Important Mageia Advisory for Chromium: 21 Security Fixes Explained
Summary
The chromium-browser-stable package has been updated to the 126.0.6478.61 release. It includes 21 security fixes. Some of them are: * High CVE-2024-5830: Type Confusion in V8. Reported by Man Yue Mo of GitHub Security Lab on 2024-05-24 * High CVE-2024-5831: Use after free in Dawn. Reported by wgslfuzz on 2024-05-07 * High CVE-2024-5832: Use after free in Dawn. Reported by wgslfuzz on 2024-05-13 * High CVE-2024-5833: Type Confusion in V8. Reported by @ginggilBesel on 2024-05-24 * High CVE-2024-5834: Inappropriate implementation in Dawn. Reported by gelatin dessert on 2024-05-26 * High CVE-2024-5835: Heap buffer overflow in Tab Groups. Reported by Weipeng Jiang (@Krace) of VRI on 2024-05-22 * High CVE-2024-5836: Inappropriate Implementation in DevTools. Reported by Allen Ding on 2024-05-21 * High CVE-2024-5837: Type Confusion in V8. Reported by Anonymous on 2024-05-23 * High CVE-2024-5838: Type Confusion in V8. Reported by Zhenghang Xiao (@Kipreyyy) on 2024-05-24 * Medium CVE-2024-583...
References
- https://bugs.mageia.org/show_bug.cgi?id=33308
- https://chromereleases.googleblog.com/2024/06/stable-channel-update-for-desktop_13.html
- https://chromereleases.googleblog.com/2024/06/stable-channel-update-for-desktop.html
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-5830
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-5831
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-5832
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-5833
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-5834
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-5835
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-5836
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-5837
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-5838
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-5839
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-5840
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-5841
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-5842
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-5843
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-5844
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-5845
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-5846
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-5847
Resolution
MGASA-2024-0230 - Updated chromium-browser-stable packages fix security vulnerabilities
SRPMS
- 9/tainted/chromium-browser-stable-126.0.6478.61-1.mga9.tainted