From a9f07dca58393c305373c7f51770b316f32a96d2 Mon Sep 17 00:00:00 2001 From: tigro Date: Tue, 25 Jun 2024 21:58:51 +0300 Subject: [PATCH] - update to 126.0.6478.126 * High CVE-2024-6290: Use after free in Dawn * High CVE-2024-6291: Use after free in Swiftshader * High CVE-2024-6292: Use after free in Dawn * High CVE-2024-6293: Use after free in Dawn --- .chromium.metadata | 2 +- .gitignore | 2 +- SPECS/chromium.spec | 9 ++++++++- 3 files changed, 10 insertions(+), 3 deletions(-) diff --git a/.chromium.metadata b/.chromium.metadata index 7a0f8a81..2cdc53bd 100644 --- a/.chromium.metadata +++ b/.chromium.metadata @@ -1,4 +1,4 @@ -9ffcfb6e518203893b5ba51d08e5f8c2479aa443 SOURCES/chromium-126.0.6478.114.tar.xz +d14397bb1b1d31117fe60e2972a726fcacd22927 SOURCES/chromium-126.0.6478.126.tar.xz dea187019741602d57aaf189a80abba261fbd2aa SOURCES/linux-x64-0.19.2.tgz 7e5d2c7864c5c83ec789b59c77cd9c20d2594916 SOURCES/linux-arm64-0.19.2.tgz 769196d081c6a0ad37f1c63dec56febfff3370de SOURCES/node-v20.6.1-linux-x64.tar.xz diff --git a/.gitignore b/.gitignore index ce4e8e7c..bc9c7395 100644 --- a/.gitignore +++ b/.gitignore @@ -1,4 +1,4 @@ -SOURCES/chromium-126.0.6478.114.tar.xz +SOURCES/chromium-126.0.6478.126.tar.xz SOURCES/linux-x64-0.19.2.tgz SOURCES/linux-arm64-0.19.2.tgz SOURCES/node-v20.6.1-linux-x64.tar.xz diff --git a/SPECS/chromium.spec b/SPECS/chromium.spec index 458a43af..3d512e57 100644 --- a/SPECS/chromium.spec +++ b/SPECS/chromium.spec @@ -350,7 +350,7 @@ %endif Name: chromium%{chromium_channel} -Version: 126.0.6478.114 +Version: 126.0.6478.126 Release: 1%{?dist}.inferit Summary: A WebKit (Blink) powered web browser that Google doesn't want you to use Url: http://www.chromium.org/Home @@ -2291,6 +2291,13 @@ getent group chrome-remote-desktop >/dev/null || groupadd -r chrome-remote-deskt %endif %changelog +* Tue Jun 25 2024 Arkady L. Shane - 126.0.6478.126-1.inferit +- update to 126.0.6478.126 + * High CVE-2024-6290: Use after free in Dawn + * High CVE-2024-6291: Use after free in Swiftshader + * High CVE-2024-6292: Use after free in Dawn + * High CVE-2024-6293: Use after free in Dawn + * Wed Jun 19 2024 Arkady L. Shane - 126.0.6478.114-1.inferit - update to 126.0.6478.114 * High CVE-2024-6100: Type Confusion in V8