stable

chromium-131.0.6778.85-2.fc40

FEDORA-2024-292aa2c246 created by than 2 months ago for Fedora 40

Update to 131.0.6778.85

  * High CVE-2024-11395: Type Confusion in V8
  * High CVE-2024-11110: Inappropriate implementation in Blink
  * Medium CVE-2024-11111: Inappropriate implementation in Autofill
  * Medium CVE-2024-11112: Use after free in Media
  * Medium CVE-2024-11113: Use after free in Accessibility
  * Medium CVE-2024-11114: Inappropriate implementation in Views
  * Medium CVE-2024-11115: Insufficient policy enforcement in Navigation
  * Medium CVE-2024-11116: Inappropriate implementation in Paint
  * Low CVE-2024-11117: Inappropriate implementation in FileSystem

How to install

Updates may require up to 24 hours to propagate to mirrors. If the following command doesn't work, please retry later:

sudo dnf upgrade --refresh --advisory=FEDORA-2024-292aa2c246

This update has been submitted for testing by than.

2 months ago

This update's test gating status has been changed to 'ignored'.

2 months ago

than edited this update.

2 months ago
User Icon imabug commented & provided feedback 2 months ago
karma

Getting this error during the upgrade

Problem: problem with installed package
- package chromium-qt6-ui-130.0.6723.116-1.fc40.x86_64 requires chromium(x86-64) = 130.0.6723.116-1.fc40, but none of the providers can be installed
- cannot install both chromium-130.0.6723.116-1.fc40.x86_64 and chromium-131.0.6778.85-1.fc40.x86_64
- cannot install the best update candidate for package chromium-130.0.6723.116-1.fc40.x86_64

Bodhi is disabling automatic push to stable due to negative karma. The maintainer may push manually if they determine that the issue is not severe.

2 months ago
User Icon than commented & provided feedback 2 months ago

I have realised that chromium-qt[5|6]-ui subpacke is missing in the update. Quick workaround is to delete chromium-qt6-ui before update to new version.

I will fix it in next build.

This update has been pushed to testing.

2 months ago
User Icon jannau commented & provided feedback a month ago
karma

Crashes randomly on aarch64 systems with a page size larger than 4kb (for example Apple silicon systems running Fedora Asahi Remix). Upstream issue is in https://issues.chromium.org/issues/378017037 (access restricted). It is supposedly fixed by reverting https://chromium-review.googlesource.com/c/v8/v8/+/5864909 Also tracked publicly for brave-browser in https://github.com/brave/brave-browser/issues/42315

karma
karma
User Icon than commented & provided feedback a month ago

There's is new build https://koji.fedoraproject.org/koji/taskinfo?taskID=126172832 that should solve the 2 problems reported above

than edited this update.

New build(s):

  • chromium-131.0.6778.85-2.fc40

Removed build(s):

  • chromium-131.0.6778.85-1.fc40

Karma has been reset.

a month ago

This update has been submitted for testing by than.

a month ago
User Icon jannau commented & provided feedback a month ago
karma

crashes on apple silicon systems are no longer reproducible with chromium-131.0.6778.85-2.fc40. thanks

karma

than edited this update.

a month ago

This update has been pushed to testing.

a month ago

This update has been submitted for stable by bodhi.

a month ago

This update has been pushed to stable.

a month ago

Please login to add feedback.

Metadata
Type
security
Severity
high
Karma
2
Signed
Content Type
RPM
Test Gating
Autopush Settings
Unstable by Karma
-3
Stable by Karma
2
Stable by Time
7 days
Dates
submitted
2 months ago
in testing
a month ago
in stable
a month ago
modified
a month ago
approved
a month ago
BZ#2325761 CVE-2024-11110 chromium: Inappropriate implementation in Extensions [epel-all]
0
0
BZ#2325762 CVE-2024-11110 chromium: Inappropriate implementation in Extensions [fedora-all]
0
0
BZ#2325763 CVE-2024-11111 chromium: Inappropriate implementation in Autofill [epel-all]
0
0
BZ#2325764 CVE-2024-11111 chromium: Inappropriate implementation in Autofill [fedora-all]
0
0
BZ#2325765 CVE-2024-11113 chromium: Use after free in Accessibility [epel-all]
0
0
BZ#2325766 CVE-2024-11113 chromium: Use after free in Accessibility [fedora-all]
0
0
BZ#2325767 CVE-2024-11116 chromium: Inappropriate implementation in Blink [epel-all]
0
0
BZ#2325768 CVE-2024-11116 chromium: Inappropriate implementation in Blink [fedora-all]
0
0
BZ#2325769 CVE-2024-11117 chromium: Inappropriate implementation in FileSystem [epel-all]
0
0
BZ#2325770 CVE-2024-11117 chromium: Inappropriate implementation in FileSystem [fedora-all]
0
0
BZ#2327554 CVE-2024-11395 chromium: Type Confusion in V8 [epel-all]
0
0
BZ#2327555 CVE-2024-11395 chromium: Type Confusion in V8 [fedora-all]
0
0

Automated Test Results