Bug 30183 - update request: chromium-browser-stable new security issues fixed in 99.0.4844.74
Summary: update request: chromium-browser-stable new security issues fixed in 99.0.484...
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 8
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA8-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2022-03-17 17:43 CET by christian barranco
Modified: 2022-03-21 21:19 CET (History)
5 users (show)

See Also:
Source RPM: chromium-browser-stable-99.0.4844.51-1.mga8.src.rpm
CVE:
Status comment:


Attachments

Description christian barranco 2022-03-17 17:43:48 CET
Hi

Update within the current stable branch (99) was released on 2022-3-15, fixing many CVE.
https://chromereleases.googleblog.com/2022/03/stable-channel-update-for-desktop_15.html?m=1

I am taking care of the update in MGA8. I will keep you posted when it is ready for QA.

Please, bare in mind Cauldron will be behind until the large lib update is complete and until a solution is found to use ffmpeg from the system lib with ffmpeg 5.0


ADVISORY PROPOSAL
=================

Updated chromium-browser-stable packages fix security vulnerability


Description
The chromium-browser-stable package has been updated to the 99.0.4844.74
version that fixes multiples security vulnerabilities.

[1299422] Critical CVE-2022-0971: Use after free in Blink Layout.
[1301320] High CVE-2022-0972: Use after free in Extensions.
[1297498] High CVE-2022-0973: Use after free in Safe Browsing.
[1291986] High CVE-2022-0974 : Use after free in Splitscreen. 
[1295411] High CVE-2022-0975: Use after free in ANGLE. 
[1296866] High CVE-2022-0976: Heap buffer overflow in GPU.
[1299225] High CVE-2022-0977: Use after free in Browser UI. 
[1299264] High CVE-2022-0978: Use after free in ANGLE. 
[1302644] High CVE-2022-0979: Use after free in Safe Browsing. 
[1302157] Medium CVE-2022-0980: Use after free in New Tab Page.


References
https://bugs.mageia.org/show_bug.cgi?id="this bug report"
https://chromereleases.googleblog.com/2022/03/stable-channel-update-for-desktop_15.html?m=1


SRPMS
8/core
chromium-browser-stable-99.0.4844.74-1.mga8
christian barranco 2022-03-17 19:18:09 CET

Source RPM: chromium-browser-stable-999.0.4844.51-1.mga8.src.rpm => chromium-browser-stable-99.0.4844.51-1.mga8.src.rpm

Comment 1 christian barranco 2022-03-18 09:57:54 CET
Hi

99.0.4844.74 is now available in core-updates_testing, MGA8.


PROVIDED PACKAGES:
x86_64
chromium-browser-99.0.4844.74-1.mga8.x86_64.rpm
chromium-browser-stable-99.0.4844.74-1.mga8.x86_64.rpm

i586
chromium-browser-99.0.4844.74-1.mga8.i586.rpm
chromium-browser-stable-99.0.4844.74-1.mga8.i586.rpm

Assignee: chb0 => qa-bugs
CC: (none) => sysadmin-bugs

Comment 2 Jose Manuel López 2022-03-18 13:03:48 CET
Hi,

I have tested from Vbox Mga X86_64. Works fine for me. 

Settings ok.
Video ok.
Audio ok.
Themes ok.
Addons ok.
Banks ok.

Updated from the last version by konsole whit urpmi.

No issues for the moment.

Greetings!

CC: (none) => joselp

Comment 3 Thomas Andrews 2022-03-20 22:32:01 CET
Gee, seems like we just did one of these updates last week. Oh, well...

No installation issues on my MGA8-64 Plasma system. Tried a number of websites, including this one, and everything seems OK.

CC: (none) => andrewsfarm

Comment 4 christian barranco 2022-03-21 07:56:48 CET
Hi

Tested on MGA8-64 LXQt VM:

-no installation issue
-browsing: OK
-Youtube: OK
Comment 5 Herman Viaene 2022-03-21 11:19:10 CET
MGA8-64 Plasma on Lenovo B50 in Dutch
No installation issues
Usual set of sites I visit daily, all work OK.

CC: (none) => herman.viaene

Comment 6 Thomas Andrews 2022-03-21 13:26:47 CET
That should be enough tests. Giving this a 64-bit OK and validating. Advisory in Comment 0.

Whiteboard: (none) => MGA8-64-OK
Keywords: (none) => validated_update

Dave Hodgins 2022-03-21 19:33:46 CET

Keywords: (none) => advisory
CC: (none) => davidwhodgins

Comment 7 Mageia Robot 2022-03-21 21:19:54 CET
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2022-0107.html

Resolution: (none) => FIXED
Status: NEW => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.