Bug 33688 - Security issues fixed in chromium-browser-stable-128.0.6613.137-2.mga9
Summary: Security issues fixed in chromium-browser-stable-128.0.6613.137-2.mga9
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 9
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA9-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2024-10-28 00:04 CET by Christiaan Welvaart
Modified: 2024-10-29 17:12 CET (History)
5 users (show)

See Also:
Source RPM: chromium-browser-stable-128.0.6613.137-1.mga9.tainted.src.rpm
CVE:
Status comment:


Attachments

Comment 1 Christiaan Welvaart 2024-10-28 00:10:27 CET
Updated packages are available for testing.

Source RPM: chromium-browser-stable-128.0.6613.137-2.mga9.tainted.src.rpm

Binary RPMs:

x86_64:
chromium-browser-128.0.6613.137-2.mga9.tainted.x86_64.rpm
chromium-browser-stable-128.0.6613.137-2.mga9.tainted.x86_64.rpm


proposed advisory:


Updated chromium-browser-stable packages fix security vulnerabilities


Integer overflow in Layout. (CVE-2024-7025)
Insufficient data validation in Mojo. (CVE-2024-9369)
Inappropriate implementation in V8. (CVE-2024-9370)
Type Confusion in V8. (CVE-2024-9602)
Type Confusion in V8. (CVE-2024-9603)

Status: NEW => ASSIGNED
CC: (none) => cjw
Assignee: cjw => qa-bugs

katnatek 2024-10-28 01:31:30 CET

Keywords: (none) => advisory

katnatek 2024-10-28 02:50:43 CET

See Also: (none) => https://bugs.mageia.org/show_bug.cgi?id=33498

Comment 2 katnatek 2024-10-28 02:51:09 CET
RH x86_64

installing chromium-browser-stable-128.0.6613.137-2.mga9.tainted.x86_64.rpm from //home/katnatek/qa-testing/x86_64
Preparing...                     ##################################################################################################
      1/1: chromium-browser-stable
                                 ##################################################################################################
      1/1: removing chromium-browser-stable-128.0.6613.137-1.mga9.tainted.x86_64
                                 ##################################################################################################

Webcam OK
Youtube OK
mail.com OK

I wonder if we should include CVEs in bug#33609 ?
Comment 3 Lloyd Osten 2024-10-28 03:28:57 CET
I just downloaded and installed the latest Chromium browser
(chromium-browser-stable-128.0.6613.137-2.mga9.tainted.x86_64.rpm)

The streaming problem (I think bug #33498) is still there.   :-(

CC: (none) => lloyd.osten

Comment 4 sturmvogel 2024-10-28 09:07:13 CET
Is there a reason why Chromium browser does not get updated properly to the latest version? Browsers should be updated instead of applying countless patches for CVEs. The spec already contains a lot of patches, but now commits for CVEs gets added additionaly ( which are not even properly documented in the spec).
 
Btw, this Frankenstein browser version from this bugreport lags 3 upstream versions and 23! security issues behind!
Comment 5 katnatek 2024-10-28 18:51:42 CET
(In reply to sturmvogel from comment #4)
> Is there a reason why Chromium browser does not get updated properly to the
> latest version? Browsers should be updated instead of applying countless
> patches for CVEs. The spec already contains a lot of patches, but now
> commits for CVEs gets added additionaly ( which are not even properly
> documented in the spec).
>  
> Btw, this Frankenstein browser version from this bugreport lags 3 upstream
> versions and 23! security issues behind!

This is a good question, we have now llvm19-suite packages in case is needed for build new versions
Comment 6 Christiaan Welvaart 2024-10-28 20:29:34 CET
If we want to skip this security-only update and go to M130 right away, that's fine with me, someone just has to prepare that version update. I hope to have it ready by next week, but it may take longer. Note that all security issues patched here are labeled "High" by upstream.
Comment 7 katnatek 2024-10-28 21:36:41 CET
(In reply to Christiaan Welvaart from comment #6)
> If we want to skip this security-only update and go to M130 right away,
> that's fine with me, someone just has to prepare that version update. I hope
> to have it ready by next week, but it may take longer. Note that all
> security issues patched here are labeled "High" by upstream.

Then we can live with this update for now, I think
Comment 8 Brian Rockwell 2024-10-29 03:15:50 CET
MGA9-64, Xfce, Intel celeron

$ chromium-browser -version
Chromium 128.0.6613.137 Mageia.Org 9

----

email
sites work

CC: (none) => brtians1

Comment 9 Morgan Leijström 2024-10-29 14:26:33 CET
Working well in my usual tests:

Restored previous tabs.

Swedish localisation.

Shopping, banking, tax, office, sites - different login methods.

Saved a picture from a Nextcloud login.

Print page to network printer

Opened local pdf and printed it to boomaga using both internal and system print dialogue.

Whiteboard: (none) => MGA9-64-OK
Keywords: (none) => validated_update
CC: (none) => fri, sysadmin-bugs

Comment 10 Mageia Robot 2024-10-29 17:12:35 CET
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2024-0341.html

Resolution: (none) => FIXED
Status: ASSIGNED => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.