Update to 135.0.7049.84 CVE-2025-3066: Use after free in Site Isolation. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-0f2d318242 2025-04-15 17:58:27.650051+00:00 -------------------------------------------------------------------------------- Name : chromium Product : Fedora 42 Version : 135.0.7049.84 Release : 1.fc42 URL : http://www.chromium.org/Home Summary : A WebKit (Blink) powered web browser that Google doesn't want you to use Description : Chromium is an open-source web browser, powered by WebKit (Blink). -------------------------------------------------------------------------------- Update Information: Update to 135.0.7049.84 CVE-2025-3066: Use after free in Site Isolation -------------------------------------------------------------------------------- ChangeLog: * Wed Apr 9 2025 Than Ngo - 135.0.7049.84-1 - Update to 135.0.7049.84 * CVE-2025-3066: Use after free in Site Isolation -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-0f2d318242' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Update to 135.0.7049.84 * CVE-2025-3066: Use after free in Site Isolation. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-20e35f4f9f 2025-04-13 01:38:34.488685+00:00 -------------------------------------------------------------------------------- Name : chromium Product : Fedora 41 Version : 135.0.7049.84 Release : 1.fc41 URL : http://www.chromium.org/Home Summary : A WebKit (Blink) powered web browser that Google doesn't want you to use Description : Chromium is an open-source web browser, powered by WebKit (Blink). -------------------------------------------------------------------------------- Update Information: Update to 135.0.7049.84 * CVE-2025-3066: Use after free in Site Isolation -------------------------------------------------------------------------------- ChangeLog: * Wed Apr 9 2025 Than Ngo - 135.0.7049.84-1 - Update to 135.0.7049.84 * CVE-2025-3066: Use after free in Site Isolation * Wed Apr 2 2025 Jan Grulich - 135.0.7049.52-2 - Add CFI suppressions for inline PipeWire functions -------------------------------------------------------------------------------- References: [ 1 ] Bug #2357598 - headless Chromium locks up trying to process some (not all) images https://bugzilla.redhat.com/show_bug.cgi?id=2357598 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-20e35f4f9f' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Update to 122.0.6261.57 High CVE-2024-1669: Out of bounds memory access in Blink High CVE-2024-1670: Use after free in Mojo Medium CVE-2024-1671: Inappropriate implementation in Site Isolation Medium CVE-2024-1672: Inappropriate implementation in Content Security Policy. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-6a879cfa63 2024-02-25 01:24:47.525768 -------------------------------------------------------------------------------- Name : chromium Product : Fedora 38 Version : 122.0.6261.57 Release : 1.fc38 URL : https://www.chromium.org/Home/ Summary : A WebKit (Blink) powered web browser that Google doesn't want you to use Description : Chromium is an open-source web browser, powered by WebKit (Blink). -------------------------------------------------------------------------------- Update Information: Update to 122.0.6261.57 High CVE-2024-1669: Out of bounds memory access in Blink High CVE-2024-1670: Use after free in Mojo Medium CVE-2024-1671: Inappropriate implementation in Site Isolation Medium CVE-2024-1672: Inappropriate implementation in Content Security Policy Medium CVE-2024-1673: Use after free in Accessibility Medium CVE-2024-1674: Inappropriate implementation in Navigation Medium CVE-2024-1675: Insufficient policy enforcement in Download Low CVE-2024-1676: Inappropriate implementation in Navigation -------------------------------------------------------------------------------- ChangeLog: * Wed Feb 21 2024 Than Ngo - 122.0.6261.57-1 - update to 122.0.6261.57 * High CVE-2024-1669: Out of bounds memory access in Blink * High CVE-2024-1670: Use after free in Mojo * Medium CVE-2024-1671: Inappropriate implementation in Site Isolation * Medium CVE-2024-1672: Inappropriate implementation in Content Security Policy * Medium CVE-2024-1673: Use after free in Accessibility * Medium CVE-2024-1674: Inappropriate implementation in Navigation * Medium CVE-2024-1675: Insufficient policy enforcement in Download * Low CVE-2024-1676: Inappropriate implementation in Navigation. * Sun Feb 18 2024 Than Ngo - 122.0.6261.39-1 - update to 122.0.6261.39 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-6a879cfa63' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Update to 118.0.5993.70. Include following security fixes: - CVE-2023-5218: Use after free in Site Isolation. - CVE-2023-5487: Inappropriate implementation in Fullscreen. - CVE-2023-5484: Inappropriate implementation in Navigation. - CVE-2023-5475: Inappropriate implementation in DevTools. - CVE-2023-5483: Inappropriate implementation in Intents. - CVE-2023-5481:. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2023-1c6a20aa0a 2023-10-14 01:26:08.208346 -------------------------------------------------------------------------------- Name : chromium Product : Fedora 37 Version : 118.0.5993.70 Release : 1.fc37 URL : https://www.chromium.org/Home/ Summary : A WebKit (Blink) powered web browser that Google doesn't want you to use Description : Chromium is an open-source web browser, powered by WebKit (Blink). -------------------------------------------------------------------------------- Update Information: Update to 118.0.5993.70. Include following security fixes: - CVE-2023-5218: Use after free in Site Isolation. - CVE-2023-5487: Inappropriate implementation in Fullscreen. - CVE-2023-5484: Inappropriate implementation in Navigation. - CVE-2023-5475: Inappropriate implementation in DevTools. - CVE-2023-5483: Inappropriate implementation in Intents. - CVE-2023-5481: Inappropriate implementation in Downloads. - CVE-2023-5476: Use after free in Blink History. - CVE-2023-5474: Heap buffer overflow in PDF. - CVE-2023-5479: Inappropriate implementation in Extensions API. - CVE-2023-5485: Inappropriate implementation in Autofill. - CVE-2023-5478: Inappropriate implementation in Autofill. - CVE-2023-5477: Inappropriate implementation in Installer. - CVE-2023-5486: Inappropriate implementation in Input. - CVE-2023-5473: Use after free inCast. -------------------------------------------------------------------------------- ChangeLog: * Wed Oct 11 2023 Than Ngo - 118.0.5993.70-1 - update to 118.0.5993.70 - CVE-2023-5218: Use after free in Site Isolation. - CVE-2023-5487: Inappropriate implementation in Fullscreen. - CVE-2023-5484: Inappropriate implementation in Navigation. - CVE-2023-5475: Inappropriate implementation in DevTools. - CVE-2023-5483: Inappropriate implementation in Intents. - CVE-2023-5481: Inappropriate implementation in Downloads. - CVE-2023-5476: Use after free in Blink History. - CVE-2023-5474: Heap buffer overflow in PDF. - CVE-2023-5479: Inappropriate implementation in Extensions API. - CVE-2023-5485: Inappropriate implementation in Autofill. - CVE-2023-5478: Inappropriate implementation in Autofill. - CVE-2023-5477: Inappropriate implementation in Installer. - CVE-2023-5486: Inappropriate implementation in Input. - CVE-2023-5473: Use after free in Cast. * Sat Oct 7 2023 Than Ngo - 118.0.5993.54-1 - update to 118.0.5993.54 - drop use_gnome_keyring as it's removed by upstream -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-1c6a20aa0a' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
An update that fixes three vulnerabilities is now available. . openSUSE Security Update: Security update for chromium ______________________________________________________________________________ Announcement ID: openSUSE-SU-2020:2016-1 Rating: important References: #1178630 #1178703 Cross-References: CVE-2020-16013 CVE-2020-16016 CVE-2020-16017 Affected Products: openSUSE Backports SLE-15-SP2 ______________________________________________________________________________ An update that fixes three vulnerabilities is now available. Description: This update for chromium fixes the following issues: Update to 86.0.4240.198 (boo#1178703) - CVE-2020-16013: Inappropriate implementation in V8 - CVE-2020-16017: Use after free in site isolation Update to 86.0.4240.193 (boo#1178630) - CVE-2020-16016: Inappropriate implementation in base. This update was imported from the openSUSE:Leap:15.2:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP2: zypper in -t patch openSUSE-2020-2016=1 Package List: - openSUSE Backports SLE-15-SP2 (aarch64 x86_64): chromedriver-86.0.4240.198-bp152.2.35.1 chromium-86.0.4240.198-bp152.2.35.1 References: https://www.suse.com/security/cve/CVE-2020-16013.html https://www.suse.com/security/cve/CVE-2020-16016.html https://www.suse.com/security/cve/CVE-2020-16017.html https://bugzilla.suse.com/1178630 https://bugzilla.suse.com/1178703 _______________________________________________ openSUSE Security Announce mailing list --
Update to 86.0.4240.198. Fixes the following security issues: CVE-2020-16013 CVE-2020-16016 CVE-2020-16017. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-2d0c0ee838 2020-11-20 01:38:40.112469 --------------------------------------------------------------------------------Name : chromium Product : Fedora 33 Version : 86.0.4240.198 Release : 1.fc33 URL : https://www.chromium.org/Home/ Summary : A WebKit (Blink) powered web browser Description : Chromium is an open-source web browser, powered by WebKit (Blink). --------------------------------------------------------------------------------Update Information: Update to 86.0.4240.198. Fixes the following security issues: CVE-2020-16013 CVE-2020-16016 CVE-2020-16017 --------------------------------------------------------------------------------ChangeLog: * Thu Nov 12 2020 Tom Callaway - 86.0.4240.198-1 - update to 86.0.4240.198 * Tue Nov 10 2020 Tom Callaway - 86.0.4240.193-1 - update to 86.0.4240.193 --------------------------------------------------------------------------------References: [ 1 ] Bug #1896641 - CVE-2020-16016 chromium-browser: Inappropriate implementation in base https://bugzilla.redhat.com/show_bug.cgi?id=1896641 [ 2 ] Bug #1897206 - CVE-2020-16013 chromium-browser: Inappropriate implementation in V8 https://bugzilla.redhat.com/show_bug.cgi?id=1897206 [ 3 ] Bug #1897207 - CVE-2020-16017 chromium-browser: Use after free in site isolation https://bugzilla.redhat.com/show_bug.cgi?id=1897207 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-2d0c0ee838' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora ProjectGPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.