Pull request for security update for chromium #280

Manually merged
products merged 2 commits from rfrohl/PackageHub:maintenance-update-1765444852 into leap-16.0 2025-12-12 16:23:52 +01:00
2 changed files with 18 additions and 1 deletions

View File

@@ -0,0 +1,17 @@
<patchinfo>
<issue tracker="cve" id="2025-14372">cve#2025-14372 not resolved: 404 Client Error: Not Found for url: https://bugzilla.suse.com/api2/issues/?references__name=CVE-2025-14372</issue>
<issue tracker="bnc" id="1254776">VUL-0: chromium: release 143.0.7499.109</issue>
<issue tracker="cve" id="2025-14373">cve#2025-14373 not resolved: 404 Client Error: Not Found for url: https://bugzilla.suse.com/api2/issues/?references__name=CVE-2025-14373</issue>
Review

This seems to have picked up an error string from a downstream system.

This seems to have picked up an error string from a downstream system.
Review

This is just a tooling problem that has no impact, I stopped to clean it up manually if I am in a rush. Proper form would be

<issue tracker="cve" id="2025-14373"/>

This is just a tooling problem that has no impact, I stopped to clean it up manually if I am in a rush. Proper form would be ` <issue tracker="cve" id="2025-14373"/>`
Review

Why are you not fixing the tooling?

Why are you not fixing the tooling?
Review

There is a bug open for the responsible team.

There is a bug open for the responsible team.
<packager>AndreasStieger</packager>
<rating>important</rating>
<category>security</category>
<summary>Security update for chromium</summary>
<description>This update for chromium fixes the following issues:
- Chromium 143.0.7499.109 (boo#1254776):
* CVE-2025-14372: Use after free in Password Manager
* CVE-2025-14373: Inappropriate implementation in Toolbar
* third issue with an exploit is known to exist in the wild
</description>
<package>chromium</package>
</patchinfo>