Bug 28180 - chromium-browser-stable new security issues fixed in 88.0.4324.150
Summary: chromium-browser-stable new security issues fixed in 88.0.4324.150
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 7
Hardware: All Linux
Priority: Normal critical
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA7-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2021-01-21 09:17 CET by Nicolas Salguero
Modified: 2021-02-15 20:25 CET (History)
6 users (show)

See Also:
Source RPM: chromium-browser-stable-87.0.4280.141-2.mga8.src.rpm
CVE:
Status comment:


Attachments

Description Nicolas Salguero 2021-01-21 09:17:31 CET
Upstream has released version 88.0.4324.96 on January 19:
https://chromereleases.googleblog.com/2021/01/stable-channel-update-for-desktop_19.html

This is the current version in the stable channel:
http://googlechromereleases.blogspot.com/search/label/Stable%20updates

It fixes several new security issues.
Nicolas Salguero 2021-01-21 09:19:14 CET

Whiteboard: (none) => MGA7TOO
Source RPM: (none) => chromium-browser-stable-87.0.4280.141-2.mga8.src.rpm

Comment 1 Lewis Smith 2021-01-21 20:10:01 CET
This looks to be for cjw - despite the fact that you have only just updated this!

Assignee: bugsquad => cjw

Comment 2 Nicolas Lécureuil 2021-01-31 11:18:58 CET
available on cauldron.

Whiteboard: MGA7TOO => (none)
Version: Cauldron => 7
CC: (none) => mageia

Comment 3 Nicolas Salguero 2021-02-03 09:12:53 CET
Upstream has released version 88.0.4324.146 on February 2:
https://chromereleases.googleblog.com/2021/02/stable-channel-update-for-desktop.html

This is the current version in the stable channel:
http://googlechromereleases.blogspot.com/search/label/Stable%20updates

It fixes several new security issues.

Summary: chromium-browser-stable new security issues fixed in 88.0.4324.96 => chromium-browser-stable new security issues fixed in 88.0.4324.146
Whiteboard: (none) => MGA7TOO
Version: 7 => Cauldron

Comment 4 Nicolas Lécureuil 2021-02-04 21:08:06 CET
new released moved to release -> Cauldron

Whiteboard: MGA7TOO => (none)
Version: Cauldron => 7

Comment 5 Nicolas Salguero 2021-02-05 08:52:21 CET
Upstream has released version 88.0.4324.150 on February 4:
https://chromereleases.googleblog.com/2021/02/stable-channel-update-for-desktop_4.html

This is the current version in the stable channel:
http://googlechromereleases.blogspot.com/search/label/Stable%20updates

It fixes a security issue in V8 engine that is actively exploited.

Version: 7 => Cauldron
Whiteboard: (none) => MGA7TOO
Summary: chromium-browser-stable new security issues fixed in 88.0.4324.146 => chromium-browser-stable new security issues fixed in 88.0.4324.150

Comment 6 Nicolas Lécureuil 2021-02-09 16:50:32 CET
Moved in cauldron.

Whiteboard: MGA7TOO => (none)
Version: Cauldron => 7

Comment 7 Nicolas Salguero 2021-02-09 17:30:35 CET
Suggested advisory:
========================

The updated packages fix security vulnerabilities. One of those problems is a security issue in V8 engine that is actively exploited.

References:
https://chromereleases.googleblog.com/2021/01/stable-channel-update-for-desktop_19.html
https://chromereleases.googleblog.com/2021/02/stable-channel-update-for-desktop.html
https://chromereleases.googleblog.com/2021/02/stable-channel-update-for-desktop_4.html
========================

Updated packages in core/updates_testing:
========================
chromium-browser-stable-88.0.4324.150-1.mga7
chromium-browser-88.0.4324.150-1.mga7

from SRPM:
chromium-browser-stable-88.0.4324.150-1.mga7.src.rpm

Assignee: cjw => qa-bugs
CC: (none) => nicolas.salguero
Status: NEW => ASSIGNED

Comment 8 Len Lawrence 2021-02-10 16:40:29 CET
mga7, x64

Updated the browser packages.  General browsing is fine.  Youtube videos.  Wikipedia.  Created QR code for this page, which I could not test (no smartphone).
General search facility working.  Found APOD easily enough.Looks fine here.

CC: (none) => tarazed25

Comment 9 PC LX 2021-02-11 23:34:07 CET
Installed and tested without issues.

Tested on a variety of sites. Tested video, audio, WebGL, benchmarks, plain HTML, JS heavy sites, etc.
No issues noticed.


System: Mageia 7, x86_64, Plasma DE, LXQt DE, Intel CPU, nVidia GPU GT 1030 using nvidia-current proprietary driver.


$ uname -a
Linux marte 5.10.14-desktop-1.mga7 #1 SMP Sun Feb 7 19:36:25 UTC 2021 x86_64 x86_64 x86_64 GNU/Linux
$ rpm -q chromium-browser-stable
chromium-browser-stable-88.0.4324.150-1.mga7

CC: (none) => mageia

Comment 10 Aurelien Oudelet 2021-02-13 15:23:57 CET
M7 Plasma x86_64

Basic usage is OK
SSL Bank website OK
DRM-widevine streaming website OK
No webcam to test.

No issue found.

Validating.
Advisory commited to SVN.

Keywords: (none) => advisory, validated_update
Whiteboard: (none) => MGA7-64-OK
CC: (none) => ouaurelien, sysadmin-bugs

Comment 11 Mageia Robot 2021-02-15 20:25:49 CET
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2021-0083.html

Resolution: (none) => FIXED
Status: ASSIGNED => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.