From 7dc229d50c2dfabff57086de7a90ad9cc8e52336 Mon Sep 17 00:00:00 2001 From: tigro Date: Tue, 3 Sep 2024 07:22:24 +0300 Subject: [PATCH] - update to 128.0.6613.119 * High CVE-2024-8362: Use after free in WebAudio. * High CVE-2024-7970: Out of bounds write in V8. --- .chromium.metadata | 2 +- .gitignore | 2 +- SPECS/chromium.spec | 7 ++++++- 3 files changed, 8 insertions(+), 3 deletions(-) diff --git a/.chromium.metadata b/.chromium.metadata index 5f4f7b8e..1ecc0f36 100644 --- a/.chromium.metadata +++ b/.chromium.metadata @@ -1,6 +1,6 @@ +088b64ba65b6a5b6d8d2d1e9788559a00c65dd34 SOURCES/chromium-128.0.6613.119.tar.xz ccd15016324e640c40f6fc01ab076dc52196ea54 SOURCES/msspi-e91bd46306cc7044b2903cd07b788c13c36481e3.tar.xz 9bd36edf9f2e882aad828ad88faa7b9d02566cea SOURCES/Chromium-Gost-648cc5b901f2447b9b12bc5b09b962ec802b025a.tar.xz -81fc28ecc7beed0dcfc5208c492865ed447c3389 SOURCES/chromium-128.0.6613.113.tar.xz dea187019741602d57aaf189a80abba261fbd2aa SOURCES/linux-x64-0.19.2.tgz 7e5d2c7864c5c83ec789b59c77cd9c20d2594916 SOURCES/linux-arm64-0.19.2.tgz 769196d081c6a0ad37f1c63dec56febfff3370de SOURCES/node-v20.6.1-linux-x64.tar.xz diff --git a/.gitignore b/.gitignore index 1fd8b0ad..24be3899 100644 --- a/.gitignore +++ b/.gitignore @@ -1,4 +1,4 @@ -SOURCES/chromium-128.0.6613.113.tar.xz +SOURCES/chromium-128.0.6613.119.tar.xz SOURCES/linux-x64-0.19.2.tgz SOURCES/linux-arm64-0.19.2.tgz SOURCES/node-v20.6.1-linux-x64.tar.xz diff --git a/SPECS/chromium.spec b/SPECS/chromium.spec index 0ef32a00..94901833 100644 --- a/SPECS/chromium.spec +++ b/SPECS/chromium.spec @@ -337,7 +337,7 @@ %endif Name: chromium%{chromium_channel} -Version: 128.0.6613.113 +Version: 128.0.6613.119 Release: 1%{?dist}.inferit Summary: A WebKit (Blink) powered web browser that Google doesn't want you to use Url: http://www.chromium.org/Home @@ -2198,6 +2198,11 @@ getent group chrome-remote-desktop >/dev/null || groupadd -r chrome-remote-deskt %endif %changelog +* Mon Sep 02 2024 Arkady L. Shane - 128.0.6613.119-1.inferit +- update to 128.0.6613.119 + * High CVE-2024-8362: Use after free in WebAudio. + * High CVE-2024-7970: Out of bounds write in V8. + * Thu Aug 29 2024 Arkady L. Shane - 128.0.6613.113-1.inferit - update to 128.0.6613.113 * High CVE-2024-7969: Type Confusion in V8