Chromium 140.0.7339.80 boo#1249093 #2
Reference in New Issue
Block a user
Delete Branch ":leap-16.0"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Chromium 140 / 140.0.7339.80 boo#1249093
- Chromium 127.0.6533.119 * CVE-2024-7532: Out of bounds memory access in ANGLE * CVE-2024-7533: Use after free in Sharing * CVE-2024-7550: Type Confusion in V8 * CVE-2024-7534: Heap buffer overflow in Layout * CVE-2024-7535: Inappropriate implementation in V8 * CVE-2024-7536: Use after free in WebAudio - Chromium 127.0.6533.88 * CVE-2024-6988: Use after free in Downloads * CVE-2024-6989: Use after free in Loader * CVE-2024-6991: Use after free in Dawn * CVE-2024-6992: Out of bounds memory access in ANGLE * CVE-2024-6993: Inappropriate implementation in Canvas * CVE-2024-6994: Heap buffer overflow in Layout * CVE-2024-6995: Inappropriate implementation in Fullscreen * CVE-2024-6996: Race in Frames * CVE-2024-6997: Use after free in Tabs * CVE-2024-6998: Use after free in User Education * CVE-2024-6999: Inappropriate implementation in FedCM * CVE-2024-7000: Use after free in CSS. Reported by Anonymous * CVE-2024-7001: Inappropriate implementation in HTML * CVE-2024-7003: Inappropriate implementation in FedCM * CVE-2024-7004: Insufficient validation of untrusted input in Safe Browsing * CVE-2024-7005: Insufficient validation of untrusted input in Safe Browsing * CVE-2024-6990: Uninitialized Use in Dawn * CVE-2024-7255: Out of bounds read in WebTransport * CVE-2024-7256: Insufficient data validation in Dawn OBS-URL: https://build.opensuse.org/request/show/1194297 OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=48- Chromium 128.0.6613.36 (current beta release) - modified patches: * chromium-norar.patch drop most hunks, upstream has a config for this now * gcc-enable-lto.patch update context * chromium-125-compiler.patch update context * chromium-127-constexpr.patch update context - drop patches: (should be obsolete with llvm>17 and libc++) chromium-120-emplace.patch chromium-125-emplace-struct.patch - drop patches: (upstream) * chromium-121-nullptr_t-without-namespace-std.patch * chromium-123-stats-collector.patch * chromium-127-paint-layer-header.patch * chromium-127-ninja-1.21.1-deps-part0.patch * chromium-127-ninja-1.21.1-deps-part1.patch * chromium-127-ninja-1.21.1-deps-part2.patch * chromium-127-ninja-1.21.1-deps-part3.patch - disable rpmlint only for factory/tw where it is broken because of the large archive size of the source here - keeplibs add third_party/devtools-frontend/src/front_end/third_party/ puppeteer/package/lib/esm/third_party/parsel-js third_party/tflite/src/third_party/xla/xla/tsl/framework - buildflags add safe_browsing_use_unrar=false OBS-URL: https://build.opensuse.org/request/show/1195041 OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=50- dropped patches: * chromium-disable-GlobalMediaControlsCastStartStop.patch it was applied at the wrong place and the crash is gone OBS-URL: https://build.opensuse.org/package/show/home:oertel:branches:network:chromium/chromium-beta?expand=0&rev=12* chromium-130-missing-include.patch include optional - bump BR for nodejs to minimal 20.0 - dropped patches: * chromium-disable-GlobalMediaControlsCastStartStop.patch it was applied at the wrong place and the crash is gone OBS-URL: https://build.opensuse.org/package/show/home:oertel:branches:network:chromium/chromium-beta?expand=0&rev=17- Chromium 130.0.6723.6 (beta released 2024-09-18) - modified patches: * exclude_ymp.patch update context * chromium-125-compiler.patch update context * chromium-125-lp155-typename.patch drop hunks for rewritten proto_fetcher.h * chromium-127-bindgen.patch update context - added patches: * chromium-130-missing-includes.patch include optional, stack * chromium-130-no-hardware_destructive_interference_size.patch workaround for older libcpp - drop from keeplibs: courgette/third_party dropped upstream - add to keepllibs: third_party/fast_float needed by v8/src/numbers/conversion.cc - bump BR for nodejs to minimal 20.0 - dropped patches: * chromium-disable-GlobalMediaControlsCastStartStop.patch it was applied at the wrong place and the crash is gone - Chromium 129.0.6668.58 (stable released 2024-09-17) (boo#1230678) OBS-URL: https://build.opensuse.org/request/show/1202767 OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=57(beta releaed 2024-10-23) - dropped patches: * chromium-130-missing-includes.patch (upstream) - added patches: * chromium-131-no-crel.patch do not use "--crel,----allow-experimental-crel" for "-Wa" - Chromium 130.0.6723.69 (boo#1232060) * CVE-2024-10229: Inappropriate implementation in Extensions * CVE-2024-10230: Type Confusion in V8 * CVE-2024-10231: Type Confusion in V8 OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=62* chromium-131-unbundle-enable-freetype.patch from git, missing in 131 release OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=71(dev released 2024-10-24) - dropped patches: * chromium-131-unbundle-enable-freetype.patch (upstream) - Chromium 131.0.6778.24 (beta releaed 2024-10-30) * chromium-131-unbundle-enable-freetype.patch from git, missing in 131 release - update context in * chromium-125-lp155-typename.patch * chromium-127-bindgen.patch * chromium-127-constexpr.patch - drop from keeplibs: (deleted upstream) third_party/devtools-frontend/src/front_end/third_party/lodash-isequal - add to keeplibs: third_party/tflite/src/third_party/xla/xla/tsl (drop subdirs) third_party/ink - Chromium 130.0.6723.91 (boo#1232566) * CVE-2024-10487: Out of bounds write in Dawn * CVE-2024-10488: Use after free in WebRTC - change BR for rust to require version 1.81 (1.82 uses a newer llvm) - Chromium 130.0.6723.69 (boo#1232060) * CVE-2024-10229: Inappropriate implementation in Extensions * CVE-2024-10230: Type Confusion in V8 * CVE-2024-10231: Type Confusion in V8 OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-dev?expand=0&rev=4(dev release 2024-11-14) - Chromium 132.0.6834.6 (beta released 2024-11-13) * chromium-127-rust-clanglib.patch * Cr122-ffmpeg-new-channel-layout.patch - Chromium 131.0.6778.69 (stable released 2024-11-12) (boo#1233311) * CVE-2024-11110: Inappropriate implementation in Blink. * CVE-2024-11111: Inappropriate implementation in Autofill. * CVE-2024-11112: Use after free in Media. (n/a for linux) * CVE-2024-11113: Use after free in Accessibility. * CVE-2024-11114: Inappropriate implementation in Views. (n/a for linux) * CVE-2024-11115: Insufficient policy enforcement in Navigation. (n/a for linux) * CVE-2024-11116: Inappropriate implementation in Paint. * CVE-2024-11117: Inappropriate implementation in FileSystem. * chromium-125-lp155-typename.patch (not required with llvm) - modified patches: * chromium-127-bindgen.patch (drop all allowlist changes) * chromium-127-constexpr.patch (update from debian patch) * chromium-131-clang-stack-protector.patch (partial revert of upstream commit c3dadb02f611a360fb40fd8844ed3c1ef1e7834e) OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-dev?expand=0&rev=18* chromium-132-base_span.patch (try to fix compile error in ffmpeg_demuxer.cc on llvm17) OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=96* chromium-132-old_libdrm.patch (applied only on 15.5 with libdrm < 2.4.116) * chromium-132-pdfium-explicit-template.patch (error: alias template requires template arguments) OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=100(dev release 2024-11-21) - Chromium 132.0.6834.32 (beta released 2024-12-04) - added patches: * chromium-8d882c289f17e3a67d6d67d5ff7e9d16ebb4f19a.patch (apply git upstream reverse for 15.x with llvm17) * chromium-93-ffmpeg-4.4-rest.patch (split off to only apply after the reverse) * chromium-132-old_libdrm.patch (applied only on 15.5 with libdrm < 2.4.116) * chromium-132-pdfium-explicit-template.patch (error: alias template requires template arguments) * chromium-127-constexpr.patch third_party/devtools-frontend/src/node_modules/fast-glob - Chromium 131.0.6778.108 (stable released 2024-12-04) (boo#1234118) * CVE-2024-12053: Type Confusion in V8 - update patches: chromium-127-constexpr.patch - Chromium 131.0.6778.85 (stable released 2024-11-19) (boo#1233534) * CVE-2024-11395: Type Confusion in V8 OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-dev?expand=0&rev=21Needs pool/gn#1
Legal review in progress.
Legal reviewed by dec16180 as acceptable_by_lawyer: