Bug 1224818 (CVE-2024-5157, CVE-2024-5158, CVE-2024-5159, CVE-2024-5160)

Summary: VUL-0: chromium: multiple vulnerabilities fixed in 125.0.6422.76
Product: [openSUSE] openSUSE Distribution Reporter: Andreas Stieger <Andreas.Stieger>
Component: SecurityAssignee: Security Team bot <security-team>
Status: RESOLVED FIXED QA Contact: E-mail List <qa-bugs>
Severity: Normal    
Priority: P3 - Medium CC: Andreas.Stieger, gmbr3
Version: Leap 15.5   
Target Milestone: ---   
Hardware: Other   
OS: Other   
Whiteboard:
Found By: --- Services Priority:
Business Priority: Blocker: ---
Marketing QA Status: --- IT Deployment: ---

Description Andreas Stieger 2024-05-21 20:44:40 UTC
Fixed in chromium 125.0.6422.76:

* CVE-2024-5157: Use after free in Scheduling.
* CVE-2024-5158: Type Confusion in V8
* CVE-2024-5159: Heap buffer overflow in ANGLE
* CVE-2024-5160: Heap buffer overflow in Dawn
* Various fixes from internal audits, fuzzing and other initiatives

https://chromereleases.googleblog.com/2024/05/stable-channel-update-for-desktop_21.html
Comment 1 OBSbugzilla Bot 2024-05-22 06:45:03 UTC
This is an autogenerated message for OBS integration:
This bug (1224818) was mentioned in
https://build.opensuse.org/request/show/1175671 Factory / chromium
https://build.opensuse.org/request/show/1175672 Backports:SLE-15-SP5 / chromium
Comment 2 Marcus Meissner 2024-05-23 10:04:53 UTC
openSUSE-SU-2024:0137-1: An update that fixes four vulnerabilities is now available.

Category: security (important)
Bug References: 1224818
CVE References: CVE-2024-5157,CVE-2024-5158,CVE-2024-5159,CVE-2024-5160
JIRA References: 
Sources used:
openSUSE Backports SLE-15-SP5 (src):    chromium-125.0.6422.76-bp155.2.85.2
Comment 3 Andreas Stieger 2024-05-23 11:11:55 UTC
done