openSUSE-SU-2021:1339-1: important: Security update for chromium
openSUSE Security Update: Security update for chromium
______________________________________________________________________________
Announcement ID: openSUSE-SU-2021:1339-1
Rating: important
References: #1190765 #1191166 #1191204
Cross-References: CVE-2021-37956 CVE-2021-37957 CVE-2021-37958
CVE-2021-37959 CVE-2021-37960 CVE-2021-37961
CVE-2021-37962 CVE-2021-37963 CVE-2021-37964
CVE-2021-37965 CVE-2021-37966 CVE-2021-37967
CVE-2021-37968 CVE-2021-37969 CVE-2021-37970
CVE-2021-37971 CVE-2021-37972 CVE-2021-37973
CVE-2021-37974 CVE-2021-37975 CVE-2021-37976
Affected Products:
openSUSE Backports SLE-15-SP3
______________________________________________________________________________
An update that fixes 21 vulnerabilities is now available.
Description:
This update for chromium fixes the following issues:
Chromium 94.0.4606.54 (boo#1190765):
* CVE-2021-37956: Use after free in Offline use
* CVE-2021-37957: Use after free in WebGPU
* CVE-2021-37958: Inappropriate implementation in Navigation
* CVE-2021-37959: Use after free in Task Manager
* CVE-2021-37960: Inappropriate implementation in Blink graphics
* CVE-2021-37961: Use after free in Tab Strip
* CVE-2021-37962: Use after free in Performance Manager
* CVE-2021-37963: Side-channel information leakage in DevTools
* CVE-2021-37964: Inappropriate implementation in ChromeOS Networking
* CVE-2021-37965: Inappropriate implementation in Background Fetch API
* CVE-2021-37966: Inappropriate implementation in Compositing
* CVE-2021-37967: Inappropriate implementation in Background Fetch API
* CVE-2021-37968: Inappropriate implementation in Background Fetch API
* CVE-2021-37969: Inappropriate implementation in Google Updater
* CVE-2021-37970: Use after free in File System API
* CVE-2021-37971: Incorrect security UI in Web Browser UI
* CVE-2021-37972: Out of bounds read in libjpeg-turbo
Chromium 94.0.4606.61 (boo#1191166):
* CVE-2021-37973: Use after free in Portals
Chromium 94.0.4606.71 (boo#1191204):
* CVE-2021-37974 : Use after free in Safe Browsing
* CVE-2021-37975 : Use after free in V8
* CVE-2021-37976 : Information leak in core
Patch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Backports SLE-15-SP3:
zypper in -t patch openSUSE-2021-1339=1
Package List:
- openSUSE Backports SLE-15-SP3 (aarch64 x86_64):
chromedriver-94.0.4606.71-bp153.2.31.1
chromium-94.0.4606.71-bp153.2.31.1
References:
https://www.suse.com/security/cve/CVE-2021-37956.html
https://www.suse.com/security/cve/CVE-2021-37957.html
https://www.suse.com/security/cve/CVE-2021-37958.html
https://www.suse.com/security/cve/CVE-2021-37959.html
https://www.suse.com/security/cve/CVE-2021-37960.html
https://www.suse.com/security/cve/CVE-2021-37961.html
https://www.suse.com/security/cve/CVE-2021-37962.html
https://www.suse.com/security/cve/CVE-2021-37963.html
https://www.suse.com/security/cve/CVE-2021-37964.html
https://www.suse.com/security/cve/CVE-2021-37965.html
https://www.suse.com/security/cve/CVE-2021-37966.html
https://www.suse.com/security/cve/CVE-2021-37967.html
https://www.suse.com/security/cve/CVE-2021-37968.html
https://www.suse.com/security/cve/CVE-2021-37969.html
https://www.suse.com/security/cve/CVE-2021-37970.html
https://www.suse.com/security/cve/CVE-2021-37971.html
https://www.suse.com/security/cve/CVE-2021-37972.html
https://www.suse.com/security/cve/CVE-2021-37973.html
https://www.suse.com/security/cve/CVE-2021-37974.html
https://www.suse.com/security/cve/CVE-2021-37975.html
https://www.suse.com/security/cve/CVE-2021-37976.html
https://bugzilla.suse.com/1190765
https://bugzilla.suse.com/1191166
https://bugzilla.suse.com/1191204
A chromium security update has been released for SUSE Linux Enterprise 15 SP3.