Bug 30259 - chromium-browser-stable new security issues fixed in 100.0.4896.75
Summary: chromium-browser-stable new security issues fixed in 100.0.4896.75
Status: RESOLVED DUPLICATE of bug 30276
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 8
Hardware: All Linux
Priority: Normal major
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard:
Keywords:
Depends on: 30276
Blocks:
  Show dependency treegraph
 
Reported: 2022-04-08 14:40 CEST by christian barranco
Modified: 2022-04-18 01:49 CEST (History)
4 users (show)

See Also:
Source RPM: chromium-browser-stable-100.0.4896.60-1.mga8.src.rpm
CVE:
Status comment:


Attachments

Description christian barranco 2022-04-08 14:40:24 CEST
Upstream has released version 100.0.4896.75 on April 4th:
https://chromereleases.googleblog.com/2022/04/stable-channel-update-for-desktop.html

It fixes the following security issue:
[1311641] High CVE-2022-1232: Type Confusion in V8. Reported by Sergei Glazunov of Google Project Zero on 2022-03-30

The build has been successful locally, and I am submitting it to our BS. An advisory proposal will follow once the build will have passed.
christian barranco 2022-04-08 14:40:58 CEST

CC: (none) => davidwhodgins

Comment 1 christian barranco 2022-04-11 19:08:26 CEST
Hi.

The new packages are now ready in core/updates_testing.


ADVISORY NOTICE PROPOSAL
========================

Updated chromium-browser-stable packages fix a CVE


Description
The chromium-browser-stable package has been updated to the 100.0.4896.75
version, fixing one CVE. 

[1311641] High CVE-2022-1232: Type Confusion in V8. Reported by Sergei Glazunov of Google Project Zero on 2022-03-30

References
https://bugs.mageia.org/show_bug.cgi?id=30259
https://chromereleases.googleblog.com/2022/04/stable-channel-update-for-desktop.html


SRPMS
8/core
chromium-browser-stable-100.0.4896.75-1.mga8


PROVIDED PACKAGES
=================
x86_64
chromium-browser-100.0.4896.75-1.mga8.x86_64.rpm
chromium-browser-stable-100.0.4896.75-1.mga8.x86_64.rpm

i586
chromium-browser-100.0.4896.75-1.mga8.i586.rpm
chromium-browser-stable-100.0.4896.75-1.mga8.i586.rpm

Assignee: chb0 => qa-bugs
CC: (none) => sysadmin-bugs

Comment 2 christian barranco 2022-04-11 19:09:57 CEST
Hi.
I also tested it in a MGA8 LXQt VM. 

* No installation issue. 
* Web browsing: ok.
* Youtube video: ok.
Comment 3 David Walser 2022-04-11 23:17:55 CEST
Works fine for me on Mageia 8 x86_64 too.
Comment 4 Dave Hodgins 2022-04-11 23:48:28 CEST
Ok for me too. Advisory committed to svn. Validating the update.

Whiteboard: (none) => MGA8-64-OK
Keywords: (none) => advisory, validated_update

Comment 5 Morgan Leijström 2022-04-12 11:54:44 CEST
OK here too my normal tests
mga8-64, old intel i7, plasma, nvidia-current, swedish

CC: (none) => fri

David Walser 2022-04-12 23:16:14 CEST

Depends on: (none) => 30276

Comment 6 Dave Hodgins 2022-04-15 22:36:31 CEST
Removing ok/validation since this version will not be being pushed.

Keywords: advisory, validated_update => (none)
Whiteboard: MGA8-64-OK => (none)

Comment 7 Brian Rockwell 2022-04-17 22:12:46 CEST
MGA8-32, mate, VM

The following 7 packages are going to be installed:

- chromium-browser-100.0.4896.75-1.mga8.i586
- chromium-browser-stable-100.0.4896.75-1.mga8.i586
- libatomic1-10.3.0-2.mga8.i586
- libjsoncpp24-1.9.4-1.mga8.i586
- libminizip1-1.2.12-1.1.mga8.i586
- libre2_9-20201101-2.mga8.i586
- libsnappy1-1.1.8-2.mga8.i586


Chromium logo
Chromium
Version 100.0.4896.75 (Developer Build) Mageia.Org 8 (32-bit)

I tested jitsi meet - works
browsed some sites - works

seems okay

CC: (none) => brtians1

Comment 8 Dave Hodgins 2022-04-17 22:33:16 CEST
Closing as wont fix since it's being replaced in bug 30276 by
chromium-browser-stable-100.0.4896.127-1.mga8 which is still building as per
http://pkgsubmit.mageia.org/

Resolution: (none) => WONTFIX
Status: NEW => RESOLVED

Comment 9 David Walser 2022-04-18 01:49:32 CEST
It's not WONTFIX though.

*** This bug has been marked as a duplicate of bug 30276 ***

Resolution: WONTFIX => DUPLICATE


Note You need to log in before you can comment on or make changes to this bug.