Bug 29522 - chromium-browser-stable new security issues fixed in 94.0.4606.71
Summary: chromium-browser-stable new security issues fixed in 94.0.4606.71
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 8
Hardware: All Linux
Priority: Normal critical
Target Milestone: ---
Assignee: Nicolas Salguero
QA Contact: Sec team
URL:
Whiteboard:
Keywords:
Depends on: 29541
Blocks:
  Show dependency treegraph
 
Reported: 2021-10-04 09:52 CEST by Nicolas Salguero
Modified: 2021-11-20 20:44 CET (History)
5 users (show)

See Also:
Source RPM: chromium-browser-stable-94.0.4606.61-1.mga8.src.rpm
CVE:
Status comment:


Attachments

Description Nicolas Salguero 2021-10-04 09:52:01 CEST
Upstream has released version 94.0.4606.71 on September 30:
https://chromereleases.googleblog.com/2021/09/stable-channel-update-for-desktop_30.html

It fixes four new security issues.  Two of them are being exploited in the wild.

This is the current version in the stable channel:
http://googlechromereleases.blogspot.com/search/label/Stable%20updates
Nicolas Salguero 2021-10-04 09:52:52 CEST

Source RPM: (none) => chromium-browser-stable-94.0.4606.61-1.mga8.src.rpm
CC: (none) => nicolas.salguero
Whiteboard: (none) => MGA8TOO

Comment 1 Nicolas Salguero 2021-10-05 09:20:34 CEST
Suggested advisory:
========================

Updated chromium-browser-stable packages fix security vulnerabilities.

The chromium-browser-stable package has been updated to 94.0.4606.71
version that fixes multiples security vulnerabilities.

References:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-37974
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-37975
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-37976
https://chromereleases.googleblog.com/2021/09/stable-channel-update-for-desktop_30.html
========================

Updated packages in core/updates_testing:
========================
chromium-browser-94.0.4606.71-1.mga8
chromium-browser-stable-94.0.4606.71-1.mga8

from SRPM:
chromium-browser-stable-94.0.4606.71-1.mga8.src.rpm

Status: NEW => ASSIGNED
Whiteboard: MGA8TOO => (none)
Assignee: bugsquad => qa-bugs
Version: Cauldron => 8

Comment 2 Jose Manuel López 2021-10-05 09:54:29 CEST
Hi,

I have update today. Install addons ok, login gmail ok, banks sites ok, youtube ok.

No problems for the moment

Greetings!!

CC: (none) => joselpddj

Comment 3 Hugues Detavernier 2021-10-05 15:54:22 CEST
Hi,

tested with youtube, google news and differents sites.

All is ok.

CC: (none) => hdetavernier

Comment 4 Herman Viaene 2021-10-05 16:06:09 CEST
MGA8-64 Plasma on Lenovo B50
No installation issues.
Did well on my usual newspaper site an the nice video's of Animusic on Youtube. Plus a few others.All seems OK.

CC: (none) => herman.viaene

Comment 5 katnatek 2021-10-05 17:34:12 CEST
Still Crash when dismiss the banner askinh to set as default browser

[7888:7888:1005/102712.915146:ERROR:gpu_init.cc(453)] Passthrough is not supported, GL is swiftshader, ANGLE is 
[1005/102739.004701:ERROR:elf_dynamic_array_reader.h(61)] tag not found
[1005/102739.005046:ERROR:elf_dynamic_array_reader.h(61)] tag not found
Received signal 11 SEGV_MAPERR 00000001597d
#0 0x0000061e263c base::debug::CollectStackTrace()
#1 0x0000061211df base::debug::StackTrace::StackTrace()
#2 0x0000061e2bb2 base::debug::(anonymous namespace)::StackDumpSignalHandler()
#3 0x0000b7f24560 ([vdso]+0x55f)
#4 0x0000091049f2 views::InkDropHost::RemoveInkDropLayer()
#5 0x000009105b07 views::InkDropImpl::DestroyInkDropHighlight()
#6 0x00000910695b views::InkDropImpl::~InkDropImpl()
#7 0x0000091069fa views::InkDropImpl::~InkDropImpl()
#8 0x000009104e51 views::InkDropHost::~InkDropHost()
#9 0x000009104eda views::InkDropHost::~InkDropHost()
#10 0x0000066afe02 ui::PropertyHandler::ClearProperties()
#11 0x0000090c1e82 views::View::~View()
#12 0x000009073690 views::Button::~Button()
#13 0x0000090791ca views::ImageButton::~ImageButton()
#14 0x0000090c20df views::View::~View()
#15 0x00000956e00f InfoBarView::~InfoBarView()
#16 0x00000956aca5 ConfirmInfoBar::~ConfirmInfoBar()
#17 0x00000956ad5a ConfirmInfoBar::~ConfirmInfoBar()
#18 0x000006d3523e gfx::Animation::Stop()
#19 0x000006d36967 gfx::LinearAnimation::Step()
#20 0x000006d35b47 gfx::AnimationContainer::Run()
#21 0x000006d35e1e base::internal::Invoker<>::Run()
#22 0x000006d362df gfx::AnimationRunner::Step()
#23 0x000009101a94 views::CompositorAnimationRunner::OnAnimationStep()
#24 0x0000079b72a4 ui::Compositor::BeginMainFrame()
#25 0x0000075a096e cc::SingleThreadProxy::DoBeginMainFrame()
#26 0x0000075a0c06 cc::SingleThreadProxy::BeginMainFrame()
#27 0x0000075a1dda base::internal::Invoker<>::RunOnce()
#28 0x00000619a2b6 base::TaskAnnotator::RunTask()
#29 0x0000061b2921 base::sequence_manager::internal::ThreadControllerWithMessagePumpImpl::DoWorkImpl()
#30 0x0000061b3511 base::sequence_manager::internal::ThreadControllerWithMessagePumpImpl::DoWork()
#31 0x000006145b3b base::MessagePumpGlib::HandleDispatch()
#32 0x000006145b7f base::(anonymous namespace)::WorkSourceDispatch()
#33 0x0000b7de3ae4 g_main_context_dispatch
#34 0x0000b7de3e79 (/usr/lib/libglib-2.0.so.0.6600.8+0x4de78)
#35 0x0000b7de3f44 g_main_context_iteration
#36 0x0000061450a4 base::MessagePumpGlib::Run()
#37 0x0000061b1985 base::sequence_manager::internal::ThreadControllerWithMessagePumpImpl::Run()
#38 0x0000061786a1 base::RunLoop::Run()
#39 0x000002a74eb9 content::BrowserMainLoop::RunMainMessageLoop()
#40 0x000002a77e0c content::BrowserMainRunnerImpl::Run()
#41 0x000002a72cf1 content::BrowserMain()
#42 0x0000058945ab content::RunBrowserProcessMain()
#43 0x000005895f77 content::ContentMainRunnerImpl::Run()
#44 0x00000589356a content::RunContentProcess()
#45 0x000005893cec content::ContentMain()
#46 0x000000b5a28f ChromeMain
#47 0x000000b0d457 main
#48 0x0000b4ae3e86 __libc_start_main
#49 0x000000b5a0b1 _start
  gs: 00000033  fs: 00000000  es: 0000007b  ds: 0000007b
 edi: 1576d9e0 esi: 1584e420 ebp: bfc54d50 esp: bfc54d50
 ebx: 1404a638 edx: 00015959 ecx: 00000000 eax: 15959140
 trp: 0000000e err: 00000004  ip: 091049f2  cs: 00000073
 efl: 00010202 usp: bfc54d50  ss: 0000007b
[end of stack trace]
Violación de segmento (`core' generado)

Now the "libva error: /usr/lib/dri/i965_drv_video.so init failed" is not showed

See Also: (none) => https://bugs.mageia.org/show_bug.cgi?id=29519

Comment 6 Morgan Leijström 2021-10-05 18:58:41 CEST
mga8-64, Plasma, Nvidia-current, 4Kscreen

Some video sites, banking: OK

Starting from command line there are a couple errors, I dont know if significant:

[584524:584524:1005/174836.901993:ERROR:vaapi_wrapper.cc(1103)] vaQuerySurfaceAttributes failed, VA error: invalid parameter
[584524:584524:1005/174836.908412:ERROR:vaapi_wrapper.cc(1051)] FillProfileInfo_Locked failed for va_profile VAProfileH264Main and entrypoint VAEntrypointVLD

And later:

Fontconfig error: Cannot load default config file: No such file: (null)
libpng warning: iCCP: known incorrect sRGB profile


Segfault at exit (one time of five):

Used a few sites, clicked the (X) to close it and it segfaulted:

[1005/185205.877407:ERROR:elf_dynamic_array_reader.h(61)] tag not found
Received signal 11 SEGV_MAPERR 000000000000
#0 0x55d108c6d6f9 base::debug::CollectStackTrace()
#1 0x55d108bb6fd6 base::debug::StackTrace::StackTrace()
#2 0x55d108c6cc8b base::debug::(anonymous namespace)::StackDumpSignalHandler()
#3 0x7f9a04d27180 (/usr/lib64/libpthread-2.32.so+0x1317f)
  r8: 00007ffe54bef544  r9: 0000000000000023 r10: 000000000000011e r11: 00007ffe54bef580
 r12: 000055d115b2af10 r13: 000055d115322050 r14: 000055d115322150 r15: 000055d10ba022c0
  di: 00007f99d8053de0  si: 00007ffe54bef6f0  bp: 00007ffe54bef750  bx: 000055d115322150
  dx: 0000000000000001  ax: 0000000000000000  cx: 0000000000000000  sp: 00007ffe54bef728
  ip: 0000000000000000 efl: 0000000000010202 cgf: 002b000000000033 erf: 0000000000000014
 trp: 000000000000000e msk: 0000000000000000 cr2: 0000000000000000
[end of stack trace]
Segmenteringsfel (minnesutskrift skapad)


On starting again, browsing, closing, no segfault.  Hmmm...


--

Yes Animusic is astonishing.
Would love to have budget to build some of that stuff for real.
Something along Marble Machine X

CC: (none) => fri

Comment 7 Thomas Backlund 2021-10-09 11:36:26 CEST
putting on hold as there is a  chromium-browser-stable-94.0.4606.81-1.mga8

currently building

Keywords: (none) => feedback

David Walser 2021-10-09 14:35:43 CEST

Assignee: qa-bugs => nicolas.salguero
Depends on: (none) => 29541
Keywords: feedback => (none)

Comment 8 Morgan Leijström 2021-10-10 12:33:53 CEST
.81 crashes too when closing that banner.

[1010/123131.711564:ERROR:elf_dynamic_array_reader.h(61)] tag not found

...etc
Comment 9 Nicolas Salguero 2021-11-20 20:44:52 CET
Fixed in bug 29541.

Status: ASSIGNED => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.