Explore top 10 tips to secure your open-source projects now. Read More
×
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2025-7457 http://linux.oracle.com/errata/ELSA-2025-7457.html The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network: x86_64: exiv2-0.28.3-3.el10_0.2.x86_64.rpm exiv2-devel-0.28.3-3.el10_0.2.x86_64.rpm exiv2-doc-0.28.3-3.el10_0.2.noarch.rpm exiv2-libs-0.28.3-3.el10_0.2.x86_64.rpm aarch64: exiv2-0.28.3-3.el10_0.2.aarch64.rpm exiv2-devel-0.28.3-3.el10_0.2.aarch64.rpm exiv2-doc-0.28.3-3.el10_0.2.noarch.rpm exiv2-libs-0.28.3-3.el10_0.2.aarch64.rpm SRPMS: http://oss.oracle.com/ol10/SRPMS-updates/exiv2-0.28.3-3.el10_0.2.src.rpm Related CVEs: CVE-2025-26623 Description of changes: [0.28.3-3.2] - Revert: remove rpath patch Resolves: RHEL-80106 - Fix CVE-2025-26623 exiv2: Use After Free Resolves: RHEL-80106 _______________________________________________ El-errata mailing list
Integer overflow in V8. (CVE-2025-6191) Use after free in Profiler. (CVE-2025-6192) References: - https://bugs.mageia.org/show_bug.cgi?id=34386 . MGASA-2025-0196 - Updated chromium-browser-stable packages fix security vulnerabilities Publication date: 25 Jun 2025 URL: https://advisories.mageia.org/MGASA-2025-0196.html Type: security Affected Mageia releases: 9 CVE: CVE-2025-6191, CVE-2025-6192 Integer overflow in V8. (CVE-2025-6191) Use after free in Profiler. (CVE-2025-6192) References: - https://bugs.mageia.org/show_bug.cgi?id=34386 - https://chromereleases.googleblog.com/2025/06/stable-channel-update-for-desktop_17.html - https://www.cve.org/CVERecord?id=CVE-2025-6191 - https://www.cve.org/CVERecord?id=CVE-2025-6192 SRPMS: - 9/tainted/chromium-browser-stable-136.0.7103.113-3.mga9.tainted . Mageia 9 releases a chromium-browser upgrade addressing buffer overflow and memory management vulnerabilities, enhancing security and system stability.. Mageia security, chromium-browser update, integer overflow fix, mageia vulnerabilities. . Severity: Critical. LinuxSecurity.com Team
Update to 137.0.7151.119 * CVE-2025-6191: Integer overflow in V8 * CVE-2025-6192: Use after free in Profiler. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-b434717c22 2025-06-22 05:57:57.824627+00:00 -------------------------------------------------------------------------------- Name : chromium Product : Fedora 42 Version : 137.0.7151.119 Release : 1.fc42 URL : http://www.chromium.org/Home Summary : A WebKit (Blink) powered web browser that Google doesn't want you to use Description : Chromium is an open-source web browser, powered by WebKit (Blink). -------------------------------------------------------------------------------- Update Information: Update to 137.0.7151.119 * CVE-2025-6191: Integer overflow in V8 * CVE-2025-6192: Use after free in Profiler -------------------------------------------------------------------------------- ChangeLog: * Wed Jun 18 2025 Than Ngo - 137.0.7151.119-1 - Update to 137.0.7151.119 * CVE-2025-6191: Integer overflow in V8 * CVE-2025-6192: Use after free in Profiler -------------------------------------------------------------------------------- References: [ 1 ] Bug #2373778 - CVE-2025-6192 chromium: Chromium use after free [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2373778 [ 2 ] Bug #2373780 - CVE-2025-6191 chromium: Chromium integer overflow [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2373780 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-b434717c22' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project canbe found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Update to 137.0.7151.119 * CVE-2025-6191: Integer overflow in V8 * CVE-2025-6192: Use after free in Profiler. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-4fed640c91 2025-06-22 01:13:34.506440+00:00 -------------------------------------------------------------------------------- Name : chromium Product : Fedora 41 Version : 137.0.7151.119 Release : 1.fc41 URL : http://www.chromium.org/Home Summary : A WebKit (Blink) powered web browser that Google doesn't want you to use Description : Chromium is an open-source web browser, powered by WebKit (Blink). -------------------------------------------------------------------------------- Update Information: Update to 137.0.7151.119 * CVE-2025-6191: Integer overflow in V8 * CVE-2025-6192: Use after free in Profiler -------------------------------------------------------------------------------- ChangeLog: * Wed Jun 18 2025 Than Ngo - 137.0.7151.119-1 - Update to 137.0.7151.119 * CVE-2025-6191: Integer overflow in V8 * CVE-2025-6192: Use after free in Profiler -------------------------------------------------------------------------------- References: [ 1 ] Bug #2373778 - CVE-2025-6192 chromium: Chromium use after free [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2373778 [ 2 ] Bug #2373780 - CVE-2025-6191 chromium: Chromium integer overflow [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2373780 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-4fed640c91' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project canbe found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Update to 137.0.7151.103 CVE-2025-5958: Use after free in Media CVE-2025-5959: Type Confusion in V8. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-aa9ea529fb 2025-06-15 01:06:28.140427+00:00 -------------------------------------------------------------------------------- Name : chromium Product : Fedora 41 Version : 137.0.7151.103 Release : 1.fc41 URL : http://www.chromium.org/Home Summary : A WebKit (Blink) powered web browser that Google doesn't want you to use Description : Chromium is an open-source web browser, powered by WebKit (Blink). -------------------------------------------------------------------------------- Update Information: Update to 137.0.7151.103 CVE-2025-5958: Use after free in Media CVE-2025-5959: Type Confusion in V8 -------------------------------------------------------------------------------- ChangeLog: * Wed Jun 11 2025 Than Ngo - 137.0.7151.103-1 - Update to 137.0.7151.103 * CVE-2025-5958: Use after free in Media * CVE-2025-5959: Type Confusion in V8 - Provide correct version for bundle librarires - Fix rhbz#2368923, Chromium crash -------------------------------------------------------------------------------- References: [ 1 ] Bug #2368923 - Chromium crashes with "SIGILL" when using the "ENTITIES HTML MathML Set" doctype in an XSLT stylesheet https://bugzilla.redhat.com/show_bug.cgi?id=2368923 [ 2 ] Bug #2371648 - CVE-2025-5958 chromium: Chrome Media Use-After-Free Vulnerability [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2371648 [ 3 ] Bug #2371653 - CVE-2025-5959 chromium: Chrome Type Confusion Vulnerability [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2371653 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-aa9ea529fb' at thecommand line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Update to 137.0.7151.68 CVE-2025-5419: Out of bounds read and write in V8 CVE-2025-5068: Use after free in Blink. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-bc0d109630 2025-06-07 06:45:35.205082+00:00 -------------------------------------------------------------------------------- Name : chromium Product : Fedora 42 Version : 137.0.7151.68 Release : 1.fc42 URL : http://www.chromium.org/Home Summary : A WebKit (Blink) powered web browser that Google doesn't want you to use Description : Chromium is an open-source web browser, powered by WebKit (Blink). -------------------------------------------------------------------------------- Update Information: Update to 137.0.7151.68 CVE-2025-5419: Out of bounds read and write in V8 CVE-2025-5068: Use after free in Blink -------------------------------------------------------------------------------- ChangeLog: * Tue Jun 3 2025 Than Ngo - 137.0.7151.68-1 - Update to 137.0.7151.68 * CVE-2025-5419: Out of bounds read and write in V8 * CVE-2025-5068: Use after free in Blink -------------------------------------------------------------------------------- References: [ 1 ] Bug #2369919 - CVE-2025-5068 chromium: Chrome Use-After-Free Vulnerability [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2369919 [ 2 ] Bug #2369920 - CVE-2025-5068 chromium: Chrome Use-After-Free Vulnerability [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2369920 [ 3 ] Bug #2369921 - CVE-2025-5419 chromium: Chrome Heap Corruption Vulnerability [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2369921 [ 4 ] Bug #2369922 - CVE-2025-5419 chromium: Chrome Heap Corruption Vulnerability [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2369922 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program.Use su -c 'dnf upgrade --advisory FEDORA-2025-bc0d109630' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Update to 137.0.7151.68 CVE-2025-5419: Out of bounds read and write in V8 CVE-2025-5068: Use after free in Blink. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-be7ea2f22d 2025-06-07 05:42:23.006513+00:00 -------------------------------------------------------------------------------- Name : chromium Product : Fedora 41 Version : 137.0.7151.68 Release : 1.fc41 URL : http://www.chromium.org/Home Summary : A WebKit (Blink) powered web browser that Google doesn't want you to use Description : Chromium is an open-source web browser, powered by WebKit (Blink). -------------------------------------------------------------------------------- Update Information: Update to 137.0.7151.68 CVE-2025-5419: Out of bounds read and write in V8 CVE-2025-5068: Use after free in Blink -------------------------------------------------------------------------------- ChangeLog: * Tue Jun 3 2025 Than Ngo - 137.0.7151.68-1 - Update to 137.0.7151.68 * CVE-2025-5419: Out of bounds read and write in V8 * CVE-2025-5068: Use after free in Blink -------------------------------------------------------------------------------- References: [ 1 ] Bug #2369919 - CVE-2025-5068 chromium: Chrome Use-After-Free Vulnerability [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2369919 [ 2 ] Bug #2369920 - CVE-2025-5068 chromium: Chrome Use-After-Free Vulnerability [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2369920 [ 3 ] Bug #2369921 - CVE-2025-5419 chromium: Chrome Heap Corruption Vulnerability [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2369921 [ 4 ] Bug #2369922 - CVE-2025-5419 chromium: Chrome Heap Corruption Vulnerability [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2369922 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program.Use su -c 'dnf upgrade --advisory FEDORA-2025-be7ea2f22d' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
* bsc#1224044 Cross-References: * CVE-2024-34397 . # Security update for glib2 Announcement ID: SUSE-SU-2025:20031-1 Release Date: 2025-02-03T08:51:58Z Rating: low References: * bsc#1224044 Cross-References: * CVE-2024-34397 CVSS scores: * CVE-2024-34397 ( SUSE ): 3.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N * CVE-2024-34397 ( NVD ): 5.2 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L Affected Products: * SUSE Linux Micro 6.0 An update that solves one vulnerability can now be installed. ## Description: This update for glib2 fixes the following issues: * Fixed a possible use after free regression introduced by CVE-2024-34397 patch (bsc#1224044). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-27=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * libglib-2_0-0-2.76.2-5.1 * glib2-tools-2.76.2-5.1 * libgio-2_0-0-debuginfo-2.76.2-5.1 * libgobject-2_0-0-debuginfo-2.76.2-5.1 * libgmodule-2_0-0-2.76.2-5.1 * libglib-2_0-0-debuginfo-2.76.2-5.1 * glib2-debugsource-2.76.2-5.1 * libgio-2_0-0-2.76.2-5.1 * libgobject-2_0-0-2.76.2-5.1 * glib2-tools-debuginfo-2.76.2-5.1 * libgmodule-2_0-0-debuginfo-2.76.2-5.1 ## References: * https://www.suse.com/security/cve/CVE-2024-34397.html * https://bugzilla.suse.com/show_bug.cgi?id=1224044 . Update to glib2 resolves a low severity issue in SUSE Linux Micro 6.0. Prompt installation recommended via zypper.. SUSE Linux Micro, glib2 update, low severity patch, security advisory. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.