Bug 1215924 (CVE-2023-5346)

Summary: VUL-0: CVE-2023-5346: chromium,ungoogled-chromium: Type Confusion in V8
Product: [openSUSE] openSUSE Distribution Reporter: Andreas Stieger <Andreas.Stieger>
Component: SecurityAssignee: Security Team bot <security-team>
Status: RESOLVED FIXED QA Contact: E-mail List <qa-bugs>
Severity: Normal    
Priority: P3 - Medium CC: gmbr3, m.szczepaniak.000
Version: Leap 15.5   
Target Milestone: ---   
Hardware: Other   
OS: Other   
Whiteboard:
Found By: --- Services Priority:
Business Priority: Blocker: ---
Marketing QA Status: --- IT Deployment: ---

Description Andreas Stieger 2023-10-04 06:22:39 UTC
Fixed in 117.0.5938.149:

* CVE-2023-5346: Type Confusion in V8

References:
https://chromereleases.googleblog.com/2023/10/stable-channel-update-for-desktop.html
https://crbug.com/1485829
Comment 1 OBSbugzilla Bot 2023-10-04 08:35:03 UTC
This is an autogenerated message for OBS integration:
This bug (1215924) was mentioned in
https://build.opensuse.org/request/show/1115101 Factory / chromium
https://build.opensuse.org/request/show/1115103 Backports:SLE-15-SP4+Backports:SLE-15-SP5 / chromium
Comment 2 Andreas Stieger 2023-10-04 16:31:47 UTC
ungoogled: https://github.com/ungoogled-software/ungoogled-chromium/pull/2541
Comment 3 Marcus Meissner 2023-10-05 13:04:54 UTC
openSUSE-SU-2023:0292-1: An update that fixes one vulnerability is now available.

Category: security (important)
Bug References: 1215924
CVE References: CVE-2023-5346
JIRA References: 
Sources used:
openSUSE Backports SLE-15-SP5 (src):    chromium-117.0.5938.149-bp155.2.43.1
Comment 4 Andreas Stieger 2023-10-05 13:08:16 UTC
done
Comment 5 OBSbugzilla Bot 2023-10-05 14:34:14 UTC
This is an autogenerated message for OBS integration:
This bug (1215924) was mentioned in
https://build.opensuse.org/request/show/1115837 Factory / ungoogled-chromium