From f250ad0669aafe3735bff9814f7bee2a1b3f732e385f9d67ee50cff33f0e6103 Mon Sep 17 00:00:00 2001 From: Marcus Meissner Date: Fri, 10 Oct 2025 13:06:00 +0200 Subject: [PATCH] Update submodules from https://src.opensuse.org/pool/chromium/pulls/11 and create patchinfo.20251010110535882810.90520734224245/_patchinfo --- chromium | 2 +- .../_patchinfo | 66 +++++++++++++++++++ 2 files changed, 67 insertions(+), 1 deletion(-) create mode 100644 patchinfo.20251010110535882810.90520734224245/_patchinfo diff --git a/chromium b/chromium index 2e70429..4476973 160000 --- a/chromium +++ b/chromium @@ -1 +1 @@ -Subproject commit 2e70429051bc9e1dfca1cf7926ddf6515fe174290094db0ee6a5735999e659ae +Subproject commit 44769739f53c9916907eefe853032d37582bc2464649b18e0fabf0878d0b68d4 diff --git a/patchinfo.20251010110535882810.90520734224245/_patchinfo b/patchinfo.20251010110535882810.90520734224245/_patchinfo new file mode 100644 index 0000000..5c74ab1 --- /dev/null +++ b/patchinfo.20251010110535882810.90520734224245/_patchinfo @@ -0,0 +1,66 @@ + + VUL-0: chromium: release 141.0.7390.65 + VUL-0: chromium: release 141.0.7390.54 + VUL-0: chromium: release 141.0.7390.54 + VUL-0: chromium: release 141.0.7390.54 + VUL-0: chromium: release 141.0.7390.54 + VUL-0: chromium: release 141.0.7390.54 + VUL-0: chromium: release 141.0.7390.54 + VUL-0: chromium: release 141.0.7390.54 + VUL-0: chromium: release 141.0.7390.54 + VUL-0: chromium: release 140.0.7339.207 + VUL-0: chromium: release 141.0.7390.54 + VUL-0: chromium: release 141.0.7390.65 + VUL-0: chromium: release 141.0.7390.54 + VUL-0: chromium: release 140.0.7339.207 + VUL-0: chromium: release 141.0.7390.54 + VUL-0: chromium: release 140.0.7339.207 + + VUL-0: chromium: release 141.0.7390.54 + VUL-0: chromium: release 141.0.7390.54 + VUL-0: chromium: release 140.0.7339.207 + AndreasStieger + critical + security + Security update for chromium + This update for chromium fixes the following issues: + +Chromium 141.0.7390.76: + + * Do not send URLs as AIM input. This is to resolve a privacy + concern, around passing urls to AI Mode. + +Chromium 141.0.7390.65 (boo#1251334): + + * CVE-2025-11458: Heap buffer overflow in Sync + * CVE-2025-11460: Use after free in Storage + * CVE-2025-11211: Out of bounds read in WebCodecs + +Chromium 141.0.7390.54 (stable released 2025-09-30) (boo#1250780) + + * CVE-2025-11205: Heap buffer overflow in WebGPU + * CVE-2025-11206: Heap buffer overflow in Video + * CVE-2025-11207: Side-channel information leakage in Storage + * CVE-2025-11208: Inappropriate implementation in Media + * CVE-2025-11209: Inappropriate implementation in Omnibox + * CVE-2025-11210: Side-channel information leakage in Tab + * CVE-2025-11211: Out of bounds read in Media + * CVE-2025-11212: Inappropriate implementation in Media + * CVE-2025-11213: Inappropriate implementation in Omnibox + * CVE-2025-11215: Off by one error in V8 + * CVE-2025-11216: Inappropriate implementation in Storage + * CVE-2025-11219: Use after free in V8 + * Various fixes from internal audits, fuzzing and other initiatives + +Chromium 141.0.7390.37 (beta released 2025-09-24) + +Chromium 140.0.7339.207 (boo#1250472) + + * CVE-2025-10890: Side-channel information leakage in V8 + * CVE-2025-10891: Integer overflow in V8 + * CVE-2025-10892: Integer overflow in V8 + + + chromium + + -- 2.51.1