Bug 34125 - chromium-browser-stable new security issue CVE-2025-2476
Summary: chromium-browser-stable new security issue CVE-2025-2476
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 9
Hardware: All Linux
Priority: Normal critical
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA9-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2025-03-21 10:51 CET by Nicolas Salguero
Modified: 2025-03-31 09:36 CEST (History)
5 users (show)

See Also:
Source RPM: chromium-browser-stable-134.0.6998.88-1.mga9.tainted.src.rpm
CVE: CVE-2025-2476
Status comment:


Attachments

Description Nicolas Salguero 2025-03-21 10:51:00 CET
Upstream has issued an advisory on March 19:
https://chromereleases.googleblog.com/2025/03/stable-channel-update-for-desktop_19.html
Nicolas Salguero 2025-03-21 10:51:43 CET

CVE: (none) => CVE-2025-2476
Source RPM: (none) => chromium-browser-stable-134.0.6998.88-1.mga9.tainted.src.rpm
Whiteboard: (none) => MGA9TOO
Status comment: (none) => Fixed upstream in 134.0.6998.117

Comment 1 Nicolas Salguero 2025-03-24 09:33:34 CET
Suggested advisory:
========================

The updated packages fix a security vulnerability:

Use after free in Lens. (CVE-2025-2476)

References:
https://chromereleases.googleblog.com/2025/03/stable-channel-update-for-desktop_19.html
========================

Updated packages in tainted/updates_testing:
========================
chromium-browser-134.0.6998.117-1.mga9.tainted
chromium-browser-stable-134.0.6998.117-1.mga9.tainted

from SRPM:
chromium-browser-stable-134.0.6998.117-1.mga9.tainted.src.rpm

Version: Cauldron => 9
Assignee: bugsquad => qa-bugs
Status: NEW => ASSIGNED
Whiteboard: MGA9TOO => (none)
Status comment: Fixed upstream in 134.0.6998.117 => (none)

Comment 2 Herman Viaene 2025-03-24 15:47:28 CET
MGA9-64  Plasma Wayland on Compaq H000SB
No installation issues.
No problems in using this version.

CC: (none) => herman.viaene

katnatek 2025-03-24 18:52:14 CET

Keywords: (none) => advisory

Comment 3 katnatek 2025-03-24 19:31:35 CET
RH x86_64

installing chromium-browser-stable-134.0.6998.117-1.mga9.tainted.x86_64.rpm from //home/katnatek/qa-testing/x86_64
Preparing...                     ##################################################################################################
      1/1: chromium-browser-stable
                                 ##################################################################################################
      1/1: removing chromium-browser-stable-134.0.6998.88-1.mga9.tainted.x86_64
                                 ##################################################################################################

Webcam on zoom test page OK
Youtube OK
mail.com OK

Usual output in terminal

Looks OK
Comment 4 Morgan Leijström 2025-03-24 20:49:04 CET
Quick check on my workstation OK

On Plasma X11

Swedish localisation
surfing some sites, incl video


[morgan@svarten ~]$ inxi -SMCG
System:
  Host: svarten.tribun Kernel: 6.6.83-server-1.mga9 arch: x86_64 bits: 64
  Desktop: KDE Plasma v: 5.27.10 Distro: Mageia 9
Machine:
  Type: Desktop Mobo: ASRock model: P55 Pro serial: <superuser required>
    BIOS: American Megatrends v: P2.60 date: 08/20/2010
CPU:
  Info: quad core model: Intel Core i7 870 bits: 64 type: MT MCP cache:
    L2: 1024 KiB
  Speed (MHz): avg: 2936 min/max: 1200/2934 cores: 1: 2936 2: 2936 3: 2936
    4: 2936 5: 2936 6: 2936 7: 2936 8: 2936
Graphics:
  Device-1: Advanced Micro Devices [AMD/ATI] Navi 24 [Radeon RX 6400/6500
    XT/6500M] driver: amdgpu v: kernel
  Display: x11 server: X.org v: 1.21.1.8 with: Xwayland v: 22.1.9 driver: X:
    loaded: amdgpu,v4l dri: radeonsi gpu: amdgpu resolution: 3840x2160~60Hz
  API: EGL v: 1.5 drivers: kms_swrast,radeonsi,swrast
    platforms: gbm,x11,surfaceless,device
  API: OpenGL v: 4.6 vendor: amd mesa v: 24.2.8 renderer: AMD Radeon RX
    6400 (radeonsi navi24 LLVM 15.0.6 DRM 3.54 6.6.83-server-1.mga9)

CC: (none) => fri

Comment 5 Thomas Andrews 2025-03-25 16:41:13 CET
MGA9-64 Plasma, i5-7500, Nvidia Quadro K620 graphics, using nvidia-current.

No installation issues. I use chromium mostly for banking, as my bank seems to trust it more than Firefox. I looged onto my bank's site, looked around, saw that they haven't lost my money yet.

Looks good here.

CC: (none) => andrewsfarm

Comment 6 Brian Rockwell 2025-03-27 14:46:11 CET
MGA8-64, Gnome, laptop

The following 2 packages are going to be installed:

- chromium-browser-134.0.6998.117-1.mga9.tainted.x86_64
- chromium-browser-stable-134.0.6998.117-1.mga9.tainted.x86_64

------

websites are working as expected
video streaming works

CC: (none) => brtians1
Whiteboard: (none) => MGA9-64-OK

Comment 7 Thomas Andrews 2025-03-27 15:17:22 CET
Yes, no reason to hold it any longer. Validating.

CC: (none) => sysadmin-bugs
Keywords: (none) => validated_update

Comment 8 Mageia Robot 2025-03-27 17:15:31 CET
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2025-0118.html

Status: ASSIGNED => RESOLVED
Resolution: (none) => FIXED

Comment 9 everything grammarians 2025-03-31 07:46:40 CEST Comment hidden (spam)

CC: (none) => beanharold564

Nicolas Salguero 2025-03-31 09:36:30 CEST

CC: beanharold564 => (none)


Note You need to log in before you can comment on or make changes to this bug.