Bug 32459 - chromium -browser-stable 118.0.5993.117 update includes security fixes
Summary: chromium -browser-stable 118.0.5993.117 update includes security fixes
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 9
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA9-64-OK MGA9-32-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2023-10-27 21:48 CEST by christian barranco
Modified: 2023-10-31 00:07 CET (History)
6 users (show)

See Also:
Source RPM: chromium-browser-stable-118.0.5993.70-1.mga9.tainted.src.rpm
CVE: CVE-2023-5472
Status comment:


Attachments

christian barranco 2023-10-27 21:49:32 CEST

CVE: (none) => CVE-2023-5472
CC: (none) => fri

Comment 1 katnatek 2023-10-27 23:21:58 CEST
Remember to remove the dark 22x22 icon
katnatek 2023-10-27 23:42:15 CEST

CC: (none) => j.alberto.vc

Comment 2 christian barranco 2023-10-28 10:05:08 CEST
(In reply to katnatek from comment #1)
> Remember to remove the dark 22x22 icon

Yep, it is included ;)
Comment 3 christian barranco 2023-10-28 13:21:46 CEST
ADVISORY NOTICE PROPOSAL
========================

New chromium-browser-stable 118.0.5993.117 fixes bugs and vulnerabilities


Description
The chromium-browser-stable package has been updated to the 118.0.5993.117 release, fixing bugs and 3 vulnerabilities, together with 118.0.5993.88; some of them are listed below:

High CVE-2023-5472: Use after free in Profiles.


References
https://bugs.mageia.org/show_bug.cgi?id=32459
https://chromereleases.googleblog.com/2023/10/stable-channel-update-for-desktop_24.html
https://chromereleases.googleblog.com/2023/10/stable-channel-update-for-desktop_17.html


SRPMS
9/tainted
chromium-browser-stable-118.0.5993.117-1.mga9.tainted.src.rpm


PROVIDED PACKAGES
=================
x86_64
chromium-browser-118.0.5993.117-1.mga9.tainted.x86_64.rpm
chromium-browser-stable-118.0.5993.117-1.mga9.tainted.x86_64.rpm

i586
chromium-browser-118.0.5993.117-1.mga9.tainted.i586.rpm
chromium-browser-stable-118.0.5993.117-1.mga9.tainted.i586.rpm
Comment 4 christian barranco 2023-10-28 13:34:58 CEST
Ready for QA when upload is over.

Assignee: chb0 => qa-bugs

Comment 5 Marja Van Waes 2023-10-28 14:58:13 CEST
Advisory from comment 3 added to SVN. Please remove the "advisory" keyword if it needs to be changed. It also helps when obsolete advisories are tagged as "obsolete"

CC: (none) => marja11
Keywords: (none) => advisory

Comment 6 Morgan Leijström 2023-10-28 18:41:31 CEST
mga9-64 OK here
Plasma, nvidia470 on GTX750, 4K screen
6.4.16-desktop-4.mga9 on Intel i8-870, P55 chipset

Help popup report:
Version 118.0.5993.117 (Officiell version) Mageia.Org 9 (64 bitar)

Swedish locale, tabs kept from previous version
Tested three video sites, three banking sites, and tax office
Comment 7 Thomas Andrews 2023-10-29 23:17:34 CET
MGA9-64 Plasma, i5-2500,Intel graphics.

US locale, looks OK here.

CC: (none) => andrewsfarm

Comment 8 christian barranco 2023-10-30 07:43:31 CET
So, x86_64 OK?
Comment 9 Thomas Andrews 2023-10-30 12:21:33 CET
Should be. Validating.

CC: (none) => sysadmin-bugs
Keywords: (none) => validated_update
Whiteboard: (none) => MGA9-64-OK

Comment 10 katnatek 2023-10-30 20:04:20 CET
Tested on Mageia 9 i586 , the 22x22 black icon is not there but now I don't get any Icon in the menu

Test youtube, works
Test web.telegram.org, works

This comment is done on chromium-browser, I get some messages on terminal, but maybe is related to my hardware

Gtk-WARNING **: 12:46:16.496: Theme parsing error: gtk.css:2:33: Failed to import: Error al abrir el archivo /home/katnatek/.config/gtk-3.0/window_decorations.css: No existe el fichero o el directorio
[32008:32008:1030/124619.655193:ERROR:policy_logger.cc(154)] :components/enterprise/browser/controller/chrome_browser_cloud_management_controller.cc(163) Cloud management controller initialization aborted as CBCM is not enabled.
libva error: /usr/lib/dri/i965_drv_video.so init failed
Warning: eglChooseConfig returned zero configs
    at Create (../../third_party/dawn/src/dawn/native/opengl/ContextEGL.cpp:52)
    at Create (../../third_party/dawn/src/dawn/native/opengl/PhysicalDeviceGL.cpp:97)

Lot of this:
[862:862:1030/124839.220708:ERROR:gl_utils.cc(398)] [.RenderCompositor-0xaaa26300] GL_INVALID_FRAMEBUFFER_OPERATION: Framebuffer is incomplete: Attachment is not renderable.
katnatek 2023-10-30 20:04:49 CET

Whiteboard: MGA9-64-OK => MGA9-64-OK MGA9-32-OK

Comment 11 katnatek 2023-10-30 20:07:43 CET
For the next update I think you can import the suse's svg you mention in the previous round.
Comment 12 christian barranco 2023-10-30 20:11:04 CET
(In reply to katnatek from comment #11)
> For the next update I think you can import the suse's svg you mention in the
> previous round.

Hi. It is there already...

Have you tried to unpin Chromium from the task bar and to pin it again?
What DE do you use? Have you restarted you machine and checked again (sorry if it is too obvious..)?
Comment 13 katnatek 2023-10-30 23:27:44 CET
(In reply to christian barranco from comment #12)
> (In reply to katnatek from comment #11)
> > For the next update I think you can import the suse's svg you mention in the
> > previous round.
> 
> Hi. It is there already...
> 
> Have you tried to unpin Chromium from the task bar and to pin it again?
> What DE do you use? Have you restarted you machine and checked again (sorry
> if it is too obvious..)?

I don't add to my task bar, It's in the menu where I not see the icon, I test in a bundle with lxqt, I will see on Plasma and keep you informed
Comment 14 katnatek 2023-10-30 23:37:02 CET
(In reply to katnatek from comment #13)
> I don't add to my task bar, It's in the menu where I not see the icon, I
> test in a bundle with lxqt, I will see on Plasma and keep you informed

Tested on Plasma, I can see the Icon
Switch back to lxqt and can see the icon, perhaps I did must test close session and start again, sorry for the noise
Comment 15 christian barranco 2023-10-30 23:41:29 CET
(In reply to katnatek from comment #14)
> (In reply to katnatek from comment #13)
> > I don't add to my task bar, It's in the menu where I not see the icon, I
> > test in a bundle with lxqt, I will see on Plasma and keep you informed
> 
> Tested on Plasma, I can see the Icon
> Switch back to lxqt and can see the icon, perhaps I did must test close
> session and start again, sorry for the noise

No worries. Glad it is solved!
Comment 16 Brian Rockwell 2023-10-31 00:01:47 CET
old equipment, physical hardware on Xfce

no installation issues

spent day using it, nothing major to note, working as expected.

CC: (none) => brtians1

Comment 17 Mageia Robot 2023-10-31 00:07:51 CET
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2023-0306.html

Status: NEW => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.