diff --git a/chromium b/chromium index ff3414e..f0003f0 160000 --- a/chromium +++ b/chromium @@ -1 +1 @@ -Subproject commit ff3414e963a0c31f77d2972e2e713427db98c2f42f186dbd0c25b5d0ef8664ff +Subproject commit f0003f0c35de44e3da4f9c3d49429d4655f046d28face25f1f7c862c0a15b719 diff --git a/patchinfo.20260213163213815955.255638743075857/_patchinfo b/patchinfo.20260213163213815955.255638743075857/_patchinfo new file mode 100644 index 0000000..c15f249 --- /dev/null +++ b/patchinfo.20260213163213815955.255638743075857/_patchinfo @@ -0,0 +1,61 @@ + + + + + + + + VUL-0: CVE-2026-2441: chromium: Use after free in CSS (fixed in 145.0.7632.75) + + + + VUL-0: chromium: release 145.0.7632.45 + + + + chromium desktop icon shows @@MENUNAME + oertel + important + security + Security update for chromium + This update for chromium fixes the following issues: + +Changes in chromium: + +- more fixes for desktop file, some variables were lowercased, + further adaptions in INSTALL script (boo#1258199) + +- also copy rollup into third_party/node/node_modules +- stay on llvm-10 for swiftshader but bring a similar patch + +- drop use of rollup binaries and use rollup-3.x which does not + use prebuilt binaries (that fail at least on older ppc64le) + follow the approach of the debian packaging + +- update/resync ppc64le patches from fedora + +- fix INSTALL.sh again to replace the tags in desktop file, + appdata and manpage (boo#1258199) + +- Chromium 145.0.7632.75: + * CVE-2026-2441: Use after free in CSS (boo#1258185) + +- Chromium 145.0.7632.67: + * Revert a change in url_fixer that may have caused crashes + +- Chromium 145.0.7632.45 (boo#1258116) + * jpeg-xl support has been readded + * CVE-2026-2313: Use after free in CSS + * CVE-2026-2314: Heap buffer overflow in Codecs + * CVE-2026-2315: Inappropriate implementation in WebGPU + * CVE-2026-2316: Insufficient policy enforcement in Frames + * CVE-2026-2317: Inappropriate implementation in Animation + * CVE-2026-2318: Inappropriate implementation in PictureInPicture + * CVE-2026-2319: Race in DevTools + * CVE-2026-2320: Inappropriate implementation in File input + * CVE-2026-2321: Use after free in Ozone + * CVE-2026-2322: Inappropriate implementation in File input + * CVE-2026-2323: Inappropriate implementation in Downloads + + chromium +