Bug 1221335 (CVE-2024-2400) - VUL-0: chromium,ungoogled-chromium: multiple vulnerabilities fixed in 122.0.6261.128
Summary: VUL-0: chromium,ungoogled-chromium: multiple vulnerabilities fixed in 122.0.6...
Status: RESOLVED FIXED
Alias: CVE-2024-2400
Product: openSUSE Distribution
Classification: openSUSE
Component: Security (show other bugs)
Version: Leap 15.5
Hardware: Other Other
: P3 - Medium : Normal (vote)
Target Milestone: ---
Assignee: Security Team bot
QA Contact: E-mail List
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2024-03-13 08:54 UTC by Andrea Mattiazzo
Modified: 2024-03-18 11:04 UTC (History)
3 users (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Andrea Mattiazzo 2024-03-13 08:54:51 UTC
The Stable channel has been updated to 122.0.6261.128 for Linux which will roll out over the coming days/weeks. 

This update includes 3 security fixes. Below, we highlight fixes that were contributed by external researchers. Please see the Chrome Security Page for more information.


[TBD][327696052] High CVE-2024-2400: Use after free in Performance Manager. Reported by zh1x1an1221 of Ant Group Tianqiong Security Lab on 2024-03-01


As usual, our ongoing internal security work was responsible for a wide range of fixes:

[329224653] Various fixes from internal audits, fuzzing and other initiatives

https://chromereleases.googleblog.com/2024/03/stable-channel-update-for-desktop_12.html
Comment 1 Andreas Stieger 2024-03-13 09:47:58 UTC
submitted
Comment 2 OBSbugzilla Bot 2024-03-13 11:55:05 UTC
This is an autogenerated message for OBS integration:
This bug (1221335) was mentioned in
https://build.opensuse.org/request/show/1157503 Factory / chromium
https://build.opensuse.org/request/show/1157504 Backports:SLE-15-SP6 / chromium
https://build.opensuse.org/request/show/1157505 Backports:SLE-15-SP5 / chromium
Comment 3 OBSbugzilla Bot 2024-03-14 15:35:03 UTC
This is an autogenerated message for OBS integration:
This bug (1221335) was mentioned in
https://build.opensuse.org/request/show/1158019 Factory / ungoogled-chromium
Comment 4 Marcus Meissner 2024-03-18 10:57:50 UTC
released
Comment 5 Marcus Meissner 2024-03-18 11:04:59 UTC
openSUSE-SU-2024:0084-1: An update that fixes 12 vulnerabilities is now available.

Category: security (important)
Bug References: 1220131,1220604,1221105,1221335
CVE References: CVE-2024-1669,CVE-2024-1670,CVE-2024-1671,CVE-2024-1672,CVE-2024-1673,CVE-2024-1674,CVE-2024-1675,CVE-2024-1676,CVE-2024-2173,CVE-2024-2174,CVE-2024-2176,CVE-2024-2400
JIRA References: 
Sources used:
openSUSE Backports SLE-15-SP5 (src):    chromium-122.0.6261.128-bp155.2.75.1, llvm17-17.0.6-bp155.2.2