Bug 33962 - chromium-browser-stable new security issues CVE-2025-061[12]
Summary: chromium-browser-stable new security issues CVE-2025-061[12]
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 9
Hardware: All Linux
Priority: Normal major
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA9-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2025-01-27 09:29 CET by Nicolas Salguero
Modified: 2025-01-30 19:37 CET (History)
4 users (show)

See Also:
Source RPM: chromium-browser-stable-132.0.6834.84-1.mga9.tainted.src.rpm
CVE: CVE-2025-0611, CVE-2025-0612
Status comment:


Attachments

Description Nicolas Salguero 2025-01-27 09:29:40 CET
Upstream has issued an advisory on January 22:
https://chromereleases.googleblog.com/2025/01/stable-channel-update-for-desktop_22.html
Comment 1 Nicolas Salguero 2025-01-27 09:33:04 CET
Suggested advisory:
========================

The updated packages fix security vulnerabilities:

Object corruption in V8. (CVE-2025-0611)

Out of bounds memory access in V8. (CVE-2025-0612)

References:
https://chromereleases.googleblog.com/2025/01/stable-channel-update-for-desktop_22.html
========================

Updated packages in tainted/updates_testing:
========================
chromium-browser-132.0.6834.110-1.mga9.tainted
chromium-browser-stable-132.0.6834.110-1.mga9.tainted

from SRPM:
chromium-browser-stable-132.0.6834.110-1.mga9.tainted.src.rpm

CVE: (none) => CVE-2025-0611, CVE-2025-0612
Assignee: bugsquad => qa-bugs
Status: NEW => ASSIGNED
Source RPM: (none) => chromium-browser-stable-132.0.6834.84-1.mga9.tainted.src.rpm

katnatek 2025-01-27 18:16:41 CET

Keywords: (none) => advisory

Comment 2 katnatek 2025-01-27 20:03:42 CET
RH x86_64

installing chromium-browser-stable-132.0.6834.110-1.mga9.tainted.x86_64.rpm from //home/katnatek/qa-testing/x86_64
Preparing...                     ##################################################################################################
      1/1: chromium-browser-stable
                                 ##################################################################################################
      1/1: removing chromium-browser-stable-132.0.6834.84-1.mga9.tainted.x86_64
                                 ##################################################################################################

mail.com OK
Youtube OK
Webcam on zoom test OK

Same messages in terminal as in bug#33609 comment#26
Looks good for normal use
Comment 3 Morgan Leijström 2025-01-27 21:39:26 CET
Updated, tests OK on two machines

Both running Plasma
Workstation: Intel i7-840 CPU, AMD GPU RX6400
Laptop: i7-3610QM, nvidia GTX 660M, xorg modesetting


Restored previous tabs. 
Swedish localisation.
Shopping, banking, tax, office, sites - different login methods.
Saved a picture from a Nextcloud login.
Printed fetched pdf to network printer

Contrary to my tests with our a few days ago released previous version it failed to print to boomaga, on both installs, but boomaga itself is unreliable (see errata9), so... whatever.

CC: (none) => fri

Comment 4 Morgan Leijström 2025-01-28 09:19:40 CET
I see it built on Cauldron too.

Thank you Christiaan and Nicholas to continue building Chromium!
Do you intend to proceed during the life of Mageia 9?

CC TJ; I read you need Chromium.

CC: (none) => andrewsfarm

Comment 5 Herman Viaene 2025-01-28 10:59:50 CET
MGA9-64 Plasma Wayland on Compag H000SB
No installation issues.
Short test on newspaper site and homebanking, no problems encountered

CC: (none) => herman.viaene

Morgan Leijström 2025-01-28 11:06:25 CET

Whiteboard: (none) => MGA9-64-OK
Keywords: (none) => validated_update
CC: (none) => sysadmin-bugs

Comment 6 Thomas Andrews 2025-01-28 15:50:09 CET
That was quick. A little late to the party, but...

MGA9-64 Plasma, no installation issues. Logged onto my bank's site, looked around, saw that most of my credit card purchases of vegetable seeds had been posted, and left. Looks OK here.
Comment 7 Mageia Robot 2025-01-30 19:37:28 CET
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2025-0029.html

Status: ASSIGNED => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.