Update to 141.0.7390.54 * High CVE-2025-11205: Heap buffer overflow in WebGPU * High CVE-2025-11206: Heap buffer overflow in Video * Medium CVE-2025-11207: Side-channel information leakage in Storage * Medium CVE-2025-11208: Inappropriate implementation in Media. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-acc92fcc12 2025-10-07 00:54:27.049559+00:00 -------------------------------------------------------------------------------- Name : chromium Product : Fedora 42 Version : 141.0.7390.54 Release : 1.fc42 URL : http://www.chromium.org/Home Summary : A WebKit (Blink) powered web browser that Google doesn't want you to use Description : Chromium is an open-source web browser, powered by WebKit (Blink). -------------------------------------------------------------------------------- Update Information: Update to 141.0.7390.54 * High CVE-2025-11205: Heap buffer overflow in WebGPU * High CVE-2025-11206: Heap buffer overflow in Video * Medium CVE-2025-11207: Side-channel information leakage in Storage * Medium CVE-2025-11208: Inappropriate implementation in Media * Medium CVE-2025-11209: Inappropriate implementation in Omnibox * Medium CVE-2025-11210: Side-channel information leakage in Tab * Medium CVE-2025-11211: Out of bounds read in Media * Medium CVE-2025-11212: Inappropriate implementation in Media * Medium CVE-2025-11213: Inappropriate implementation in Omnibox * Medium CVE-2025-11215: Off by one error in V8 * Low CVE-2025-11216: Inappropriate implementation in Storage * Low CVE-2025-11219: Use after free in V8 -------------------------------------------------------------------------------- ChangeLog: * Thu Oct 2 2025 Than Ngo - 141.0.7390.54-1 - Update to 141.0.7390.54 * High CVE-2025-11205: Heap buffer overflow in WebGPU * High CVE-2025-11206: Heap buffer overflow in Video * Medium CVE-2025-11207: Side-channel informationleakage in Storage * Medium CVE-2025-11208: Inappropriate implementation in Media * Medium CVE-2025-11209: Inappropriate implementation in Omnibox * Medium CVE-2025-11210: Side-channel information leakage in Tab * Medium CVE-2025-11211: Out of bounds read in Media * Medium CVE-2025-11212: Inappropriate implementation in Media * Medium CVE-2025-11213: Inappropriate implementation in Omnibox * Medium CVE-2025-11215: Off by one error in V8 * Low CVE-2025-11216: Inappropriate implementation in Storage * Low CVE-2025-11219: Use after free in V8 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2381730 - DebugInfo packages aren't being produced. https://bugzilla.redhat.com/show_bug.cgi?id=2381730 [ 2 ] Bug #2400095 - Update chromium-141.0.7390.54 major release [fedora-all, epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2400095 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-acc92fcc12' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
High CVE-2025-1914: Out of bounds read in V8. Medium CVE-2025-1915: Improper Limitation of a Pathname to a Restricted Directory in DevTools. Medium CVE-2025-1916: Use after free in Profiles. Medium CVE-2025-1917: Inappropriate Implementation in Browser UI. . MGASA-2025-0091 - Updated chromium-browser-stable packages fix security vulnerabilities Publication date: 08 Mar 2025 URL: https://advisories.mageia.org/MGASA-2025-0091.html Type: security Affected Mageia releases: 9 CVE: CVE-2025-0444, CVE-2025-0445, CVE-2025-0451, CVE-2025-0995, CVE-2025-0996, CVE-2025-0997, CVE-2025-0998, CVE-2025-0999, CVE-2025-1426, CVE-2025-1006, CVE-2025-1914, CVE-2025-1915, CVE-2025-1916, CVE-2025-1917, CVE-2025-1918, CVE-2025-1919, CVE-2025-1921, CVE-2025-1922 High CVE-2025-1914: Out of bounds read in V8. Medium CVE-2025-1915: Improper Limitation of a Pathname to a Restricted Directory in DevTools. Medium CVE-2025-1916: Use after free in Profiles. Medium CVE-2025-1917: Inappropriate Implementation in Browser UI. Medium CVE-2025-1918: Out of bounds read in PDFium. Medium CVE-2025-1919: Out of bounds read in Media. Medium CVE-2025-1921: Inappropriate Implementation in Media Low CVE-2025-1922: Inappropriate Implementation in Selection. Low CVE-2025-1923: Inappropriate Implementation in Permission Prompts. And more, please see the references. References: - https://bugs.mageia.org/show_bug.cgi?id=34012 - https://chromereleases.googleblog.com/2025/03/stable-channel-update-for-desktop.html - https://chromereleases.googleblog.com/2025/02/stable-channel-update-for-desktop_25.html - https://chromereleases.googleblog.com/2025/02/stable-channel-update-for-desktop_18.html - https://chromereleases.googleblog.com/2025/02/stable-channel-update-for-desktop_12.html - https://chromereleases.googleblog.com/2025/02/stable-channel-update-for-desktop.html - https://www.cve.org/CVERecord?id=CVE-2025-0444 - https://www.cve.org/CVERecord?id=CVE-2025-0445 -https://www.cve.org/CVERecord?id=CVE-2025-0451 - https://www.cve.org/CVERecord?id=CVE-2025-0995 - https://www.cve.org/CVERecord?id=CVE-2025-0996 - https://www.cve.org/CVERecord?id=CVE-2025-0997 - https://www.cve.org/CVERecord?id=CVE-2025-0998 - https://www.cve.org/CVERecord?id=CVE-2025-0999 - https://www.cve.org/CVERecord?id=CVE-2025-1426 - https://www.cve.org/CVERecord?id=CVE-2025-1006 - https://www.cve.org/CVERecord?id=CVE-2025-1914 - https://www.cve.org/CVERecord?id=CVE-2025-1915 - https://www.cve.org/CVERecord?id=CVE-2025-1916 - https://www.cve.org/CVERecord?id=CVE-2025-1917 - https://www.cve.org/CVERecord?id=CVE-2025-1918 - https://www.cve.org/CVERecord?id=CVE-2025-1919 - https://www.cve.org/CVERecord?id=CVE-2025-1921 - https://www.cve.org/CVERecord?id=CVE-2025-1922 SRPMS: - 9/tainted/chromium-browser-stable-134.0.6998.35-1.mga9.tainted . Recent updates to the chromium-browser-stable packages address both high and medium severity security issues that have been revealed.. chromium-browser update, Mageia security advisory, browser vulnerabilities. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.