| Summary: | Updated chromium 125.0.6422.76 packages fix vulnerabilities CVE-2024-49[57/58/59/60] | ||
|---|---|---|---|
| Product: | Mageia | Reporter: | christian barranco <chb0> |
| Component: | Security | Assignee: | QA Team <qa-bugs> |
| Status: | RESOLVED FIXED | QA Contact: | Sec team <security> |
| Severity: | normal | ||
| Priority: | Normal | CC: | andrewsfarm, brtians1, fri, herman.viaene, sysadmin-bugs |
| Version: | 9 | Keywords: | advisory, validated_update |
| Target Milestone: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | MGA9-64-OK | ||
| Source RPM: | chromium-browser-stable-125.0.6422.60-1.1.mga9.tainted.src.rpm | CVE: | CVE-2024-5157,CVE-2024-5158,CVE-2024-5159,CVE-2024-5160 |
| Status comment: | |||
| Bug Depends on: | |||
| Bug Blocks: | 33240 | ||
|
Description
christian barranco
2024-05-21 21:52:29 CEST
christian barranco
2024-05-21 21:54:29 CEST
CC:
(none) =>
andrewsfarm, brtians1, fri ETA on arriving in tainted updates testing? Chromium usually take almost 24h... You know you can check on http://pkgsubmit.mageia.org/ ? Right now it is green=finished, submitted 22 h ago, build time 20 h. So about now it should be on mirrors. It is in my favourite mirror https://ftp.acc.umu.se/mirror/mageia/distrib/9/x86_64/media/tainted/updates_testing/ MGA9-64, Cinnamon, i7 M620, nvidia GT218M (Nouveau), laptop The following 3 packages are going to be installed: - chromium-browser-125.0.6422.76-1.mga9.tainted.x86_64 - chromium-browser-stable-125.0.6422.76-1.mga9.tainted.x86_64 - google-roboto-fonts-1.2-4.mga9.noarch 748KB of disk space will be freed. --- used for awhile no issues RH mageia 9 x86_64 Plasma Wayland Update without issues Set Ozone plataform to wayland: Youtube OK Facebook OK Mageia sites OK Use to post this comment Keywords:
(none) =>
advisory
katnatek
2024-05-23 23:18:40 CEST
CVE:
(none) =>
CVE-2024-5157,CVE-2024-5158,CVE-2024-5159,CVE-2024-5160 MGA9-64, Xfce, Intel celeron The following 3 packages are going to be installed: - chromium-browser-125.0.6422.76-1.mga9.tainted.x86_64 - chromium-browser-stable-125.0.6422.76-1.mga9.tainted.x86_64 - google-roboto-fonts-1.2-4.mga9.noarch 48MB of additional disk space will be used. email sites work google-roboto-fonts-1.2-4.mga9.noarch not found in the remote repository And it is not listed in Morgan's favorite mirror either. CC:
(none) =>
herman.viaene (In reply to Herman Viaene from comment #7) > google-roboto-fonts-1.2-4.mga9.noarch not found in the remote repository > And it is not listed in Morgan's favorite mirror either. Must be a new dependency. It's in the main repos, to be drawn in when you update the other two packages. Right, but it is confusing that is listed in Comments 4 and 6 seemingly as update packages My bad. I have forgotten to post the advisory and you will not find the roboto package in it. I’ll do it tonight. ADVISORY NOTICE PROPOSAL ======================== New chromium-browser-stable 125.0.6422.76 security update Description The chromium-browser-stable package has been updated to the 125.0.6422.76 release. It includes 6 security fixes. Please, do note, only x86_64 is supported from now on. i586 support for linux was stopped some years ago and the community is not able to provide patches anymore for the latest Chromium code. Some of the security fixes are: * High CVE-2024-5157: Use after free in Scheduling. Reported by Looben Yang on 2024-04-21 * High CVE-2024-5158: Type Confusion in V8. Reported by Zhenghang Xiao (@Kipreyyy) on 2024-05-06 * High CVE-2024-5159: Heap buffer overflow in ANGLE. Reported by David Sievers (@loknop) on 2024-04-18 * High CVE-2024-5160: Heap buffer overflow in Dawn. Reported by wgslfuzz on 2024-05-01 References https://bugs.mageia.org/show_bug.cgi?id=33231 https://chromereleases.googleblog.com/2024/05/stable-channel-update-for-desktop_21.html SRPMS 9/tainted chromium-browser-stable-125.0.6422.76-1.mga9.tainted.src.rpm PROVIDED PACKAGES ================= x86_64 chromium-browser-125.0.6422.76-1.mga9.tainted.x86_64.rpm chromium-browser-stable-125.0.6422.76-1.mga9.tainted.x86_64.rpm
christian barranco
2024-05-24 21:17:40 CEST
Blocks:
(none) =>
33240 MGA9-64, Plasma, Nvidia 1050 (550) usual install of 3 -- Chromium working as expected in video and audio as well as some pages. Whiteboard:
(none) =>
MGA9-64-OK OK mga9-64 Plasma X11, nvidia470 Clean update, open tabs and settings preserved, Swedish localisation Used a few banking and shop sites and a few video sites file saving, pdf printing Also OK on Thinkpad T510 using nouveau graphic driver, same terminal warnings as https://bugs.mageia.org/show_bug.cgi?id=33227#c10 Keywords:
(none) =>
validated_update An update for this issue has been pushed to the Mageia Updates repository. https://advisories.mageia.org/MGASA-2024-0194.html Status:
NEW =>
RESOLVED |