An update that fixes 5 vulnerabilities is now available.. openSUSE Security Update: Security update for chromium ______________________________________________________________________________ Announcement ID: openSUSE-SU-2025:0475-1 Rating: important References: #1254776 #1255115 Cross-References: CVE-2025-14174 CVE-2025-14372 CVE-2025-14373 CVE-2025-14765 CVE-2025-14766 Affected Products: openSUSE Backports SLE-15-SP6 ______________________________________________________________________________ An update that fixes 5 vulnerabilities is now available. Description: This update for chromium fixes the following issues: - Chromium 143.0.7499.146 (boo#1255115): * CVE-2025-14765: Use after free in WebGPU * CVE-2025-14766: Out of bounds read and write in V8 - Chromium 143.0.7499.109 (boo#1254776): * CVE-2025-14372: Use after free in Password Manager * CVE-2025-14373: Inappropriate implementation in Toolbar * CVE-2025-14174: Out of bounds memory access in ANGLE Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP6: zypper in -t patch openSUSE-2025-475=1 Package List: - openSUSE Backports SLE-15-SP6 (aarch64 ppc64le x86_64): chromedriver-143.0.7499.146-bp156.2.209.1 chromium-143.0.7499.146-bp156.2.209.1 References: https://www.suse.com/security/cve/CVE-2025-14174.html https://www.suse.com/security/cve/CVE-2025-14372.html https://www.suse.com/security/cve/CVE-2025-14373.html https://www.suse.com/security/cve/CVE-2025-14765.html https://www.suse.com/security/cve/CVE-2025-14766.html https://bugzilla.suse.com/1254776 https://bugzilla.suse.com/1255115 . Update for openSUSE addresses multiple critical vulnerabilities in Chromium, enhancing its security andperformance.. openSUSE, chromium, security update, vulnerabilities, memory access. . Severity: Important. LinuxSecurity.com Team
HTML document may be able to render iframes with sensitive user information (CVE-2022-0108) maliciously crafted web content may lead to arbitrary code execution. (CVE-2022-32885) use-after-free vulnerability exists in WebCore::RenderLayer. This issue . MGASA-2023-0177 - Updated webkit2 packages fix security vulnerability Publication date: 21 May 2023 URL: https://advisories.mageia.org/MGASA-2023-0177.html Type: security Affected Mageia releases: 8 CVE: CVE-2022-0108, CVE-2022-32885, CVE-2023-25358, CVE-2023-27932, CVE-2023-27954, CVE-2023-28205 HTML document may be able to render iframes with sensitive user information (CVE-2022-0108) maliciously crafted web content may lead to arbitrary code execution. (CVE-2022-32885) use-after-free vulnerability exists in WebCore::RenderLayer. This issue allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site. (CVE-2023-25358) maliciously crafted web content may bypass Same Origin Policy (CVE-2023-27932) Website may be able to track sensitive user information. Description: The issue was addressed by removing origin information. (CVE-2023-27954) maliciously crafted web content may lead to arbitrary code execution (CVE-2023-28205) References: - https://bugs.mageia.org/show_bug.cgi?id=31854 - https://webkitgtk.org/security/WSA-2023-0003.html - https://webkitgtk.org/2023/04/20/webkitgtk2.38.6-released.html - https://www.cve.org/CVERecord?id=CVE-2022-0108 - https://www.cve.org/CVERecord?id=CVE-2022-32885 - https://www.cve.org/CVERecord?id=CVE-2023-25358 - https://www.cve.org/CVERecord?id=CVE-2023-27932 - https://www.cve.org/CVERecord?id=CVE-2023-27954 - https://www.cve.org/CVERecord?id=CVE-2023-28205 SRPMS: - 8/core/webkit2-2.38.6-1.mga8 . Recent updates to webkit2 packages for Mageia bolster security by fixing critical vulnerabilities and promoting user protection.. Mageia Security Updates, Webkit2 Vulnerabilities, Code Execution Risks, Information Exposure. .LinuxSecurity.com Team
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2023-0016 https://linux.oracle.com/errata/ELSA-2023-0016.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: webkit2gtk3-2.36.7-1.el8_7.1.i686.rpm webkit2gtk3-2.36.7-1.el8_7.1.x86_64.rpm webkit2gtk3-devel-2.36.7-1.el8_7.1.i686.rpm webkit2gtk3-devel-2.36.7-1.el8_7.1.x86_64.rpm webkit2gtk3-jsc-2.36.7-1.el8_7.1.i686.rpm webkit2gtk3-jsc-2.36.7-1.el8_7.1.x86_64.rpm webkit2gtk3-jsc-devel-2.36.7-1.el8_7.1.i686.rpm webkit2gtk3-jsc-devel-2.36.7-1.el8_7.1.x86_64.rpm aarch64: webkit2gtk3-2.36.7-1.el8_7.1.aarch64.rpm webkit2gtk3-devel-2.36.7-1.el8_7.1.aarch64.rpm webkit2gtk3-jsc-2.36.7-1.el8_7.1.aarch64.rpm webkit2gtk3-jsc-devel-2.36.7-1.el8_7.1.aarch64.rpm SRPMS: https://oss.oracle.com:443/ol8/SRPMS-updates/webkit2gtk3-2.36.7-1.el8_7.1.src.rpm Related CVEs: CVE-2022-42856 Description of changes: [2.36.7-1.1] - Add patch for CVE-2022-42856 Resolves: #2153735 _______________________________________________ El-errata mailing list
Update to 87.0.4280.88. As with pretty much every chromium release ever, this fixes some security bugs. This batch is: CVE-2020-16037 CVE-2020-16038 CVE-2020-16039 CVE-2020-16040 CVE-2020-16041 CVE-2020-16042. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-f43efd09e8 2020-12-10 01:13:07.369048 --------------------------------------------------------------------------------Name : chromium Product : Fedora 33 Version : 87.0.4280.88 Release : 1.fc33 URL : https://www.chromium.org/Home/ Summary : A WebKit (Blink) powered web browser Description : Chromium is an open-source web browser, powered by WebKit (Blink). --------------------------------------------------------------------------------Update Information: Update to 87.0.4280.88. As with pretty much every chromium release ever, this fixes some security bugs. This batch is: CVE-2020-16037 CVE-2020-16038 CVE-2020-16039 CVE-2020-16040 CVE-2020-16041 CVE-2020-16042 --------------------------------------------------------------------------------ChangeLog: * Thu Dec 3 2020 Tom Callaway - 87.0.4280.88-1 - update to 87.0.4280.88 --------------------------------------------------------------------------------References: [ 1 ] Bug #1904510 - CVE-2020-16037 chromium-browser: Use after free in clipboard https://bugzilla.redhat.com/show_bug.cgi?id=1904510 [ 2 ] Bug #1904511 - CVE-2020-16038 chromium-browser: Use after free in media https://bugzilla.redhat.com/show_bug.cgi?id=1904511 [ 3 ] Bug #1904512 - CVE-2020-16039 chromium-browser: Use after free in extensions https://bugzilla.redhat.com/show_bug.cgi?id=1904512 [ 4 ] Bug #1904513 - CVE-2020-16040 chromium-browser: Insufficient data validation in V8 https://bugzilla.redhat.com/show_bug.cgi?id=1904513 [ 5 ] Bug #1904514 - CVE-2020-16041 chromium-browser: Out of bounds read in networking https://bugzilla.redhat.com/show_bug.cgi?id=1904514 [ 6 ] Bug #1904515 - CVE-2020-16042 chromium-browser: Uninitialized Use in V8 https://bugzilla.redhat.com/show_bug.cgi?id=1904515 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-f43efd09e8' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Joxean Koret discovered several security problems in tutos, a web-based team organization software. The Common Vulnerabilities and Exposures Project identifies the following problems.... - --------------------------------------------------------------------------Debian Security Advisory DSA 980-1
Get the latest Linux and open source security news straight to your inbox.