openSUSE-SU-2024:0084-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2024:0084-1.json
JSON Data
https://api.osv.dev/v1/vulns/openSUSE-SU-2024:0084-1
Related
Published
2024-03-18T07:51:17Z
Modified
2024-03-18T07:51:17Z
Summary
Security update for chromium
Details

This update for chromium fixes the following issue:

Chromium 122.0.6261.128 (boo#1221335)

  • CVE-2024-2400: Use after free in Performance Manager

Chromium 122.0.6261.111 (boo#1220131,boo#1220604,boo#1221105)

  • New upstream security release.
  • CVE-2024-2173: Out of bounds memory access in V8.
  • CVE-2024-2174: Inappropriate implementation in V8.
  • CVE-2024-2176: Use after free in FedCM.

Chromium 122.0.6261.94

  • CVE-2024-1669: Out of bounds memory access in Blink.
  • CVE-2024-1670: Use after free in Mojo.
  • CVE-2024-1671: Inappropriate implementation in Site Isolation.
  • CVE-2024-1672: Inappropriate implementation in Content Security Policy.
  • CVE-2024-1673: Use after free in Accessibility.
  • CVE-2024-1674: Inappropriate implementation in Navigation.
  • CVE-2024-1675: Insufficient policy enforcement in Download.
  • CVE-2024-1676: Inappropriate implementation in Navigation.
  • Type Confusion in V8
References

Affected packages

SUSE:Package Hub 15 SP5 / chromium

Package

Name
chromium
Purl
pkg:rpm/suse/chromium&distro=SUSE%20Package%20Hub%2015%20SP5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
122.0.6261.128-bp155.2.75.1

Ecosystem specific

{
    "binaries": [
        {
            "lld17": "17.0.6-bp155.2.2",
            "libclang-cpp17-64bit": "17.0.6-bp155.2.2",
            "clang17-devel": "17.0.6-bp155.2.2",
            "llvm17-vim-plugins": "17.0.6-bp155.2.2",
            "libclang-cpp17-32bit": "17.0.6-bp155.2.2",
            "libLLVM17-64bit": "17.0.6-bp155.2.2",
            "clang17": "17.0.6-bp155.2.2",
            "clang17-doc": "17.0.6-bp155.2.2",
            "python3-clang17": "17.0.6-bp155.2.2",
            "llvm17-gold": "17.0.6-bp155.2.2",
            "llvm17-libclang13": "17.0.6-bp155.2.2",
            "python3-lldb17": "17.0.6-bp155.2.2",
            "llvm17-doc": "17.0.6-bp155.2.2",
            "llvm17-polly": "17.0.6-bp155.2.2",
            "libLTO17": "17.0.6-bp155.2.2",
            "llvm17-libc++-devel": "17.0.6-bp155.2.2",
            "lldb17-devel": "17.0.6-bp155.2.2",
            "lldb17": "17.0.6-bp155.2.2",
            "llvm17-libc++abi1": "17.0.6-bp155.2.2",
            "llvm17": "17.0.6-bp155.2.2",
            "libomp17-devel": "17.0.6-bp155.2.2",
            "llvm17-libc++abi-devel": "17.0.6-bp155.2.2",
            "libclang-cpp17": "17.0.6-bp155.2.2",
            "llvm17-libc++1": "17.0.6-bp155.2.2",
            "llvm17-devel": "17.0.6-bp155.2.2",
            "llvm17-opt-viewer": "17.0.6-bp155.2.2",
            "llvm17-polly-devel": "17.0.6-bp155.2.2",
            "chromedriver": "122.0.6261.128-bp155.2.75.1",
            "chromium": "122.0.6261.128-bp155.2.75.1",
            "liblldb17": "17.0.6-bp155.2.2",
            "libLLVM17-32bit": "17.0.6-bp155.2.2",
            "libLLVM17": "17.0.6-bp155.2.2"
        }
    ]
}

SUSE:Package Hub 15 SP5 / llvm17

Package

Name
llvm17
Purl
pkg:rpm/suse/llvm17&distro=SUSE%20Package%20Hub%2015%20SP5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
17.0.6-bp155.2.2

Ecosystem specific

{
    "binaries": [
        {
            "lld17": "17.0.6-bp155.2.2",
            "libclang-cpp17-64bit": "17.0.6-bp155.2.2",
            "clang17-devel": "17.0.6-bp155.2.2",
            "llvm17-vim-plugins": "17.0.6-bp155.2.2",
            "libclang-cpp17-32bit": "17.0.6-bp155.2.2",
            "libLLVM17-64bit": "17.0.6-bp155.2.2",
            "clang17": "17.0.6-bp155.2.2",
            "clang17-doc": "17.0.6-bp155.2.2",
            "python3-clang17": "17.0.6-bp155.2.2",
            "llvm17-gold": "17.0.6-bp155.2.2",
            "llvm17-libclang13": "17.0.6-bp155.2.2",
            "python3-lldb17": "17.0.6-bp155.2.2",
            "llvm17-doc": "17.0.6-bp155.2.2",
            "llvm17-polly": "17.0.6-bp155.2.2",
            "libLTO17": "17.0.6-bp155.2.2",
            "llvm17-libc++-devel": "17.0.6-bp155.2.2",
            "lldb17-devel": "17.0.6-bp155.2.2",
            "lldb17": "17.0.6-bp155.2.2",
            "llvm17-libc++abi1": "17.0.6-bp155.2.2",
            "llvm17": "17.0.6-bp155.2.2",
            "libomp17-devel": "17.0.6-bp155.2.2",
            "llvm17-libc++abi-devel": "17.0.6-bp155.2.2",
            "libclang-cpp17": "17.0.6-bp155.2.2",
            "llvm17-libc++1": "17.0.6-bp155.2.2",
            "llvm17-devel": "17.0.6-bp155.2.2",
            "llvm17-opt-viewer": "17.0.6-bp155.2.2",
            "llvm17-polly-devel": "17.0.6-bp155.2.2",
            "chromedriver": "122.0.6261.128-bp155.2.75.1",
            "chromium": "122.0.6261.128-bp155.2.75.1",
            "liblldb17": "17.0.6-bp155.2.2",
            "libLLVM17-32bit": "17.0.6-bp155.2.2",
            "libLLVM17": "17.0.6-bp155.2.2"
        }
    ]
}

openSUSE:Leap 15.5 / chromium

Package

Name
chromium
Purl
pkg:rpm/opensuse/chromium&distro=openSUSE%20Leap%2015.5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
122.0.6261.128-bp155.2.75.1

Ecosystem specific

{
    "binaries": [
        {
            "lld17": "17.0.6-bp155.2.2",
            "libclang-cpp17-64bit": "17.0.6-bp155.2.2",
            "clang17-devel": "17.0.6-bp155.2.2",
            "llvm17-vim-plugins": "17.0.6-bp155.2.2",
            "libclang-cpp17-32bit": "17.0.6-bp155.2.2",
            "libLLVM17-64bit": "17.0.6-bp155.2.2",
            "clang17": "17.0.6-bp155.2.2",
            "clang17-doc": "17.0.6-bp155.2.2",
            "python3-clang17": "17.0.6-bp155.2.2",
            "llvm17-gold": "17.0.6-bp155.2.2",
            "llvm17-libclang13": "17.0.6-bp155.2.2",
            "python3-lldb17": "17.0.6-bp155.2.2",
            "llvm17-doc": "17.0.6-bp155.2.2",
            "llvm17-polly": "17.0.6-bp155.2.2",
            "libLTO17": "17.0.6-bp155.2.2",
            "llvm17-libc++-devel": "17.0.6-bp155.2.2",
            "lldb17-devel": "17.0.6-bp155.2.2",
            "lldb17": "17.0.6-bp155.2.2",
            "llvm17-libc++abi1": "17.0.6-bp155.2.2",
            "llvm17": "17.0.6-bp155.2.2",
            "libomp17-devel": "17.0.6-bp155.2.2",
            "llvm17-libc++abi-devel": "17.0.6-bp155.2.2",
            "libclang-cpp17": "17.0.6-bp155.2.2",
            "llvm17-libc++1": "17.0.6-bp155.2.2",
            "llvm17-devel": "17.0.6-bp155.2.2",
            "llvm17-opt-viewer": "17.0.6-bp155.2.2",
            "llvm17-polly-devel": "17.0.6-bp155.2.2",
            "chromedriver": "122.0.6261.128-bp155.2.75.1",
            "chromium": "122.0.6261.128-bp155.2.75.1",
            "liblldb17": "17.0.6-bp155.2.2",
            "libLLVM17-32bit": "17.0.6-bp155.2.2",
            "libLLVM17": "17.0.6-bp155.2.2"
        }
    ]
}

openSUSE:Leap 15.5 / llvm17

Package

Name
llvm17
Purl
pkg:rpm/opensuse/llvm17&distro=openSUSE%20Leap%2015.5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
17.0.6-bp155.2.2

Ecosystem specific

{
    "binaries": [
        {
            "lld17": "17.0.6-bp155.2.2",
            "libclang-cpp17-64bit": "17.0.6-bp155.2.2",
            "clang17-devel": "17.0.6-bp155.2.2",
            "llvm17-vim-plugins": "17.0.6-bp155.2.2",
            "libclang-cpp17-32bit": "17.0.6-bp155.2.2",
            "libLLVM17-64bit": "17.0.6-bp155.2.2",
            "clang17": "17.0.6-bp155.2.2",
            "clang17-doc": "17.0.6-bp155.2.2",
            "python3-clang17": "17.0.6-bp155.2.2",
            "llvm17-gold": "17.0.6-bp155.2.2",
            "llvm17-libclang13": "17.0.6-bp155.2.2",
            "python3-lldb17": "17.0.6-bp155.2.2",
            "llvm17-doc": "17.0.6-bp155.2.2",
            "llvm17-polly": "17.0.6-bp155.2.2",
            "libLTO17": "17.0.6-bp155.2.2",
            "llvm17-libc++-devel": "17.0.6-bp155.2.2",
            "lldb17-devel": "17.0.6-bp155.2.2",
            "lldb17": "17.0.6-bp155.2.2",
            "llvm17-libc++abi1": "17.0.6-bp155.2.2",
            "llvm17": "17.0.6-bp155.2.2",
            "libomp17-devel": "17.0.6-bp155.2.2",
            "llvm17-libc++abi-devel": "17.0.6-bp155.2.2",
            "libclang-cpp17": "17.0.6-bp155.2.2",
            "llvm17-libc++1": "17.0.6-bp155.2.2",
            "llvm17-devel": "17.0.6-bp155.2.2",
            "llvm17-opt-viewer": "17.0.6-bp155.2.2",
            "llvm17-polly-devel": "17.0.6-bp155.2.2",
            "chromedriver": "122.0.6261.128-bp155.2.75.1",
            "chromium": "122.0.6261.128-bp155.2.75.1",
            "liblldb17": "17.0.6-bp155.2.2",
            "libLLVM17-32bit": "17.0.6-bp155.2.2",
            "libLLVM17": "17.0.6-bp155.2.2"
        }
    ]
}