An update that fixes 12 vulnerabilities is now available. . openSUSE Security Update: Security update for chromium ______________________________________________________________________________ Announcement ID: openSUSE-SU-2024:0084-1 Rating: important References: #1220131 #1220604 #1221105 #1221335 Cross-References: CVE-2024-1669 CVE-2024-1670 CVE-2024-1671 CVE-2024-1672 CVE-2024-1673 CVE-2024-1674 CVE-2024-1675 CVE-2024-1676 CVE-2024-2173 CVE-2024-2174 CVE-2024-2176 CVE-2024-2400 Affected Products: openSUSE Backports SLE-15-SP5 ______________________________________________________________________________ An update that fixes 12 vulnerabilities is now available. Description: This update for chromium fixes the following issue: Chromium 122.0.6261.128 (boo#1221335) * CVE-2024-2400: Use after free in Performance Manager Chromium 122.0.6261.111 (boo#1220131,boo#1220604,boo#1221105) * New upstream security release. * CVE-2024-2173: Out of bounds memory access in V8. * CVE-2024-2174: Inappropriate implementation in V8. * CVE-2024-2176: Use after free in FedCM. Chromium 122.0.6261.94 * CVE-2024-1669: Out of bounds memory access in Blink. * CVE-2024-1670: Use after free in Mojo. * CVE-2024-1671: Inappropriate implementation in Site Isolation. * CVE-2024-1672: Inappropriate implementation in Content Security Policy. * CVE-2024-1673: Use after free in Accessibility. * CVE-2024-1674: Inappropriate implementation in Navigation. * CVE-2024-1675: Insufficient policy enforcement in Download. * CVE-2024-1676: Inappropriate implementation in Navigation. * Type Confusion in V8 Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: -openSUSE Backports SLE-15-SP5: zypper in -t patch openSUSE-2024-84=1 Package List: - openSUSE Backports SLE-15-SP5 (aarch64 i586 ppc64le s390x x86_64): clang17-17.0.6-bp155.2.2 clang17-debuginfo-17.0.6-bp155.2.2 clang17-devel-17.0.6-bp155.2.2 libLLVM17-17.0.6-bp155.2.2 libLLVM17-debuginfo-17.0.6-bp155.2.2 libLTO17-17.0.6-bp155.2.2 libLTO17-debuginfo-17.0.6-bp155.2.2 libclang-cpp17-17.0.6-bp155.2.2 libclang-cpp17-debuginfo-17.0.6-bp155.2.2 lld17-17.0.6-bp155.2.2 lld17-debuginfo-17.0.6-bp155.2.2 llvm17-17.0.6-bp155.2.2 llvm17-debuginfo-17.0.6-bp155.2.2 llvm17-devel-17.0.6-bp155.2.2 llvm17-devel-debuginfo-17.0.6-bp155.2.2 llvm17-gold-17.0.6-bp155.2.2 llvm17-gold-debuginfo-17.0.6-bp155.2.2 llvm17-libclang13-17.0.6-bp155.2.2 llvm17-libclang13-debuginfo-17.0.6-bp155.2.2 llvm17-polly-17.0.6-bp155.2.2 llvm17-polly-debuginfo-17.0.6-bp155.2.2 llvm17-polly-devel-17.0.6-bp155.2.2 - openSUSE Backports SLE-15-SP5 (aarch64 i586 ppc64le x86_64): libomp17-devel-17.0.6-bp155.2.2 libomp17-devel-debuginfo-17.0.6-bp155.2.2 - openSUSE Backports SLE-15-SP5 (aarch64 x86_64): chromedriver-122.0.6261.128-bp155.2.75.1 chromedriver-debuginfo-122.0.6261.128-bp155.2.75.1 chromium-122.0.6261.128-bp155.2.75.1 chromium-debuginfo-122.0.6261.128-bp155.2.75.1 liblldb17-17.0.6-bp155.2.2 liblldb17-debuginfo-17.0.6-bp155.2.2 lldb17-17.0.6-bp155.2.2 lldb17-debuginfo-17.0.6-bp155.2.2 lldb17-devel-17.0.6-bp155.2.2 llvm17-libc++-devel-17.0.6-bp155.2.2 llvm17-libc++1-17.0.6-bp155.2.2 llvm17-libc++1-debuginfo-17.0.6-bp155.2.2 llvm17-libc++abi-devel-17.0.6-bp155.2.2 llvm17-libc++abi1-17.0.6-bp155.2.2 llvm17-libc++abi1-debuginfo-17.0.6-bp155.2.2 python3-lldb17-17.0.6-bp155.2.2 - openSUSE Backports SLE-15-SP5 (aarch64_ilp32): libLLVM17-64bit-17.0.6-bp155.2.2 libLLVM17-64bit-debuginfo-17.0.6-bp155.2.2 libclang-cpp17-64bit-17.0.6-bp155.2.2 libclang-cpp17-64bit-debuginfo-17.0.6-bp155.2.2 - openSUSE Backports SLE-15-SP5 (x86_64): libLLVM17-32bit-17.0.6-bp155.2.2 libLLVM17-32bit-debuginfo-17.0.6-bp155.2.2 libclang-cpp17-32bit-17.0.6-bp155.2.2 libclang-cpp17-32bit-debuginfo-17.0.6-bp155.2.2 - openSUSE Backports SLE-15-SP5 (noarch): clang17-doc-17.0.6-bp155.2.2 llvm17-doc-17.0.6-bp155.2.2 llvm17-opt-viewer-17.0.6-bp155.2.2 llvm17-vim-plugins-17.0.6-bp155.2.2 python3-clang17-17.0.6-bp155.2.2 References: https://www.suse.com/security/cve/CVE-2024-1669.html https://www.suse.com/security/cve/CVE-2024-1670.html https://www.suse.com/security/cve/CVE-2024-1671.html https://www.suse.com/security/cve/CVE-2024-1672.html https://www.suse.com/security/cve/CVE-2024-1673.html https://www.suse.com/security/cve/CVE-2024-1674.html https://www.suse.com/security/cve/CVE-2024-1675.html https://www.suse.com/security/cve/CVE-2024-1676.html https://www.suse.com/security/cve/CVE-2024-2173.html https://www.suse.com/security/cve/CVE-2024-2174.html https://www.suse.com/security/cve/CVE-2024-2176.html https://www.suse.com/security/cve/CVE-2024-2400.html https://bugzilla.suse.com/1220131 https://bugzilla.suse.com/1220604 https://bugzilla.suse.com/1221105 https://bugzilla.suse.com/1221335 . A critical openSUSE security patch for firefox tackles 15 vulnerabilities, strengthening system defenses.. openSUSE security update, chromium vulnerabilities, important patch, openSUSE Backports. . Severity: Important. LinuxSecurity.com Team
upstream security release 122.0.6261.128 High CVE-2024-2400: Use after free in Performance Manager. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-ac1eb810c5 2024-03-16 01:50:49.900381 -------------------------------------------------------------------------------- Name : chromium Product : Fedora 38 Version : 122.0.6261.128 Release : 1.fc38 URL : https://www.chromium.org/Home/ Summary : A WebKit (Blink) powered web browser that Google doesn't want you to use Description : Chromium is an open-source web browser, powered by WebKit (Blink). -------------------------------------------------------------------------------- Update Information: upstream security release 122.0.6261.128 High CVE-2024-2400: Use after free in Performance Manager -------------------------------------------------------------------------------- ChangeLog: * Wed Mar 13 2024 Than Ngo - 122.0.6261.128-1 - upstream security release 122.0.6261.128 * High CVE-2024-2400: Use after free in Performance Manager * Mon Mar 11 2024 Than Ngo - 122.0.6261.111-2 - enable ppc64le build -------------------------------------------------------------------------------- References: [ 1 ] Bug #2269306 - CVE-2024-2400 chromium: chromium-browser: Use after free in Performance Manager [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2269306 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-ac1eb810c5' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.