Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 10 articles for you...
89

Fedora 43 Chromium Critical Use After Free Issues Vulnern 2026-ddd87cb1db

chromium-149.0.7827.196 security release * CVE-2026-13028: Use after free in WebGL * CVE-2026-13032: Use after free in WebGL * CVE-2026-13033: Out of bounds read in Blink> InterestGroups * CVE-2026-13038: Use after free in Autofill. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-ddd87cb1db 2026-06-28 01:07:37.246098+00:00 -------------------------------------------------------------------------------- Name : chromium Product : Fedora 43 Version : 149.0.7827.196 Release : 1.fc43 URL : http://www.chromium.org/Home Summary : A WebKit (Blink) powered web browser that Google doesn't want you to use Description : Chromium is an open-source web browser, powered by WebKit (Blink). -------------------------------------------------------------------------------- Update Information: chromium-149.0.7827.196 security release * CVE-2026-13028: Use after free in WebGL * CVE-2026-13032: Use after free in WebGL * CVE-2026-13033: Out of bounds read in Blink> InterestGroups * CVE-2026-13038: Use after free in Autofill * CVE-2026-13021: Inappropriate implementation in DeviceBoundSessionCredentials * CVE-2026-13022: Inappropriate implementation in Autofill * CVE-2026-13023: Uninitialized Use in GPU * CVE-2026-13024: Insufficient validation of untrusted input in Navigation * CVE-2026-13025: Insufficient validation of untrusted input in DevTools * CVE-2026-13026: Use after free in Digital Credentials * CVE-2026-13027: Use after free in FileSystem * CVE-2026-13029: Use after free in Web Authentication * CVE-2026-13030: Uninitialized Use in GPU * CVE-2026-13031: Use after free in Blink * CVE-2026-13034: Inappropriate implementation in Passwords * CVE-2026-13035: Use after free in Bluetooth * CVE-2026-13036: Use after free in Blink * CVE-2026-13037: Use after free inWebView -------------------------------------------------------------------------------- ChangeLog: * Wed Jun 24 2026 Than Ngo - 149.0.7827.196-1 - Update to 149.0.7827.196 - Upstream patch, Make dark mode apply filter to images irrespective of layout zoom -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-ddd87cb1db' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Chromium 149.0.7827.196 release addresses critical use-after-free issues and more in Fedora 43. Update recommended.. Chromium Security, Fedora Browser Update, Use After Free Issues, Security Release Update. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 27, 2026 Critical Fedora
89

Fedora 44 Chromium Critical Use After Free CVE-2026-12437 Advisory

Update to 149.0.7827.155 CVE-2026-12437: Use after free in WebShare CVE-2026-12438: Inappropriate implementation in WebView CVE-2026-12439: Use after free in Digital Credentials CVE-2026-12440: Use after free in DigitalCredentials. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-650bd96540 2026-06-21 00:58:50.478412+00:00 -------------------------------------------------------------------------------- Name : chromium Product : Fedora 44 Version : 149.0.7827.155 Release : 1.fc44 URL : http://www.chromium.org/Home Summary : A WebKit (Blink) powered web browser that Google doesn't want you to use Description : Chromium is an open-source web browser, powered by WebKit (Blink). -------------------------------------------------------------------------------- Update Information: Update to 149.0.7827.155 CVE-2026-12437: Use after free in WebShare CVE-2026-12438: Inappropriate implementation in WebView CVE-2026-12439: Use after free in Digital Credentials CVE-2026-12440: Use after free in DigitalCredentials CVE-2026-12441: Use after free in File Input CVE-2026-12442: Use after free in Passwords CVE-2026-12443: Use after free in Web Authentication CVE-2026-12444: Out of bounds read in Chromoting CVE-2026-12445: Use after free in Extensions CVE-2026-12446: Insufficient data validation in Passwords CVE-2026-12447: Heap buffer overflow in WebRTC CVE-2026-12448: Inappropriate implementation in WebView CVE-2026-12449: Use after free in Chromoting CVE-2026-12450: Inappropriate implementation in Media CVE-2026-12451: Use after free in DigitalCredentials CVE-2026-12452: Use after free in Downloads CVE-2026-12453: Insufficient validation of untrusted input in Input CVE-2026-12454: Race in Safe Browsing CVE-2026-12455: Use after free in Tab Strip CVE-2026-12456: Insufficient validation of untrusted input in Extensions CVE-2026-12457: Insufficient data validation inExtensions CVE-2026-12458: Incorrect security UI in Passwords CVE-2026-12459: Inappropriate implementation in Serial CVE-2026-12460: Insufficient policy enforcement in File System Access CVE-2026-12461: Out of bounds read in WebRTC CVE-2026-12462: Use after free in Media CVE-2026-12463: Inappropriate implementation in Views CVE-2026-12464: Use after free in Browser CVE-2026-12465: Insufficient validation of untrusted input in Metrics CVE-2026-12466: Heap buffer overflow in WebRTC CVE-2026-12467: Use after free in Extensions CVE-2026-12468: Inappropriate implementation in Updater CVE-2026-12469: Uninitialized Use in GPU -------------------------------------------------------------------------------- ChangeLog: * Wed Jun 17 2026 Than Ngo - 149.0.7827.155-1 - Update to 149.0.7827.155 * CVE-2026-12437: Use after free in WebShare * CVE-2026-12438: Inappropriate implementation in WebView * CVE-2026-12439: Use after free in Digital Credentials * CVE-2026-12440: Use after free in DigitalCredentials * CVE-2026-12441: Use after free in File Input * CVE-2026-12442: Use after free in Passwords * CVE-2026-12443: Use after free in Web Authentication * CVE-2026-12444: Out of bounds read in Chromoting * CVE-2026-12445: Use after free in Extensions * CVE-2026-12446: Insufficient data validation in Passwords * CVE-2026-12447: Heap buffer overflow in WebRTC * CVE-2026-12448: Inappropriate implementation in WebView * CVE-2026-12449: Use after free in Chromoting * CVE-2026-12450: Inappropriate implementation in Media * CVE-2026-12451: Use after free in DigitalCredentials * CVE-2026-12452: Use after free in Downloads * CVE-2026-12453: Insufficient validation of untrusted input in Input * CVE-2026-12454: Race in Safe Browsing * CVE-2026-12455: Use after free in Tab Strip * CVE-2026-12456: Insufficient validation of untrusted input in Extensions * CVE-2026-12457: Insufficient data validation in Extensions * CVE-2026-12458: Incorrect security UI inPasswords * CVE-2026-12459: Inappropriate implementation in Serial * CVE-2026-12460: Insufficient policy enforcement in File System Access * CVE-2026-12461: Out of bounds read in WebRTC * CVE-2026-12462: Use after free in Media * CVE-2026-12463: Inappropriate implementation in Views * CVE-2026-12464: Use after free in Browser * CVE-2026-12465: Insufficient validation of untrusted input in Metrics * CVE-2026-12466: Heap buffer overflow in WebRTC * CVE-2026-12467: Use after free in Extensions * CVE-2026-12468: Inappropriate implementation in Updater * CVE-2026-12469: Uninitialized Use in GPU -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-650bd96540' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Critical updates for Fedora 44 improve chromium security addressing multiple vulnerabilities including use after free issues. Fedora update, chromium browser, security patch, use after free, inappropriate implementation. . Severity:Critical. LinuxSecurity.com Team

Calendar%202 Jun 20, 2026 Critical Fedora
89

Fedora 42 Chromium Update FEDORA-2026-06657d1811 Integer Overflow

Update to 145.0.7632.159 CVE-2026-3536: Integer overflow in ANGLE CVE-2026-3537: Object lifecycle issue in PowerVR CVE-2026-3538: Integer overflow in Skia CVE-2026-3539: Object lifecycle issue in DevTools. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-06657d1811 2026-03-10 01:09:17.058043+00:00 -------------------------------------------------------------------------------- Name : chromium Product : Fedora 42 Version : 145.0.7632.159 Release : 1.fc42 URL : http://www.chromium.org/Home Summary : A WebKit (Blink) powered web browser that Google doesn't want you to use Description : Chromium is an open-source web browser, powered by WebKit (Blink). -------------------------------------------------------------------------------- Update Information: Update to 145.0.7632.159 CVE-2026-3536: Integer overflow in ANGLE CVE-2026-3537: Object lifecycle issue in PowerVR CVE-2026-3538: Integer overflow in Skia CVE-2026-3539: Object lifecycle issue in DevTools CVE-2026-3540: Inappropriate implementation in WebAudio CVE-2026-3541: Inappropriate implementation in CSS CVE-2026-3542: Inappropriate implementation in WebAssembly CVE-2026-3543: Inappropriate implementation in V8 CVE-2026-3544: Heap buffer overflow in WebCodecs CVE-2026-3545: Insufficient data validation in Navigation -------------------------------------------------------------------------------- ChangeLog: * Fri Mar 6 2026 Than Ngo - 145.0.7632.159-1 - Update to 145.0.7632.159 * CVE-2026-3536: Integer overflow in ANGLE * CVE-2026-3537: Object lifecycle issue in PowerVR * CVE-2026-3538: Integer overflow in Skia * CVE-2026-3539: Object lifecycle issue in DevTools * CVE-2026-3540: Inappropriate implementation in WebAudio * CVE-2026-3541: Inappropriate implementation in CSS * CVE-2026-3542: Inappropriate implementation in WebAssembly * CVE-2026-3543: Inappropriate implementation in V8 *CVE-2026-3544: Heap buffer overflow in WebCodecs * CVE-2026-3545: Insufficient data validation in Navigation -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-06657d1811' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Update Chromium in Fedora 42 to address multiple security issues, including integer overflows and object lifecycle problems.. Fedora Chromium update integer overflow buffer. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Mar 10, 2026 Important Fedora
202

openSUSE Leap 16.0 Chromium Important Update 2026-20277-1

An update that solves 3 vulnerabilities and has one bug fix can now be installed.. openSUSE security update: security update for chromium ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:20277-1 Rating: important References: * bsc#1258733 Cross-References: * CVE-2025-3063 * CVE-2026-3061 * CVE-2026-3062 Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves 3 vulnerabilities and has one bug fix can now be installed. Description: This update for chromium fixes the following issues: Changes in chromium: - Chromium 145.0.7632.116 (boo#1258733): * CVE-2026-3061: Out of bounds read in Media * CVE-2026-3062: Out of bounds read and write in Tint * CVE-2025-3063: Inappropriate implementation in DevTools Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-packagehub-142=1 Package List: - openSUSE Leap 16.0: chromedriver-145.0.7632.116-bp160.1.1 chromium-145.0.7632.116-bp160.1.1 References: * https://www.suse.com/security/cve/CVE-2025-3063.html * https://www.suse.com/security/cve/CVE-2026-3061.html * https://www.suse.com/security/cve/CVE-2026-3062.html . Critical update for openSUSE addressing important issues in Chromium with three security fixes and one bug.. openSUSE Chromium security update important issues vulnerabilities. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Feb 27, 2026 Important OpenSUSE
89

Fedora 42 cef Patch for CVE-2026-1504 - Background Fetch API Vulnerability

Update to Chromium 144.0.7559.109 CVE-2026-1504: Inappropriate implementation in Background Fetch API. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-24ed079b30 2026-02-10 01:08:32.523402+00:00 -------------------------------------------------------------------------------- Name : cef Product : Fedora 42 Version : 144.0.11^chromium144.0.7559.109 Release : 2.fc42 URL : https://bitbucket.org/chromiumembedded/cef Summary : Chromium Embedded Framework Description : CEF is an embeddable build of Chromium, powered by WebKit (Blink). -------------------------------------------------------------------------------- Update Information: Update to Chromium 144.0.7559.109 CVE-2026-1504: Inappropriate implementation in Background Fetch API -------------------------------------------------------------------------------- ChangeLog: * Sat Jan 31 2026 Jan Stan\u011bk - 144.0.11^chromium144.0.7559.109-2 - Update BR for nodejs * Sat Jan 31 2026 Than Ngo - 144.0.11^chromium144.0.7559.109-1 - Update to 144.0.7559.109 - * CVE-2026-1504: Inappropriate implementation in Background Fetch API -------------------------------------------------------------------------------- References: [ 1 ] Bug #2435464 - cef-144.0.12 is available https://bugzilla.redhat.com/show_bug.cgi?id=2435464 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-24ed079b30' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . Update to Chromium 144.0.7559.109 inFedora 42 addresses a critical issue found in the Background Fetch API.. Fedora Update, Chromium Embedded Framework, Background Fetch API, Fedora 42, Security Advisory. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Feb 10, 2026 Important Fedora
89

Fedora 43: chromium High CVE-2025-13630 Type Confusion and more

Update to 143.0.7499.40 * High CVE-2025-13630: Type Confusion in V8 * High CVE-2025-13631: Inappropriate implementation in Google Updater * High CVE-2025-13632: Inappropriate implementation in DevTools * High CVE-2025-13633: Use after free in Digital Credentials. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-3c51a0ed51 2025-12-06 00:48:01.839843+00:00 -------------------------------------------------------------------------------- Name : chromium Product : Fedora 43 Version : 143.0.7499.40 Release : 1.fc43 URL : http://www.chromium.org/Home Summary : A WebKit (Blink) powered web browser that Google doesn't want you to use Description : Chromium is an open-source web browser, powered by WebKit (Blink). -------------------------------------------------------------------------------- Update Information: Update to 143.0.7499.40 * High CVE-2025-13630: Type Confusion in V8 * High CVE-2025-13631: Inappropriate implementation in Google Updater * High CVE-2025-13632: Inappropriate implementation in DevTools * High CVE-2025-13633: Use after free in Digital Credentials * Medium CVE-2025-13634: Inappropriate implementation in Downloads * Medium CVE-2025-13720: Bad cast in Loader * Medium CVE-2025-13721: Race in v8 * Low CVE-2025-13635: Inappropriate implementation in Downloads * Low CVE-2025-13636: Inappropriate implementation in Split View * Low CVE-2025-13637: Inappropriate implementation in Downloads * Low CVE-2025-13638: Use after free in Media Stream * Low CVE-2025-13639: Inappropriate implementation in WebRTC * Low CVE-2025-13640: Inappropriate implementation in Passwords -------------------------------------------------------------------------------- ChangeLog: * Tue Dec 2 2025 Than Ngo - 143.0.7499.40-1 - Update to 143.0.7499.40 * High CVE-2025-13630: Type Confusion in V8 * High CVE-2025-13631: Inappropriate implementation in GoogleUpdater * High CVE-2025-13632: Inappropriate implementation in DevTools * High CVE-2025-13633: Use after free in Digital Credentials * Medium CVE-2025-13634: Inappropriate implementation in Downloads * Medium CVE-2025-13720: Bad cast in Loader * Medium CVE-2025-13721: Race in v8 * Low CVE-2025-13635: Inappropriate implementation in Downloads * Low CVE-2025-13636: Inappropriate implementation in Split View * Low CVE-2025-13637: Inappropriate implementation in Downloads * Low CVE-2025-13638: Use after free in Media Stream * Low CVE-2025-13639: Inappropriate implementation in WebRTC * Low CVE-2025-13640: Inappropriate implementation in Passwords * Mon Dec 1 2025 LuK1337 - 142.0.7444.175-5 - Backport one more Wayland DnD bug fix from upstream -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-3c51a0ed51' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue . Critical security update addressing high-severity issues in Chromium for Fedora 43,including type confusion and insecure implementations.. CVE-2025-13630,CVE-2025-13631,CVE-2025-13632,Chromium,security advisory. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Dec 06, 2025 Critical Fedora
89

Fedora 41: Chromium High CVE-2025-13042 Inappropriate Implementation Threat

Update to 142.0.7444.162 * High CVE-2025-13042: Inappropriate implementation in V8. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-7c82e2b870 2025-11-19 01:21:16.309060+00:00 -------------------------------------------------------------------------------- Name : chromium Product : Fedora 41 Version : 142.0.7444.162 Release : 1.fc41 URL : http://www.chromium.org/Home Summary : A WebKit (Blink) powered web browser that Google doesn't want you to use Description : Chromium is an open-source web browser, powered by WebKit (Blink). -------------------------------------------------------------------------------- Update Information: Update to 142.0.7444.162 * High CVE-2025-13042: Inappropriate implementation in V8 -------------------------------------------------------------------------------- ChangeLog: * Wed Nov 12 2025 Than Ngo - 142.0.7444.162-1 - Update to 142.0.7444.162 * High CVE-2025-13042: Inappropriate implementation in V8 * Tue Nov 11 2025 Dominik Mierzejewski - 142.0.7444.134-2 - Rebuilt for FFmpeg 8 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2414356 - CVE-2025-12906 chromium: Inappropriate implementation in Permissions [epel-10] https://bugzilla.redhat.com/show_bug.cgi?id=2414356 [ 2 ] Bug #2414357 - CVE-2025-12906 chromium: Inappropriate implementation in Permissions [epel-8] https://bugzilla.redhat.com/show_bug.cgi?id=2414357 [ 3 ] Bug #2414359 - CVE-2025-12906 chromium: Inappropriate implementation in Permissions [epel-9] https://bugzilla.redhat.com/show_bug.cgi?id=2414359 [ 4 ] Bug #2414362 - CVE-2025-12906 chromium: Inappropriate implementation in Permissions [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2414362 [ 5 ] Bug #2414364 - CVE-2025-12906 chromium: Inappropriate implementation in Permissions [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2414364 [ 6 ] Bug #2414366 - CVE-2025-12906 chromium: Inappropriate implementation in Permissions [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2414366 [ 7 ] Bug #2414368 - CVE-2025-12910 chromium: Inappropriate implementation in Passkeys [epel-10] https://bugzilla.redhat.com/show_bug.cgi?id=2414368 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-7c82e2b870' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue . Update for Chromium on Fedora 41 addresses High severity CVE-2025-13042, enhancing browser security.. Fedora Chromium Security Update CVE-2025-13042. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Nov 19, 2025 Critical Fedora
89

Fedora 42: Advisory on Chromium CVE-2025-13042 High Risk Vulnerability

Update to 142.0.7444.162 * High CVE-2025-13042: Inappropriate implementation in V8. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-c92c2e0d79 2025-11-18 01:18:18.999249+00:00 -------------------------------------------------------------------------------- Name : chromium Product : Fedora 42 Version : 142.0.7444.162 Release : 1.fc42 URL : http://www.chromium.org/Home Summary : A WebKit (Blink) powered web browser that Google doesn't want you to use Description : Chromium is an open-source web browser, powered by WebKit (Blink). -------------------------------------------------------------------------------- Update Information: Update to 142.0.7444.162 * High CVE-2025-13042: Inappropriate implementation in V8 -------------------------------------------------------------------------------- ChangeLog: * Wed Nov 12 2025 Than Ngo - 142.0.7444.162-1 - Update to 142.0.7444.162 * High CVE-2025-13042: Inappropriate implementation in V8 * Tue Nov 11 2025 Dominik Mierzejewski - 142.0.7444.134-2 - Rebuilt for FFmpeg 8 * Thu Nov 6 2025 Than Ngo - 142.0.7444.134-1 - Update to 142.0.7444.134 * High CVE-2025-12725: Out of bounds write in WebGPU * High CVE-2025-12726: Inappropriate implementation in Views * High CVE-2025-12727: Inappropriate implementation in V8 * Medium CVE-2025-12728: Inappropriate implementation in Omnibox * Medium CVE-2025-12729: Inappropriate implementation in Omnibox * Wed Nov 5 2025 Dominik Mierzejewski - 142.0.7444.59-2 - Rebuilt for FFmpeg 8 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2414356 - CVE-2025-12906 chromium: Inappropriate implementation in Permissions [epel-10] https://bugzilla.redhat.com/show_bug.cgi?id=2414356 [ 2 ] Bug #2414357 - CVE-2025-12906 chromium: Inappropriate implementation in Permissions [epel-8] https://bugzilla.redhat.com/show_bug.cgi?id=2414357 [ 3 ] Bug #2414359 - CVE-2025-12906 chromium: Inappropriate implementation in Permissions [epel-9] https://bugzilla.redhat.com/show_bug.cgi?id=2414359 [ 4 ] Bug #2414362 - CVE-2025-12906 chromium: Inappropriate implementation in Permissions [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2414362 [ 5 ] Bug #2414364 - CVE-2025-12906 chromium: Inappropriate implementation in Permissions [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2414364 [ 6 ] Bug #2414366 - CVE-2025-12906 chromium: Inappropriate implementation in Permissions [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2414366 [ 7 ] Bug #2414368 - CVE-2025-12910 chromium: Inappropriate implementation in Passkeys [epel-10] https://bugzilla.redhat.com/show_bug.cgi?id=2414368 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-c92c2e0d79' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue .Fedora 42 updates chromium to version 142.0.7444.162 addressing high impact security issues effectively.. Fedora 42, chromium, security update, software vulnerability. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Nov 18, 2025 Critical Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200