Bug 32156

Summary: chromium-browser-stable new security issues fixed in 116.0.5845.96
Product: Mageia Reporter: David Walser <luigiwalser>
Component: SecurityAssignee: QA Team <qa-bugs>
Status: RESOLVED FIXED QA Contact: Sec team <security>
Severity: critical    
Priority: Normal CC: chb0, fri
Version: Cauldron   
Target Milestone: ---   
Hardware: All   
OS: Linux   
Whiteboard: MGA9-64-OK
Source RPM: chromium-browser-stable-115.0.5790.110-1.mga9 CVE:
Status comment:

Description David Walser 2023-08-04 17:01:58 CEST
Upstream has released version 115.0.5790.98 on July 18:
https://chromereleases.googleblog.com/2023/07/stable-channel-update-for-desktop.html

Upstream has released version 115.0.5790.170 on August 2:
https://chromereleases.googleblog.com/2023/08/stable-channel-update-for-desktop.html

There were two bugfix updates in between (115.0.5790.102 and 115.0.5790.110):
https://chromereleases.googleblog.com/2023/07/stable-channel-update-for-desktop_20.html

This is the current version in the stable channel:
http://googlechromereleases.blogspot.com/search/label/Stable%20updates

It fixes several new security issues.
Comment 1 Lewis Smith 2023-08-05 21:17:40 CEST
chromium-browser-stable is keeping you busy, Christian. Here is yet another update.

Assignee: bugsquad => chb0

Comment 2 christian barranco 2023-08-06 00:58:47 CEST
Hi. Saw that lately but on vacation. I will not be able to push it before 16th of August. Usually, update within the same branch should be smooth, in case someone would like just to update the version number and submit it.
Comment 3 christian barranco 2023-08-15 21:24:17 CEST
Hi. I propose to go directly to 116.0.5845.96:
https://chromereleases.googleblog.com/2023/08/stable-channel-update-for-desktop_15.html

Summary: chromium-browser-stable new security issues fixed in 115.0.5790.170 => chromium-browser-stable new security issues fixed in 116.0.5845.96

Comment 4 christian barranco 2023-08-16 10:02:26 CEST
Ready for QA!

ADVISORY NOTICE PROPOSAL
========================

New chromium-browser-stable 116.0.5845.96 fixes bugs and vulnerabilities


Description
The chromium-browser-stable package has been updated to the 116.0.5845.96 release, fixing 26 vulnerabilities.

Some of the security fixes are:

High CVE-2023-2312: Use after free in Offline. Reported by avaue at S.S.L. on 2023-05-24

High CVE-2023-4349: Use after free in Device Trust Connectors. Reported by Weipeng Jiang (@Krace) of VRI on 2023-06-27

High CVE-2023-4350: Inappropriate implementation in Fullscreen. Reported by Khiem Tran (@duckhiem) on 2023-06-14

High CVE-2023-4351: Use after free in Network. Reported by Guang and Weipeng Jiang of VRI on 2023-07-18

High CVE-2023-4352: Type Confusion in V8. Reported by Sergei Glazunov of Google Project Zero on 2023-06-07

High CVE-2023-4353: Heap buffer overflow in ANGLE. Reported by Christoph Diehl / Microsoft Vulnerability Research on 2023-06-27

High CVE-2023-4354: Heap buffer overflow in Skia. Reported by Mark Brand of Google Project Zero on 2023-07-12

High CVE-2023-4355: Out of bounds memory access in V8. Reported by Sergei Glazunov of Google Project Zero on 2023-07-31

Medium CVE-2023-4356: Use after free in Audio. Reported by Zhenghang Xiao (@Kipreyyy) on 2023-05-30

Medium CVE-2023-4357: Insufficient validation of untrusted input in XML. Reported by Igor Sak-Sakovskii on 2023-06-28

Medium CVE-2023-4358: Use after free in DNS. Reported by Weipeng Jiang (@Krace) of VRI on 2023-07-20

Medium CVE-2023-4359: Inappropriate implementation in App Launcher. Reported by @retsew0x01 on 2023-05-09

Medium CVE-2023-4360: Inappropriate implementation in Color. Reported by Axel Chong on 2023-07-07

[$2000][1465230] Medium CVE-2023-4361: Inappropriate implementation in Autofill. Reported by Thomas Orlita on 2023-07-17

Medium CVE-2023-4362: Heap buffer overflow in Mojom IDL. Reported by Zhao Hai of NanJing Cyberpeace TianYu Lab on 2022-04-14

Medium CVE-2023-4363: Inappropriate implementation in WebShare. Reported by Alesandro Ortiz on 2022-09-23

Medium CVE-2023-4364: Inappropriate implementation in Permission Prompts. Reported by Jasper Rebane on 2023-01-13

Medium CVE-2023-4365: Inappropriate implementation in Fullscreen. Reported by Hafiizh on 2023-04-06

Medium CVE-2023-4366: Use after free in Extensions. Reported by asnine on 2023-06-02

Medium CVE-2023-4367: Insufficient policy enforcement in Extensions API. Reported by Axel Chong on 2023-07-26

Medium CVE-2023-4368: Insufficient policy enforcement in Extensions API. Reported by Axel Chong on 2023-07-26

References
https://bugs.mageia.org/show_bug.cgi?id=32156
https://chromereleases.googleblog.com/2023/08/stable-channel-update-for-desktop_15.html



SRPMS
9/tainted
chromium-browser-stable-116.0.5845.96-1.mga9.tainted.src.rpm


PROVIDED PACKAGES
=================
x86_64
chromium-browser-116.0.5845.96-1.mga9.tainted.x86_64.rpm
chromium-browser-stable-116.0.5845.96-1.mga9.tainted.x86_64.rpm

i586
chromium-browser-116.0.5845.96-1.mga9.tainted.i586.rpm
chromium-browser-stable-116.0.5845.96-1.mga9.tainted.i586.rpm

Assignee: chb0 => qa-bugs

Morgan Leijström 2023-08-16 10:46:36 CEST

Whiteboard: (none) => MGA9-OK
CC: (none) => fri

Comment 5 Morgan Leijström 2023-08-16 10:52:46 CEST
(oops...)

Test OK mga9-64 
nvidia-current, on GTX750
Kernel from backport, as 6.4 have issues resuming on my system
Plasma

Tested some video sites and banking sites: no issues noted.



Below, output in terminal from where i started it:

  Some usual lines if type:

libpng warning: iCCP: known incorrect sRGB profile

  These are new to me I think:

[1539447:1539447:0816/101528.510001:ERROR:chrome_browser_cloud_management_controller.cc(163)] Cloud management controller initialization aborted as CBCM is not enabled.

[1539487:1539487:0816/104015.913019:ERROR:shared_image_manager.cc(217)] SharedImageManager::ProduceSkia: Trying to Produce a Skia representation from a non-existent mailbox.

Whiteboard: MGA9-OK => MGA9-64-OK

Comment 6 David Walser 2023-08-16 23:45:29 CEST
The advisory is missing the references from Comment 0.
Comment 7 christian barranco 2023-08-17 06:50:05 CEST
(In reply to David Walser from comment #6)
> The advisory is missing the references from Comment 0.

IMHO, only 
https://chromereleases.googleblog.com/2023/08/stable-channel-update-for-desktop.html
would be relevant as info, as 115.0.5790.110 is the current version and 115.0.5790.170 has fixed some CVE.

CC: (none) => chb0

Comment 8 christian barranco 2023-08-17 06:52:28 CEST
(In reply to Morgan Leijström from comment #5)
> 
>   These are new to me I think:
> 
> [1539447:1539447:0816/101528.510001:ERROR:
> chrome_browser_cloud_management_controller.cc(163)] Cloud management
> controller initialization aborted as CBCM is not enabled.
> 
> [1539487:1539487:0816/104015.913019:ERROR:shared_image_manager.cc(217)]
> SharedImageManager::ProduceSkia: Trying to Produce a Skia representation
> from a non-existent mailbox.

I will have a deeper look but I am not concerned by these as no crash is reported. Chromium is known as "polluting" quite a lot the terminal window with such messages.
Comment 9 Thomas Backlund 2023-08-19 19:54:15 CEST
moved to release for final release tree updates

Resolution: (none) => FIXED
Status: NEW => RESOLVED