openSUSE Security Update: Security update for chromium ______________________________________________________________________________ Announcement ID: openSUSE-SU-2021:1339-1 Rating: important References: #1190765 #1191166 #1191204 Cross-References: CVE-2021-37956 CVE-2021-37957 CVE-2021-37958 CVE-2021-37959 CVE-2021-37960 CVE-2021-37961 CVE-2021-37962 CVE-2021-37963 CVE-2021-37964 CVE-2021-37965 CVE-2021-37966 CVE-2021-37967 CVE-2021-37968 CVE-2021-37969 CVE-2021-37970 CVE-2021-37971 CVE-2021-37972 CVE-2021-37973 CVE-2021-37974 CVE-2021-37975 CVE-2021-37976 Affected Products: openSUSE Backports SLE-15-SP3 ______________________________________________________________________________ An update that fixes 21 vulnerabilities is now available. Description: This update for chromium fixes the following issues: Chromium 94.0.4606.54 (boo#1190765): * CVE-2021-37956: Use after free in Offline use * CVE-2021-37957: Use after free in WebGPU * CVE-2021-37958: Inappropriate implementation in Navigation * CVE-2021-37959: Use after free in Task Manager * CVE-2021-37960: Inappropriate implementation in Blink graphics * CVE-2021-37961: Use after free in Tab Strip * CVE-2021-37962: Use after free in Performance Manager * CVE-2021-37963: Side-channel information leakage in DevTools * CVE-2021-37964: Inappropriate implementation in ChromeOS Networking * CVE-2021-37965: Inappropriate implementation in Background Fetch API * CVE-2021-37966: Inappropriate implementation in Compositing * CVE-2021-37967: Inappropriate implementation in Background Fetch API * CVE-2021-37968: Inappropriate implementation in Background Fetch API * CVE-2021-37969: Inappropriate implementation in Google Updater * CVE-2021-37970: Use after free in File System API * CVE-2021-37971: Incorrect security UI in Web Browser UI * CVE-2021-37972: Out of bounds read in libjpeg-turbo Chromium 94.0.4606.61 (boo#1191166): * CVE-2021-37973: Use after free in Portals Chromium 94.0.4606.71 (boo#1191204): * CVE-2021-37974 : Use after free in Safe Browsing * CVE-2021-37975 : Use after free in V8 * CVE-2021-37976 : Information leak in core Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP3: zypper in -t patch openSUSE-2021-1339=1 Package List: - openSUSE Backports SLE-15-SP3 (aarch64 x86_64): chromedriver-94.0.4606.71-bp153.2.31.1 chromium-94.0.4606.71-bp153.2.31.1 References: https://www.suse.com/security/cve/CVE-2021-37956.html https://www.suse.com/security/cve/CVE-2021-37957.html https://www.suse.com/security/cve/CVE-2021-37958.html https://www.suse.com/security/cve/CVE-2021-37959.html https://www.suse.com/security/cve/CVE-2021-37960.html https://www.suse.com/security/cve/CVE-2021-37961.html https://www.suse.com/security/cve/CVE-2021-37962.html https://www.suse.com/security/cve/CVE-2021-37963.html https://www.suse.com/security/cve/CVE-2021-37964.html https://www.suse.com/security/cve/CVE-2021-37965.html https://www.suse.com/security/cve/CVE-2021-37966.html https://www.suse.com/security/cve/CVE-2021-37967.html https://www.suse.com/security/cve/CVE-2021-37968.html https://www.suse.com/security/cve/CVE-2021-37969.html https://www.suse.com/security/cve/CVE-2021-37970.html https://www.suse.com/security/cve/CVE-2021-37971.html https://www.suse.com/security/cve/CVE-2021-37972.html https://www.suse.com/security/cve/CVE-2021-37973.html https://www.suse.com/security/cve/CVE-2021-37974.html https://www.suse.com/security/cve/CVE-2021-37975.html https://www.suse.com/security/cve/CVE-2021-37976.html https://bugzilla.suse.com/1190765 https://bugzilla.suse.com/1191166 https://bugzilla.suse.com/1191204