From beef8c9dfcfe36cb0cb0107f6cbf94b1dbb1bd3b Mon Sep 17 00:00:00 2001 From: tigro Date: Thu, 14 Mar 2024 08:14:00 +0300 Subject: [PATCH] - upstream security release 122.0.6261.128 * High CVE-2024-2400: Use after free in Performance Manager --- .chromium.metadata | 2 +- .gitignore | 2 +- SPECS/chromium.spec | 19 +++++++++++-------- 3 files changed, 13 insertions(+), 10 deletions(-) diff --git a/.chromium.metadata b/.chromium.metadata index 3352d263..68a46cb4 100644 --- a/.chromium.metadata +++ b/.chromium.metadata @@ -1,4 +1,4 @@ -f821455b00eeac196dea07e378f45505b95c746e SOURCES/chromium-122.0.6261.111.tar.xz +b3c172451846281a8c1c04835412632ff99566a2 SOURCES/chromium-122.0.6261.128.tar.xz dea187019741602d57aaf189a80abba261fbd2aa SOURCES/linux-x64-0.19.2.tgz 7e5d2c7864c5c83ec789b59c77cd9c20d2594916 SOURCES/linux-arm64-0.19.2.tgz 769196d081c6a0ad37f1c63dec56febfff3370de SOURCES/node-v20.6.1-linux-x64.tar.xz diff --git a/.gitignore b/.gitignore index a4da528d..b65fd787 100644 --- a/.gitignore +++ b/.gitignore @@ -1,4 +1,4 @@ -SOURCES/chromium-122.0.6261.111.tar.xz +SOURCES/chromium-122.0.6261.128.tar.xz SOURCES/linux-x64-0.19.2.tgz SOURCES/linux-arm64-0.19.2.tgz SOURCES/node-v20.6.1-linux-x64.tar.xz diff --git a/SPECS/chromium.spec b/SPECS/chromium.spec index 49eb5585..8ca5dcfa 100644 --- a/SPECS/chromium.spec +++ b/SPECS/chromium.spec @@ -333,7 +333,7 @@ %endif Name: chromium%{chromium_channel} -Version: 122.0.6261.111 +Version: 122.0.6261.128 Release: 1%{?dist}.inferit Summary: A WebKit (Blink) powered web browser that Google doesn't want you to use Url: http://www.chromium.org/Home @@ -593,11 +593,11 @@ Patch414: 0002-Highway-disable-128-bit-vsx.patch Patch500: chromium-122-el8-support-64kpage.patch # Old Yandex patch -Patch500: 0001-Yandex-as-default-search-engine.patch +Patch600: 0001-Yandex-as-default-search-engine.patch # MSVSphere -Patch501: 0001-Added-Russian-description-and-summary-for-gnome-soft.patch +Patch601: 0001-Added-Russian-description-and-summary-for-gnome-soft.patch # Yandex Search by default -Patch502: 0001-Added-Yandex-search-bar-as-default-on-newtab-and-new.patch +Patch602: 0001-Added-Yandex-search-bar-as-default-on-newtab-and-new.patch # upstream patches @@ -1423,12 +1423,11 @@ sed -i 's/std::string data_dir_basename = "chromium"/std::string data_dir_basena %endif %endif -#%patch -P500 -p1 -b .Yandex-as-default-search-engine -%patch -P501 -p1 -b .Added-Russian-description-and-summary-for-gnome-soft +%patch -P601 -p1 -b .Added-Russian-description-and-summary-for-gnome-soft %if ! %{with gost} -%patch -P502 -p1 -b .Yandex-as-default-search-engine +%patch -P602 -p1 -b .Yandex-as-default-search-engine %else -%patch -P500 -p1 -b .Yandex-as-default-search-engine +%patch -P600 -p1 -b .Yandex-as-default-search-engine %endif # We patch Chromium to open chrome://new-tab-page even with non-Google search engines @@ -2237,6 +2236,10 @@ getent group chrome-remote-desktop >/dev/null || groupadd -r chrome-remote-deskt %endif %changelog +* Thu Mar 14 2024 Arkady L. Shane - 122.0.6261.128-1.inferit +- upstream security release 122.0.6261.128 + * High CVE-2024-2400: Use after free in Performance Manager + * Thu Mar 07 2024 Arkady L. Shane - 122.0.6261.111-1.inferit - upstream security release 122.0.6261.111 * High CVE-2024-2173: Out of bounds memory access in V8