Fedora alert FEDORA-2026-2debc85b3c (chromium)
| From: | updates--- via package-announce <package-announce@lists.fedoraproject.org> | |
| To: | package-announce@lists.fedoraproject.org | |
| Subject: | [SECURITY] Fedora 44 Update: chromium-149.0.7827.102-1.fc44 | |
| Date: | Sat, 13 Jun 2026 01:13:33 +0000 | |
| Message-ID: | <20260613011333.5C93476632@bastion01.rdu3.fedoraproject.org> | |
| Archive-link: | Article |
-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-2debc85b3c 2026-06-13 01:09:32.029747+00:00 -------------------------------------------------------------------------------- Name : chromium Product : Fedora 44 Version : 149.0.7827.102 Release : 1.fc44 URL : http://www.chromium.org/Home Summary : A WebKit (Blink) powered web browser that Google doesn't want you to use Description : Chromium is an open-source web browser, powered by WebKit (Blink). -------------------------------------------------------------------------------- Update Information: Update to 149.0.7827.102 CVE-2026-11628: Use after free in Ozone CVE-2026-11629: Use after free in Ozone CVE-2026-11630: Use after free in File Input CVE-2026-11631: Use after free in Aura CVE-2026-11632: Use after free in TabStrip CVE-2026-11633: Use after free in Bluetooth CVE-2026-11634: Use after free in Gamepad CVE-2026-11635: Use after free in Bluetooth CVE-2026-11636: Use after free in Autofill CVE-2026-11637: Use after free in Views CVE-2026-11638: Use after free in Printing CVE-2026-11639: Use after free in Compositing CVE-2026-11640: Integer overflow in libyuv CVE-2026-11641: Use after free in Bluetooth CVE-2026-11642: Use after free in Web Apps CVE-2026-11643: Use after free in Proxy CVE-2026-11644: Use after free in Views CVE-2026-11645: Out of bounds memory access in V8 CVE-2026-11646: Use after free in ViewTransitions CVE-2026-11647: Use after free in Printing CVE-2026-11648: Use after free in FullScreen CVE-2026-11649: Use after free in V8 CVE-2026-11650: Use after free in V8 CVE-2026-11651: Use after free in Network CVE-2026-11652: Use after free in Extensions CVE-2026-11653: Insufficient validation of untrusted input in Extensions CVE-2026-11654: Use after free in CameraCapture CVE-2026-11655: Integer overflow in Media CVE-2026-11656: Use after free in ServiceWorker CVE-2026-11657: Use after free in Payments CVE-2026-11658: Insufficient validation of untrusted input in Extensions CVE-2026-11659: Insufficient validation of untrusted input in UI CVE-2026-11660: Insufficient validation of untrusted input in New Tab Page CVE-2026-11661: Use after free in Views CVE-2026-11662: Type Confusion in Bindings CVE-2026-11663: Use after free in Skia CVE-2026-11664: Use after free in Payments CVE-2026-11665: Out of bounds read in Dawn CVE-2026-11666: Insufficient validation of untrusted input in Input CVE-2026-11667: Out of bounds read in WebRTC CVE-2026-11668: Uninitialized Use in Codecs CVE-2026-11669: Integer overflow in Media CVE-2026-11670: Use after free in PDF CVE-2026-11671: Use after free in Navigation CVE-2026-11672: Out of bounds write in GPU CVE-2026-11673: Use after free in InterestGroups CVE-2026-11674: Use after free in Guest View CVE-2026-11675: Insufficient validation of untrusted input in Skia CVE-2026-11676: Insufficient validation of untrusted input in Dawn CVE-2026-11677: Race in Network CVE-2026-11678: Integer overflow in libyuv CVE-2026-11679: Use after free in Codecs CVE-2026-11680: Use after free in Media CVE-2026-11681: Use after free in Ozone CVE-2026-11682: Insufficient validation of untrusted input in Views CVE-2026-11683: Use after free in WebCodecs CVE-2026-11684: Insufficient policy enforcement in Network CVE-2026-11685: Insufficient data validation in MediaCapture CVE-2026-11686: Insufficient validation of untrusted input in Dawn CVE-2026-11687: Use after free in Dawn CVE-2026-11688: Object lifecycle issue in SVG CVE-2026-11689: Insufficient validation of untrusted input in Passwords CVE-2026-11690: Out of bounds read and write in Media CVE-2026-11691: Insufficient validation of untrusted input in New Tab Page CVE-2026-11692: Use after free in Read Anything CVE-2026-11693: Inappropriate implementation in Plugins CVE-2026-11694: Use after free in ServiceWorker CVE-2026-11695: Inappropriate implementation in Passwords CVE-2026-11696: Uninitialized Use in Video CVE-2026-11697: Insufficient validation of untrusted input in UI CVE-2026-11698: Use after free in Bluetooth CVE-2026-11699: Use after free in Bluetooth CVE-2026-11700: Use after free in Tracing CVE-2026-11701: Insufficient validation of untrusted input in Guest View -------------------------------------------------------------------------------- ChangeLog: * Tue Jun 9 2026 Than Ngo <than@redhat.com> - 149.0.7827.102-1 - Update to 149.0.7827.102 * CVE-2026-11628: Use after free in Ozone * CVE-2026-11629: Use after free in Ozone * CVE-2026-11630: Use after free in File Input * CVE-2026-11631: Use after free in Aura * CVE-2026-11632: Use after free in TabStrip * CVE-2026-11633: Use after free in Bluetooth * CVE-2026-11634: Use after free in Gamepad * CVE-2026-11635: Use after free in Bluetooth * CVE-2026-11636: Use after free in Autofill * CVE-2026-11637: Use after free in Views * CVE-2026-11638: Use after free in Printing * CVE-2026-11639: Use after free in Compositing * CVE-2026-11640: Integer overflow in libyuv * CVE-2026-11641: Use after free in Bluetooth * CVE-2026-11642: Use after free in Web Apps * CVE-2026-11643: Use after free in Proxy * CVE-2026-11644: Use after free in Views * CVE-2026-11645: Out of bounds memory access in V8 * CVE-2026-11646: Use after free in ViewTransitions * CVE-2026-11647: Use after free in Printing * CVE-2026-11648: Use after free in FullScreen * CVE-2026-11649: Use after free in V8 * CVE-2026-11650: Use after free in V8 * CVE-2026-11651: Use after free in Network * CVE-2026-11652: Use after free in Extensions * CVE-2026-11653: Insufficient validation of untrusted input in Extensions * CVE-2026-11654: Use after free in CameraCapture * CVE-2026-11655: Integer overflow in Media * CVE-2026-11656: Use after free in ServiceWorker * CVE-2026-11657: Use after free in Payments * CVE-2026-11658: Insufficient validation of untrusted input in Extensions * CVE-2026-11659: Insufficient validation of untrusted input in UI * CVE-2026-11660: Insufficient validation of untrusted input in New Tab Page * CVE-2026-11661: Use after free in Views * CVE-2026-11662: Type Confusion in Bindings * CVE-2026-11663: Use after free in Skia * CVE-2026-11664: Use after free in Payments * CVE-2026-11665: Out of bounds read in Dawn * CVE-2026-11666: Insufficient validation of untrusted input in Input * CVE-2026-11667: Out of bounds read in WebRTC * CVE-2026-11668: Uninitialized Use in Codecs * CVE-2026-11669: Integer overflow in Media * CVE-2026-11670: Use after free in PDF * CVE-2026-11671: Use after free in Navigation * CVE-2026-11672: Out of bounds write in GPU * CVE-2026-11673: Use after free in InterestGroups * CVE-2026-11674: Use after free in Guest View * CVE-2026-11675: Insufficient validation of untrusted input in Skia * CVE-2026-11676: Insufficient validation of untrusted input in Dawn * CVE-2026-11677: Race in Network * CVE-2026-11678: Integer overflow in libyuv * CVE-2026-11679: Use after free in Codecs * CVE-2026-11680: Use after free in Media * CVE-2026-11681: Use after free in Ozone * CVE-2026-11682: Insufficient validation of untrusted input in Views * CVE-2026-11683: Use after free in WebCodecs * CVE-2026-11684: Insufficient policy enforcement in Network * CVE-2026-11685: Insufficient data validation in MediaCapture * CVE-2026-11686: Insufficient validation of untrusted input in Dawn * CVE-2026-11687: Use after free in Dawn * CVE-2026-11688: Object lifecycle issue in SVG * CVE-2026-11689: Insufficient validation of untrusted input in Passwords * CVE-2026-11690: Out of bounds read and write in Media * CVE-2026-11691: Insufficient validation of untrusted input in New Tab Page * CVE-2026-11692: Use after free in Read Anything * CVE-2026-11693: Inappropriate implementation in Plugins * CVE-2026-11694: Use after free in ServiceWorker * CVE-2026-11695: Inappropriate implementation in Passwords * CVE-2026-11696: Uninitialized Use in Video * CVE-2026-11697: Insufficient validation of untrusted input in UI * CVE-2026-11698: Use after free in Bluetooth * CVE-2026-11699: Use after free in Bluetooth * CVE-2026-11700: Use after free in Tracing * CVE-2026-11701: Insufficient validation of untrusted input in Guest View - Refresh ppc64le patches -------------------------------------------------------------------------------- References: [ 1 ] Bug #2483935 - Remove setuid bit from chromium-browser's chrome-sandbox (now relies on namespaces) https://bugzilla.redhat.com/show_bug.cgi?id=2483935 [ 2 ] Bug #2486052 - CVE-2026-10881 CVE-2026-10882 CVE-2026-10883 CVE-2026-10884 CVE-2026-10885 CVE-2026-10886 CVE-2026-10887 CVE-2026-10888 CVE-2026-10889 CVE-2026-10890 CVE-2026-10891 CVE-2026-10892 CVE-2026-10893 CVE-2026-10894 ... chromium: various flaws [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2486052 [ 3 ] Bug #2487620 - CVE-2026-11628 CVE-2026-11629 CVE-2026-11630 CVE-2026-11631 CVE-2026-11632 CVE-2026-11633 CVE-2026-11634 CVE-2026-11635 CVE-2026-11636 CVE-2026-11637 CVE-2026-11638 CVE-2026-11639 CVE-2026-11640 CVE-2026-11641 ... chromium: various flaws [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2487620 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-2debc85b3c' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgr... All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- package-announce@lists.fedoraproject.org To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-cond... List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/package-ann... Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
