024-3157: Out of bounds write in Compositing * High CVE-2024-3516: Heap buffer overflow in ANGLE * High CVE-2024-3515: Use after free in Dawn -------------------------------------------------------------------------------- ChangeLog: * Thu Apr 11 2024 Than Ngo - 123.0.6312.122-1 - update to 123.0.6312.122 * High CVE-2024-3157: Out of bounds write in Compositing * High CVE-2024-3516: Heap buffer overflow in ANGLE * High CVE-2024-3515: Use after free in Dawn -------------------------------------------------------------------------------- References: [ 1 ] Bug #2274472 - CVE-2024-3157 CVE-2024-3515 CVE-2024-3516 chromium: various flaws [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2274472 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-f94660c56d' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPGkey. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
An update that fixes 5 vulnerabilities is now available.. openSUSE Security Update: Security update for chromium ______________________________________________________________________________ Announcement ID: openSUSE-SU-2020:1718-1 Rating: important References: #1177936 Cross-References: CVE-2020-15999 CVE-2020-16000 CVE-2020-16001 CVE-2020-16002 CVE-2020-16003 Affected Products: openSUSE Leap 15.1 ______________________________________________________________________________ An update that fixes 5 vulnerabilities is now available. Description: This update for chromium fixes the following issues: - Update to 86.0.4240.111 boo#1177936 - CVE-2020-16000: Inappropriate implementation in Blink. - CVE-2020-16001: Use after free in media. - CVE-2020-16002: Use after free in PDFium. - CVE-2020-15999: Heap buffer overflow in Freetype. - CVE-2020-16003: Use after free in printing. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.1: zypper in -t patch openSUSE-2020-1718=1 Package List: - openSUSE Leap 15.1 (x86_64): chromedriver-86.0.4240.111-lp151.2.147.1 chromedriver-debuginfo-86.0.4240.111-lp151.2.147.1 chromium-86.0.4240.111-lp151.2.147.1 chromium-debuginfo-86.0.4240.111-lp151.2.147.1 References: https://www.suse.com/security/cve/CVE-2020-15999.html https://www.suse.com/security/cve/CVE-2020-16000.html https://www.suse.com/security/cve/CVE-2020-16001.html https://www.suse.com/security/cve/CVE-2020-16002.html https://www.suse.com/security/cve/CVE-2020-16003.html https://bugzilla.suse.com/1177936 -- . Important openSUSE patch for chromium tackling 5 vulnerabilities, featuring critical heap buffer overflow and use-after-free problems.. Security Update,openSUSE, Chromium Update, CVE Fixes, Important Patch. . Severity: Important. LinuxSecurity.com Team
An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: chromium-browser security update Advisory ID: RHSA-2020:2643-01 Product: Red Hat Enterprise Linux Supplementary Advisory URL: https://access.redhat.com/errata/RHSA-2020:2643 Issue date: 2020-06-22 CVE Names: CVE-2020-6505 CVE-2020-6506 CVE-2020-6507 ==================================================================== 1. Summary: An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Desktop Supplementary (v. 6) - i386, i686, x86_64 Red Hat Enterprise Linux HPC Node Supplementary (v. 6) - i686, x86_64 Red Hat Enterprise Linux Server Supplementary (v. 6) - i386, i686, x86_64 Red Hat Enterprise Linux Workstation Supplementary (v. 6) - i386, i686, x86_64 3. Description: Chromium is an open-source web browser, powered by WebKit (Blink). This update upgrades Chromium to version 83.0.4103.106. Security Fix(es): * chromium-browser: Use after free in speech (CVE-2020-6505) * chromium-browser: Insufficient policy enforcement in WebView (CVE-2020-6506) * chromium-browser: Out of bounds write in V8 (CVE-2020-6507) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in theReferences section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 After installing the update, Chromium must be restarted for the changes to take effect. 5. Bugs fixed (https://bugzilla.redhat.com/): 1847268 - CVE-2020-6505 chromium-browser: Use after free in speech 1847269 - CVE-2020-6506 chromium-browser: Insufficient policy enforcement in WebView 1847270 - CVE-2020-6507 chromium-browser: Out of bounds write in V8 6. Package List: Red Hat Enterprise Linux Desktop Supplementary (v. 6): i386: chromium-browser-83.0.4103.106-1.el6_10.i686.rpm chromium-browser-debuginfo-83.0.4103.106-1.el6_10.i686.rpm i686: chromium-browser-83.0.4103.106-1.el6_10.i686.rpm chromium-browser-debuginfo-83.0.4103.106-1.el6_10.i686.rpm x86_64: chromium-browser-83.0.4103.106-1.el6_10.x86_64.rpm chromium-browser-debuginfo-83.0.4103.106-1.el6_10.x86_64.rpm Red Hat Enterprise Linux HPC Node Supplementary (v. 6): i686: chromium-browser-83.0.4103.106-1.el6_10.i686.rpm chromium-browser-debuginfo-83.0.4103.106-1.el6_10.i686.rpm x86_64: chromium-browser-83.0.4103.106-1.el6_10.x86_64.rpm chromium-browser-debuginfo-83.0.4103.106-1.el6_10.x86_64.rpm Red Hat Enterprise Linux Server Supplementary (v. 6): i386: chromium-browser-83.0.4103.106-1.el6_10.i686.rpm chromium-browser-debuginfo-83.0.4103.106-1.el6_10.i686.rpm i686: chromium-browser-83.0.4103.106-1.el6_10.i686.rpm chromium-browser-debuginfo-83.0.4103.106-1.el6_10.i686.rpm x86_64: chromium-browser-83.0.4103.106-1.el6_10.x86_64.rpm chromium-browser-debuginfo-83.0.4103.106-1.el6_10.x86_64.rpm Red Hat Enterprise Linux Workstation Supplementary (v.6): i386: chromium-browser-83.0.4103.106-1.el6_10.i686.rpm chromium-browser-debuginfo-83.0.4103.106-1.el6_10.i686.rpm i686: chromium-browser-83.0.4103.106-1.el6_10.i686.rpm chromium-browser-debuginfo-83.0.4103.106-1.el6_10.i686.rpm x86_64: chromium-browser-83.0.4103.106-1.el6_10.x86_64.rpm chromium-browser-debuginfo-83.0.4103.106-1.el6_10.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2020-6505 https://access.redhat.com/security/cve/CVE-2020-6506 https://access.redhat.com/security/cve/CVE-2020-6507 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2020 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBXvBhFtzjgjWX9erEAQjqUhAAkEmNSNTElUO67clsJOKgZj1qv05wnCK6 s/an+y8i3idtHdjn6XlkXVg4iTXBiXbOc8cKR5fattVrsMiCn91m+NUgKqdjYnWJ 6R0Mx3qbgMR1aL5CrUmQYglVARc0B1TYMY/9kuXnvcS63bvJSYdPFiT5JexUfRIe ybAX1aAjcW0fL2vUAC1s/Ilqg6yNXmBknNP5Qk1P+T4pl7w435aksEFeXsfUInjl YxbOIuZG0g0iZ08S9J6b6cBjLdtJ7VHLpnljohnhqvsfZb7po8oK2ZVeGWSomnZx yX9M4F4SZa3Vt4Dsy4wSvwfehTfDudie+R3mQIqzZx0FTEyYYYnct/Sqij+u1UOK XUI70++4TAKiSDjoe58VVKiiSW5UYtqp1xlGpl2jhm5gQ8tcyy27/s9pgQZhi/hg 7uiCcMEaQAjo3u6HWUun9NO8apD2aRCEItVDrfw+8zs/vzt54FWjj3m/lQwCL4Xb 5yUtjTuX32dDyGI/H25en7UuU5fnVvI5uaaoBpmCc600uL6KEcOYDih0N0FvO7AI niJ5ADNC907uK2sJ4Ucavw5CnZofAda7aYmj+3GUiPpeSw/IrdgJiZII+r7kvFp0 dvvcAs0Kdl3i6H7lKP/1rdpR1cI7dpty2L0DLNJ1QugAkY/SYvEAADUhKAtq5M71 bPkcMyGaoqg=p0tW -----END PGP SIGNATURE----- -- RHSA-announce mailing list
Get the latest Linux and open source security news straight to your inbox.