Fedora Linux 8772 Published by

Fedora Linux has received security updates for chromium and golang-github-nvidia-container-toolkit:

Fedora 41 Update: chromium-130.0.6723.116-1.fc41
Fedora 41 Update: golang-github-nvidia-container-toolkit-1.16.2-1.fc41
Fedora 40 Update: chromium-130.0.6723.116-1.fc40
Fedora 40 Update: golang-github-nvidia-container-toolkit-1.16.2-1.fc40




[SECURITY] Fedora 41 Update: chromium-130.0.6723.116-1.fc41


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2024-1e45ea2e6c
2024-11-13 03:11:38.048267
--------------------------------------------------------------------------------

Name : chromium
Product : Fedora 41
Version : 130.0.6723.116
Release : 1.fc41
URL : http://www.chromium.org/Home
Summary : A WebKit (Blink) powered web browser that Google doesn't want you to use
Description :
Chromium is an open-source web browser, powered by WebKit (Blink).

--------------------------------------------------------------------------------
Update Information:

Update to 130.0.6723.116
--------------------------------------------------------------------------------
ChangeLog:

* Sun Nov 10 2024 Than Ngo [than@redhat.com] - 130.0.6723.116-1
- Update to 130.0.6723.116
* High CVE-2024-10826: Use after free in Family Experience
* High CVE-2024-10827: Use after free in Serial
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2324200 - CVE-2024-10827 chromium: Use after free in Serial [epel-8]
https://bugzilla.redhat.com/show_bug.cgi?id=2324200
[ 2 ] Bug #2324201 - CVE-2024-10827 chromium: Use after free in Serial [epel-9]
https://bugzilla.redhat.com/show_bug.cgi?id=2324201
[ 3 ] Bug #2324202 - CVE-2024-10827 chromium: Use after free in Serial [fedora-39]
https://bugzilla.redhat.com/show_bug.cgi?id=2324202
[ 4 ] Bug #2324203 - CVE-2024-10827 chromium: Use after free in Serial [fedora-40]
https://bugzilla.redhat.com/show_bug.cgi?id=2324203
[ 5 ] Bug #2324204 - CVE-2024-10827 chromium: Use after free in Serial [fedora-41]
https://bugzilla.redhat.com/show_bug.cgi?id=2324204
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2024-1e45ea2e6c' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------

--



[SECURITY] Fedora 41 Update: golang-github-nvidia-container-toolkit-1.16.2-1.fc41


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2024-cd6112750e
2024-11-13 03:11:38.048220
--------------------------------------------------------------------------------

Name : golang-github-nvidia-container-toolkit
Product : Fedora 41
Version : 1.16.2
Release : 1.fc41
URL : https://github.com/NVIDIA/nvidia-container-toolkit
Summary : Build and run containers leveraging NVIDIA GPUs
Description :
The NVIDIA Container Toolkit allows users to build and run NVIDIA GPU
accelerated containers. The toolkit includes a container runtime library and
utilities to automatically configure containers to leverage NVIDIA GPUs.

--------------------------------------------------------------------------------
Update Information:

Update to 1.16.2
Fixes CVE-2024-0132 or GHSA-mjjw-553x-87pq, and CVE-2024-0133 or
GHSA-f748-7hpg-88ch
--------------------------------------------------------------------------------
ChangeLog:

* Thu Oct 31 2024 Debarshi Ray [rishi@fedoraproject.org] - 1.16.2-1
- Update to 1.16.2
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2024-cd6112750e' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------

--



[SECURITY] Fedora 40 Update: chromium-130.0.6723.116-1.fc40


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2024-011c4d53e5
2024-11-13 02:58:44.846824
--------------------------------------------------------------------------------

Name : chromium
Product : Fedora 40
Version : 130.0.6723.116
Release : 1.fc40
URL : http://www.chromium.org/Home
Summary : A WebKit (Blink) powered web browser that Google doesn't want you to use
Description :
Chromium is an open-source web browser, powered by WebKit (Blink).

--------------------------------------------------------------------------------
Update Information:

Update to 130.0.6723.116
--------------------------------------------------------------------------------
ChangeLog:

* Sun Nov 10 2024 Than Ngo [than@redhat.com] - 130.0.6723.116-1
- Update to 130.0.6723.116
* High CVE-2024-10826: Use after free in Family Experience
* High CVE-2024-10827: Use after free in Serial
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2324200 - CVE-2024-10827 chromium: Use after free in Serial [epel-8]
https://bugzilla.redhat.com/show_bug.cgi?id=2324200
[ 2 ] Bug #2324201 - CVE-2024-10827 chromium: Use after free in Serial [epel-9]
https://bugzilla.redhat.com/show_bug.cgi?id=2324201
[ 3 ] Bug #2324202 - CVE-2024-10827 chromium: Use after free in Serial [fedora-39]
https://bugzilla.redhat.com/show_bug.cgi?id=2324202
[ 4 ] Bug #2324203 - CVE-2024-10827 chromium: Use after free in Serial [fedora-40]
https://bugzilla.redhat.com/show_bug.cgi?id=2324203
[ 5 ] Bug #2324204 - CVE-2024-10827 chromium: Use after free in Serial [fedora-41]
https://bugzilla.redhat.com/show_bug.cgi?id=2324204
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2024-011c4d53e5' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------

--



[SECURITY] Fedora 40 Update: golang-github-nvidia-container-toolkit-1.16.2-1.fc40


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2024-8c218846ee
2024-11-13 02:58:44.846802
--------------------------------------------------------------------------------

Name : golang-github-nvidia-container-toolkit
Product : Fedora 40
Version : 1.16.2
Release : 1.fc40
URL : https://github.com/NVIDIA/nvidia-container-toolkit
Summary : Build and run containers leveraging NVIDIA GPUs
Description :
The NVIDIA Container Toolkit allows users to build and run NVIDIA GPU
accelerated containers. The toolkit includes a container runtime library and
utilities to automatically configure containers to leverage NVIDIA GPUs.

--------------------------------------------------------------------------------
Update Information:

Update to 1.16.2
Fixes CVE-2024-0132 or GHSA-mjjw-553x-87pq, and CVE-2024-0133 or
GHSA-f748-7hpg-88ch
--------------------------------------------------------------------------------
ChangeLog:

* Thu Oct 31 2024 Debarshi Ray [rishi@fedoraproject.org] - 1.16.2-1
- Update to 1.16.2
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2024-8c218846ee' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------

--