Bug 34208 - chromium-browser-stable new security issues CVE-2025-3619 and CVE-2025-3620
Summary: chromium-browser-stable new security issues CVE-2025-3619 and CVE-2025-3620
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 9
Hardware: All Linux
Priority: Normal critical
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA9-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2025-04-22 11:22 CEST by Nicolas Salguero
Modified: 2025-04-28 22:02 CEST (History)
4 users (show)

See Also:
Source RPM: chromium-browser-stable-134.0.6998.165-1.mga9.tainted.src.rpm
CVE: CVE-2025-3619, CVE-2025-3620
Status comment: To build in Cauldron


Attachments

Description Nicolas Salguero 2025-04-22 11:22:02 CEST
Upstream has issued an advisory on April 15:
https://chromereleases.googleblog.com/2025/04/stable-channel-update-for-desktop_15.html
Nicolas Salguero 2025-04-22 11:23:15 CEST

Whiteboard: (none) => MGA9TOO
Source RPM: (none) => chromium-browser-stable-134.0.6998.165-1.mga9.tainted.src.rpm
CVE: (none) => CVE-2025-3619, CVE-2025-3620
Status comment: (none) => Fixed upstream in 135.0.7049.95

Morgan Leijström 2025-04-22 11:27:40 CEST

CC: (none) => fri

Comment 1 Lewis Smith 2025-04-22 21:41:30 CEST
Assigning to you, nicolas, as you now 'do' this package.

Assignee: bugsquad => nicolas.salguero

Nicolas Salguero 2025-04-23 08:27:58 CEST

Assignee: nicolas.salguero => cjw

Comment 2 Nicolas Salguero 2025-04-25 09:13:10 CEST
Upstream has issued an advisory on April 22:
https://chromereleases.googleblog.com/2025/04/stable-channel-update-for-desktop_22.html
Comment 3 Nicolas Salguero 2025-04-25 09:13:53 CEST
Suggested advisory:
========================

The updated packages fix security vulnerabilities:

Heap buffer overflow in Codecs. (CVE-2025-3619)

Use after free in USB. (CVE-2025-3620)

References:
https://chromereleases.googleblog.com/2025/04/stable-channel-update-for-desktop_15.html
https://chromereleases.googleblog.com/2025/04/stable-channel-update-for-desktop_22.html
========================

Updated packages in tainted/updates_testing:
========================
chromium-browser-134.0.6998.165-2.mga9.tainted
chromium-browser-stable-134.0.6998.165-2.mga9.tainted

from SRPM:
chromium-browser-stable-134.0.6998.165-2.mga9.tainted.src.rpm

Status: NEW => ASSIGNED
Version: Cauldron => 9
Status comment: Fixed upstream in 135.0.7049.95 => (none)
Whiteboard: MGA9TOO => (none)
Assignee: cjw => qa-bugs

Comment 4 Brian Rockwell 2025-04-25 23:03:04 CEST
MGA9-64, Xfce, laptop - AMD A6

The following 2 packages are going to be installed:

- chromium-browser-134.0.6998.165-2.mga9.tainted.x86_64
- chromium-browser-stable-134.0.6998.165-2.mga9.tainted.x86_64

419KB of additional disk space will be used.

------

all important websites including theonion are working as expected
video streaming works

CC: (none) => brtians1

katnatek 2025-04-26 00:41:56 CEST

Keywords: (none) => advisory

Comment 5 katnatek 2025-04-26 03:46:36 CEST
installing chromium-browser-stable-134.0.6998.165-2.mga9.tainted.x86_64.rpm from //home/katnatek/qa-testing/x86_64
Preparing...                     ##################################################################################################
      1/1: chromium-browser-stable
                                 ##################################################################################################
      1/1: removing chromium-browser-stable-134.0.6998.165-1.mga9.tainted.x86_64
                                 ##################################################################################################

Facebook OK
Youtube OK
Mail.com OK
Webcam on zoom test page OK

Usual output in terminal
Comment 6 Herman Viaene 2025-04-26 11:37:18 CEST
MGA9-64 Plasma Wayland on Compaq H000SB
No installation issues.
Tested with newspaper site, youtube, homebanking, all OK

CC: (none) => herman.viaene

Comment 7 Morgan Leijström 2025-04-26 14:11:03 CEST
Quick check on my workstation OK

On Plasma X11

Settings kept, tabs restored automatically
Swedish localisation
surfing some sites, incl video and banking, writing this
Printing using both native and system print dialogues

In the terminal from where i lauched it, the same messages ass seen on previous versions:

[morgan@svarten ~]$ chromium-browser --version
Chromium 134.0.6998.165 Mageia.Org 9
[morgan@svarten ~]$ chromium-browser
Gtk-Message: 12:03:44.283: Failed to load module "appmenu-gtk-module": 'gtk_module_display_init': /usr/lib64/gtk-3.0/modules/libwindow-decorations-gtk-module.so: undefined symbol: gtk_module_display_init
[49990:49990:0426/120347.345757:ERROR:request.cc(169)] Request ended (non-user cancelled).
[49990:50014:0426/120354.283337:ERROR:registration_request.cc(291)] Registration response error message: DEPRECATED_ENDPOINT
[49990:50014:0426/120421.865656:ERROR:registration_request.cc(291)] Registration response error message: DEPRECATED_ENDPOINT
*** stack smashing detected ***: terminated
*** stack smashing detected ***: terminated
*** stack smashing detected ***: terminated

And

libpng warning: iCCP: known incorrect sRGB profile

- all seem to repeat now and then.


[morgan@svarten ~]$ inxi -SMCG
System:
  Host: svarten.tribun Kernel: 6.6.87-desktop-1.mga9 arch: x86_64 bits: 64
  Desktop: KDE Plasma v: 5.27.10 Distro: Mageia 9
Machine:
  Type: Desktop Mobo: ASRock model: P55 Pro serial: <superuser required>
    BIOS: American Megatrends v: P2.60 date: 08/20/2010
CPU:
  Info: quad core model: Intel Core i7 870 bits: 64 type: MT MCP cache:
    L2: 1024 KiB
  Speed (MHz): avg: 1205 min/max: 1200/2934 cores: 1: 1205 2: 1205 3: 1205
    4: 1205 5: 1205 6: 1205 7: 1205 8: 1205
Graphics:
  Device-1: Advanced Micro Devices [AMD/ATI] Navi 24 [Radeon RX 6400/6500
    XT/6500M] driver: amdgpu v: kernel
  Display: x11 server: X.org v: 1.21.1.8 with: Xwayland v: 22.1.9 driver: X:
    loaded: amdgpu,v4l dri: radeonsi gpu: amdgpu resolution: 3840x2160~60Hz
  API: EGL v: 1.5 drivers: kms_swrast,radeonsi,swrast
    platforms: gbm,x11,surfaceless,device
  API: OpenGL v: 4.6 vendor: amd mesa v: 25.0.4 renderer: AMD Radeon RX
    6400 (radeonsi navi24 LLVM 15.0.6 DRM 3.54 6.6.87-desktop-1.mga9)
Comment 8 Morgan Leijström 2025-04-26 14:18:28 CEST
Not yet built in Cauldron, but as this is marked as critical security update, lets ship it to our users!

Keywords: (none) => validated_update
Status comment: (none) => To build in Cauldron
Whiteboard: (none) => MGA9-64-OK
CC: (none) => sysadmin-bugs

Comment 9 Mageia Robot 2025-04-28 22:02:16 CEST
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2025-0140.html

Status: ASSIGNED => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.