ArchLinux: 202109-6: chromium: arbitrary code execution
Summary
- CVE-2021-30625 (arbitrary code execution)
A use after free security issue has been found in the Selection API
component of the Chromium browser engine before version 93.0.4577.82.
- CVE-2021-30626 (arbitrary code execution)
An out of bounds memory access security issue has been found in the
ANGLE component of the Chromium browser engine before version
93.0.4577.82.
- CVE-2021-30627 (arbitrary code execution)
A type confusion security issue has been found in the Blink layout
component of the Chromium browser engine before version 93.0.4577.82.
- CVE-2021-30628 (arbitrary code execution)
A stack buffer overflow security issue has been found in the ANGLE
component of the Chromium browser engine before version 93.0.4577.82.
- CVE-2021-30629 (arbitrary code execution)
A use after free security issue has been found in the Permissions
component of the Chromium browser engine before version 93.0.4577.82.
- CVE-2021-30630 (arbitrary code execution)
An inappropriate implementation security issue has been found in the
Blink component of the Chromium browser engine before version
93.0.4577.82.
- CVE-2021-30631 (arbitrary code execution)
A type confusion security issue has been found in the Blink layout
component of the Chromium browser engine before version 93.0.4577.82.
- CVE-2021-30632 (arbitrary code execution)
An out of bounds write security issue has been found in the V8
component of the Chromium browser engine before version 93.0.4577.82.
Google is aware that exploits for this issue exist in the wild.
- CVE-2021-30633 (arbitrary code execution)
A use after free security issue has been found in the Indexed DB API
component of the Chromium browser engine before version 93.0.4577.82.
Google is aware that exploits for this issue exist in the wild.
Resolution
Upgrade to 93.0.4577.82-1.
# pacman -Syu "chromium>=93.0.4577.82-1"
The problems have been fixed upstream in version 93.0.4577.82.
References
https://chromereleases.googleblog.com/2021/09/stable-channel-update-for-desktop.html https://security.archlinux.org/CVE-2021-30625 https://security.archlinux.org/CVE-2021-30626 https://security.archlinux.org/CVE-2021-30627 https://security.archlinux.org/CVE-2021-30628 https://security.archlinux.org/CVE-2021-30629 https://security.archlinux.org/CVE-2021-30630 https://security.archlinux.org/CVE-2021-30631 https://security.archlinux.org/CVE-2021-30632 https://security.archlinux.org/CVE-2021-30633
Workaround
None.