Explore top 10 tips to secure your open-source projects now. Read More
×
Update to 137.0.7151.68 CVE-2025-5419: Out of bounds read and write in V8 CVE-2025-5068: Use after free in Blink. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-bc0d109630 2025-06-07 06:45:35.205082+00:00 -------------------------------------------------------------------------------- Name : chromium Product : Fedora 42 Version : 137.0.7151.68 Release : 1.fc42 URL : http://www.chromium.org/Home Summary : A WebKit (Blink) powered web browser that Google doesn't want you to use Description : Chromium is an open-source web browser, powered by WebKit (Blink). -------------------------------------------------------------------------------- Update Information: Update to 137.0.7151.68 CVE-2025-5419: Out of bounds read and write in V8 CVE-2025-5068: Use after free in Blink -------------------------------------------------------------------------------- ChangeLog: * Tue Jun 3 2025 Than Ngo - 137.0.7151.68-1 - Update to 137.0.7151.68 * CVE-2025-5419: Out of bounds read and write in V8 * CVE-2025-5068: Use after free in Blink -------------------------------------------------------------------------------- References: [ 1 ] Bug #2369919 - CVE-2025-5068 chromium: Chrome Use-After-Free Vulnerability [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2369919 [ 2 ] Bug #2369920 - CVE-2025-5068 chromium: Chrome Use-After-Free Vulnerability [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2369920 [ 3 ] Bug #2369921 - CVE-2025-5419 chromium: Chrome Heap Corruption Vulnerability [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2369921 [ 4 ] Bug #2369922 - CVE-2025-5419 chromium: Chrome Heap Corruption Vulnerability [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2369922 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program.Use su -c 'dnf upgrade --advisory FEDORA-2025-bc0d109630' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Update to 137.0.7151.68 CVE-2025-5419: Out of bounds read and write in V8 CVE-2025-5068: Use after free in Blink. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-be7ea2f22d 2025-06-07 05:42:23.006513+00:00 -------------------------------------------------------------------------------- Name : chromium Product : Fedora 41 Version : 137.0.7151.68 Release : 1.fc41 URL : http://www.chromium.org/Home Summary : A WebKit (Blink) powered web browser that Google doesn't want you to use Description : Chromium is an open-source web browser, powered by WebKit (Blink). -------------------------------------------------------------------------------- Update Information: Update to 137.0.7151.68 CVE-2025-5419: Out of bounds read and write in V8 CVE-2025-5068: Use after free in Blink -------------------------------------------------------------------------------- ChangeLog: * Tue Jun 3 2025 Than Ngo - 137.0.7151.68-1 - Update to 137.0.7151.68 * CVE-2025-5419: Out of bounds read and write in V8 * CVE-2025-5068: Use after free in Blink -------------------------------------------------------------------------------- References: [ 1 ] Bug #2369919 - CVE-2025-5068 chromium: Chrome Use-After-Free Vulnerability [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2369919 [ 2 ] Bug #2369920 - CVE-2025-5068 chromium: Chrome Use-After-Free Vulnerability [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2369920 [ 3 ] Bug #2369921 - CVE-2025-5419 chromium: Chrome Heap Corruption Vulnerability [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2369921 [ 4 ] Bug #2369922 - CVE-2025-5419 chromium: Chrome Heap Corruption Vulnerability [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2369922 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program.Use su -c 'dnf upgrade --advisory FEDORA-2025-be7ea2f22d' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
* bsc#1241162 * bsc#1241214 * bsc#1241226 * bsc#1241238 * bsc#1241252 . # Security update for libsoup2 Announcement ID: SUSE-SU-2025:01802-1 Release Date: 2025-06-03T01:15:23Z Rating: important References: * bsc#1241162 * bsc#1241214 * bsc#1241226 * bsc#1241238 * bsc#1241252 * bsc#1241263 * bsc#1243332 * bsc#1243423 Cross-References: * CVE-2025-32906 * CVE-2025-32909 * CVE-2025-32910 * CVE-2025-32911 * CVE-2025-32912 * CVE-2025-32913 * CVE-2025-4948 * CVE-2025-4969 CVSS scores: * CVE-2025-32906 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2025-32906 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-32909 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2025-32909 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2025-32909 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-32910 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-32910 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2025-32910 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2025-32911 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2025-32911 ( NVD ): 9.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H * CVE-2025-32912 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2025-32912 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2025-32913 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-32913 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-4948 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-4948 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-4948 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-4969 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N *CVE-2025-4969 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2025-4969 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L Affected Products: * Basesystem Module 15-SP6 * Basesystem Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves eight vulnerabilities can now be installed. ## Description: This update for libsoup2 fixes the following issues: * CVE-2025-4948: Fixed integer underflow in soup_multipart_new_from_message() leading to denial of service (bsc#1243332) * CVE-2025-4969: Fixed off-by-one out-of-bounds read may lead to infoleak (bsc#1243423) * CVE-2025-32906: Fixed out of bounds reads in soup_headers_parse_request() (bsc#1241263) * CVE-2025-32909: Fixed NULL pointer dereference in the sniff_mp4 function in soup-content-sniffer.c (bsc#1241226) * CVE-2025-32910: Fixed null pointer deference on client when server omits the realm parameter in an Unauthorized response with Digest authentication (bsc#1241252) * CVE-2025-32911: Fixed double free on soup_message_headers_get_content_disposition() via "params". (bsc#1241238) * CVE-2025-32912: Fixed NULL pointer dereference in SoupAuthDigest (bsc#1241214) * CVE-2025-32913: Fixed NULL pointer dereference in soup_message_headers_get_content_disposition (bsc#1241162) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2025-1802=1 SUSE-2025-1802=1 * Basesystem Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP6-2025-1802=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2025-1802=1 ## Package List: * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64 i586) * libsoup-2_4-1-debuginfo-2.74.3-150600.4.9.1 * libsoup-2_4-1-2.74.3-150600.4.9.1 * libsoup2-debugsource-2.74.3-150600.4.9.1 * libsoup2-devel-2.74.3-150600.4.9.1 * typelib-1_0-Soup-2_4-2.74.3-150600.4.9.1 * openSUSE Leap 15.6 (x86_64) * libsoup2-devel-32bit-2.74.3-150600.4.9.1 * libsoup-2_4-1-32bit-2.74.3-150600.4.9.1 * libsoup-2_4-1-32bit-debuginfo-2.74.3-150600.4.9.1 * openSUSE Leap 15.6 (noarch) * libsoup2-lang-2.74.3-150600.4.9.1 * openSUSE Leap 15.6 (aarch64_ilp32) * libsoup-2_4-1-64bit-debuginfo-2.74.3-150600.4.9.1 * libsoup2-devel-64bit-2.74.3-150600.4.9.1 * libsoup-2_4-1-64bit-2.74.3-150600.4.9.1 * Basesystem Module 15-SP6 (aarch64 ppc64le s390x x86_64) * libsoup-2_4-1-debuginfo-2.74.3-150600.4.9.1 * libsoup-2_4-1-2.74.3-150600.4.9.1 * libsoup2-debugsource-2.74.3-150600.4.9.1 * libsoup2-devel-2.74.3-150600.4.9.1 * typelib-1_0-Soup-2_4-2.74.3-150600.4.9.1 * Basesystem Module 15-SP6 (noarch) * libsoup2-lang-2.74.3-150600.4.9.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libsoup-2_4-1-debuginfo-2.74.3-150600.4.9.1 * libsoup-2_4-1-2.74.3-150600.4.9.1 * libsoup2-debugsource-2.74.3-150600.4.9.1 * libsoup2-devel-2.74.3-150600.4.9.1 * typelib-1_0-Soup-2_4-2.74.3-150600.4.9.1 * Basesystem Module 15-SP7 (noarch) * libsoup2-lang-2.74.3-150600.4.9.1 ## References: * https://www.suse.com/security/cve/CVE-2025-32906.html * https://www.suse.com/security/cve/CVE-2025-32909.html * https://www.suse.com/security/cve/CVE-2025-32910.html * https://www.suse.com/security/cve/CVE-2025-32911.html * https://www.suse.com/security/cve/CVE-2025-32912.html * https://www.suse.com/security/cve/CVE-2025-32913.html *https://www.suse.com/security/cve/CVE-2025-4948.html * https://www.suse.com/security/cve/CVE-2025-4969.html * https://bugzilla.suse.com/show_bug.cgi?id=1241162 * https://bugzilla.suse.com/show_bug.cgi?id=1241214 * https://bugzilla.suse.com/show_bug.cgi?id=1241226 * https://bugzilla.suse.com/show_bug.cgi?id=1241238 * https://bugzilla.suse.com/show_bug.cgi?id=1241252 * https://bugzilla.suse.com/show_bug.cgi?id=1241263 * https://bugzilla.suse.com/show_bug.cgi?id=1243332 * https://bugzilla.suse.com/show_bug.cgi?id=1243423 . Critical patches released for libsoup2 vulnerabilities impacting SUSE systems. Ensure you update promptly for your security!. SUSE Security, libsoup2 Update, Software Vulnerabilities, Important Patch. . Severity: Important. LinuxSecurity.com Team
* bsc#1241162 * bsc#1241214 * bsc#1241226 * bsc#1241238 * bsc#1241252 . # Security update for libsoup Announcement ID: SUSE-SU-2025:01794-1 Release Date: 2025-06-02T09:04:19Z Rating: important References: * bsc#1241162 * bsc#1241214 * bsc#1241226 * bsc#1241238 * bsc#1241252 * bsc#1241263 * bsc#1243332 * bsc#1243423 Cross-References: * CVE-2025-32906 * CVE-2025-32909 * CVE-2025-32910 * CVE-2025-32911 * CVE-2025-32912 * CVE-2025-32913 * CVE-2025-4948 * CVE-2025-4969 CVSS scores: * CVE-2025-32906 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2025-32906 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-32909 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2025-32909 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2025-32909 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-32910 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-32910 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2025-32910 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2025-32911 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2025-32911 ( NVD ): 9.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H * CVE-2025-32912 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2025-32912 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2025-32913 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-32913 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-4948 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-4948 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-4948 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-4969 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N *CVE-2025-4969 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2025-4969 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves eight vulnerabilities can now be installed. ## Description: This update for libsoup fixes the following issues: * CVE-2025-4948: Fixed integer underflow in soup_multipart_new_from_message() leading to denial of service (bsc#1243332) * CVE-2025-4969: Fixed off-by-one out-of-bounds read may lead to infoleak (bsc#1243423) * CVE-2025-32906: Fixed out of bounds reads in soup_headers_parse_request() (bsc#1241263) * CVE-2025-32909: Fixed NULL pointer dereference in the sniff_mp4 function in soup-content-sniffer.c (bsc#1241226) * CVE-2025-32910: Fixed null pointer deference on client when server omits the realm parameter in an Unauthorized response with Digest authentication (bsc#1241252) * CVE-2025-32911: Fixed double free on soup_message_headers_get_content_disposition() via "params". (bsc#1241238) * CVE-2025-32912: Fixed NULL pointer dereference in SoupAuthDigest (bsc#1241214) * CVE-2025-32913: Fixed NULL pointer dereference in soup_message_headers_get_content_disposition (bsc#1241162) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2025-1794=1 * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2025-1794=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5LTSS Extended Security (x86_64) * libsoup-2_4-1-32bit-2.62.2-5.15.1 * libsoup-2_4-1-debuginfo-2.62.2-5.15.1 * libsoup-debugsource-2.62.2-5.15.1 * typelib-1_0-Soup-2_4-2.62.2-5.15.1 * libsoup-2_4-1-debuginfo-32bit-2.62.2-5.15.1 * libsoup-2_4-1-2.62.2-5.15.1 * libsoup-devel-2.62.2-5.15.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (noarch) * libsoup-lang-2.62.2-5.15.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * libsoup-2_4-1-debuginfo-2.62.2-5.15.1 * libsoup-debugsource-2.62.2-5.15.1 * typelib-1_0-Soup-2_4-2.62.2-5.15.1 * libsoup-2_4-1-2.62.2-5.15.1 * libsoup-devel-2.62.2-5.15.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (noarch) * libsoup-lang-2.62.2-5.15.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (s390x x86_64) * libsoup-2_4-1-debuginfo-32bit-2.62.2-5.15.1 * libsoup-2_4-1-32bit-2.62.2-5.15.1 ## References: * https://www.suse.com/security/cve/CVE-2025-32906.html * https://www.suse.com/security/cve/CVE-2025-32909.html * https://www.suse.com/security/cve/CVE-2025-32910.html * https://www.suse.com/security/cve/CVE-2025-32911.html * https://www.suse.com/security/cve/CVE-2025-32912.html * https://www.suse.com/security/cve/CVE-2025-32913.html * https://www.suse.com/security/cve/CVE-2025-4948.html * https://www.suse.com/security/cve/CVE-2025-4969.html * https://bugzilla.suse.com/show_bug.cgi?id=1241162 * https://bugzilla.suse.com/show_bug.cgi?id=1241214 * https://bugzilla.suse.com/show_bug.cgi?id=1241226 * https://bugzilla.suse.com/show_bug.cgi?id=1241238 * https://bugzilla.suse.com/show_bug.cgi?id=1241252 * https://bugzilla.suse.com/show_bug.cgi?id=1241263 * https://bugzilla.suse.com/show_bug.cgi?id=1243332 * https://bugzilla.suse.com/show_bug.cgi?id=1243423 . The recent patch addresses various vulnerabilities in libsoup, specifically focusing on mitigating denial of service threats and enhancing overall security measures for SUSE systems.. libsoup update, SUSEsecurity fix, software vulnerabilities, denial of service, out of bounds errors. . Severity: Important. LinuxSecurity.com Team
Update to 137.0.7151.55 CVE-2025-5063: Use after free in Compositing CVE-2025-5280: Out of bounds write in V8 CVE-2025-5064: Inappropriate implementation in Background Fetch API CVE-2025-5065: Inappropriate implementation in FileSystemAccess API. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-680072bb22 2025-06-02 01:26:34.790050+00:00 -------------------------------------------------------------------------------- Name : chromium Product : Fedora 41 Version : 137.0.7151.55 Release : 1.fc41 URL : http://www.chromium.org/Home Summary : A WebKit (Blink) powered web browser that Google doesn't want you to use Description : Chromium is an open-source web browser, powered by WebKit (Blink). -------------------------------------------------------------------------------- Update Information: Update to 137.0.7151.55 CVE-2025-5063: Use after free in Compositing CVE-2025-5280: Out of bounds write in V8 CVE-2025-5064: Inappropriate implementation in Background Fetch API CVE-2025-5065: Inappropriate implementation in FileSystemAccess API CVE-2025-5066: Inappropriate implementation in Messages CVE-2025-5281: Inappropriate implementation in BFCache CVE-2025-5283: Use after free in libvpx CVE-2025-5067: Inappropriate implementation in Tab Strip -------------------------------------------------------------------------------- ChangeLog: * Tue May 27 2025 Than Ngo - 137.0.7151.55-1 - Update to 137.0.7151.55 * CVE-2025-5063: Use after free in Compositing * CVE-2025-5280: Out of bounds write in V8 * CVE-2025-5064: Inappropriate implementation in Background Fetch API * CVE-2025-5065: Inappropriate implementation in FileSystemAccess API * CVE-2025-5066: Inappropriate implementation in Messages * CVE-2025-5281: Inappropriate implementation in BFCache * CVE-2025-5283: Use after free in libvpx * CVE-2025-5067: Inappropriate implementation in Tab Strip - Fix FTBFS causedby simdutf and pdfium-png_decoder - Remove chromium-135-gperf.patch and chromium-135-add-cfi-suppressions-for-pipewire-functions.patch, merged by upstream - Refresh ppc64le patches - Enable system simdutf for F43 * Tue May 27 2025 Jitka Plesnikova - 136.0.7103.113-2 - Rebuilt for flac 1.5.0 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-680072bb22' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Update to 136.0.7103.59 CVE-2025-4096: Heap buffer overflow in HTML CVE-2025-4050: Out of bounds memory access in DevTools CVE-2025-4051: Insufficient data validation in DevTools CVE-2025-4052: Inappropriate implementation in DevTools. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-b1804b97fc 2025-05-04 01:43:02.601141+00:00 -------------------------------------------------------------------------------- Name : chromium Product : Fedora 40 Version : 136.0.7103.59 Release : 1.fc40 URL : http://www.chromium.org/Home Summary : A WebKit (Blink) powered web browser that Google doesn't want you to use Description : Chromium is an open-source web browser, powered by WebKit (Blink). -------------------------------------------------------------------------------- Update Information: Update to 136.0.7103.59 CVE-2025-4096: Heap buffer overflow in HTML CVE-2025-4050: Out of bounds memory access in DevTools CVE-2025-4051: Insufficient data validation in DevTools CVE-2025-4052: Inappropriate implementation in DevTools -------------------------------------------------------------------------------- ChangeLog: * Tue Apr 29 2025 Than Ngo - 136.0.7103.59-1 - Update to 136.0.7103.59 * CVE-2025-4096: Heap buffer overflow in HTML * CVE-2025-4050: Out of bounds memory access in DevTools * CVE-2025-4051: Insufficient data validation in DevTools * CVE-2025-4052: Inappropriate implementation in DevTools * Thu Apr 24 2025 Than Ngo - 136.0.7103.48-1 - Update to 136.0.7103.48 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-b1804b97fc' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora ProjectGPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Several security issues were fixed in the Linux kernel.. ========================================================================== Ubuntu Security Notice USN-7475-1 May 02, 2025 linux-xilinx-zynqmp vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 22.04 LTS Summary: Several security issues were fixed in the Linux kernel. Software Description: - linux-xilinx-zynqmp: Linux kernel for Xilinx ZynqMP processors Details: Jann Horn discovered that the watch_queue event notification subsystem in the Linux kernel contained an out-of-bounds write vulnerability. A local attacker could use this to cause a denial of service (system crash) or escalate their privileges. (CVE-2022-0995) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - iSCSI Boot Firmware Table Attributes driver; - GPU drivers; - Network drivers; - File systems infrastructure; - NTFS3 file system; - SMB network file system; - Network namespace; - Ethernet bridge; - Networking core; - Ethtool driver; - IPv6 networking; - Network traffic control; - VMware vSockets driver; (CVE-2024-50248, CVE-2024-57798, CVE-2025-21702, CVE-2024-56651, CVE-2024-26837, CVE-2025-21703, CVE-2024-46826, CVE-2025-21700, CVE-2024-50256, CVE-2024-35864, CVE-2025-21756, CVE-2025-21993, CVE-2024-26928, CVE-2024-56658, CVE-2025-21701) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 22.04 LTS linux-image-5.15.0-1046-xilinx-zynqmp 5.15.0-1046.50 linux-image-xilinx-zynqmp 5.15.0.1046.50 After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompileand reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-7475-1 CVE-2022-0995, CVE-2024-26837, CVE-2024-26928, CVE-2024-35864, CVE-2024-46826, CVE-2024-50248, CVE-2024-50256, CVE-2024-56651, CVE-2024-56658, CVE-2024-57798, CVE-2025-21700, CVE-2025-21701, CVE-2025-21702, CVE-2025-21703, CVE-2025-21756, CVE-2025-21993 Package Information: https://launchpad.net/ubuntu/+source/linux-xilinx-zynqmp/5.15.0-1046.50 . Several vulnerabilities fixed in Ubuntu 22.04 LTS Linux kernel - essential patches and guidance to protect your device.. ubuntu security updates, linux kernel security, zynqmp security advisory. . Severity: Critical. LinuxSecurity.com Team
An out of bounds write with subglyph structures has been fixed in the font rendering library FreeType. For Debian 11 bullseye, this problem has been fixed in version . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-4104-1
Get the latest Linux and open source security news straight to your inbox.