1
0

Compare commits

..

10 Commits

Author SHA256 Message Date
5b687c4a59 Update patchinfo.20260213163213815955.255638743075857/_patchinfo
update patchinfo for latest pool PR update
2026-02-17 09:41:20 +01:00
AutoGits PR Review Bot
058e86b532 auto-created for chromium
This commit was autocreated by AutoGits PR Review Bot

referencing PRs:
 PR: pool/chromium!33
2026-02-17 08:34:45 +00:00
AutoGits PR Review Bot
a8d1ade5b7 auto-created for chromium
This commit was autocreated by AutoGits PR Review Bot

referencing PRs:
 PR: pool/chromium!33
2026-02-13 19:59:46 +00:00
AutoGits PR Review Bot
c125f5317e auto-created for chromium
This commit was autocreated by AutoGits PR Review Bot

referencing PRs:
 PR: pool/chromium!33
2026-02-13 19:41:49 +00:00
f366e3a76f Update patchinfo.20260213163213815955.255638743075857/_patchinfo
update patchinfo
2026-02-13 20:41:19 +01:00
3e972378ce Update submodules from pool/chromium#33 and create patchinfo.20260213163213815955.255638743075857/_patchinfo 2026-02-13 17:32:32 +01:00
d8ef588e45 Update patchinfo incident numbers [skip actions] 2026-02-13 15:59:55 +00:00
AutoGits PR Review Bot
c42bd6d2d4 Merging
PR: products/PackageHub!389
2026-02-13 15:59:34 +00:00
AutoGits PR Review Bot
cb50b6a227 Merging
PR: products/PackageHub!444
2026-02-13 14:50:10 +00:00
2882c46b9e Update submodules from pool/htmldoc#1 and create patchinfo.20260203172101250739.93181000773252/_patchinfo 2026-02-03 18:23:31 +01:00
4 changed files with 119 additions and 2 deletions

Submodule htmldoc updated: db696f6a95...0677f71aa3

View File

@@ -0,0 +1,56 @@
<patchinfo incident="packagehub-128">
<issue tracker="cve" id="2024-46478"/>
<issue tracker="bnc" id="1232380">VUL-0: CVE-2024-46478: htmldoc: buffer overflow when handling tabs through the parse_pre function (ps-pdf.cxx)</issue>
<issue tracker="cve" id="2024-45508"/>
<packager>pgajdos</packager>
<rating>critical</rating>
<category>security</category>
<summary>Security update for htmldoc</summary>
<description>This update for htmldoc fixes the following issues:
Changes in htmldoc:
- CVE-2024-46478: Fixed buffer overflow when handling tabs through the parse_pre function (bsc#1232380).
- version update to 1.9.23:
* Fixed a regression in list handling that caused a crash for empty list items
(Issue #553)
* Fixed a regression in the number of rendered table of contents levels in PDF
and PostScript output (Issue #554)
- version update to 1.9.22:
* Added a "--without-http" configure option to build without CUPS HTTP/HTTPS
support (Issue #547)
* Updated HTTP/HTTPS support to work with both CUPS 2.x and 3.x.
* Updated the maximum image dimension to prevent integer overflow on 32-bit
platforms (Issue #550)
* Updated the HTML parser to correctly report the line number of errors in files
with more than 2^32-1 lines (Issue #551)
* Fixed a crash bug with certain markdown files (Issue #548)
* Fixed an unrestricted recursion bug when reading and formatting HTML (Issue #552)
- version update to 1.9.21
* Updated HTTP/HTTPS connection error reporting to include the reason.
* Updated markdown parser.
* Updated the HTTP/HTTPS connection timeout to 5 minutes (Issue #541)
* Fixed a bug in the new PDF link code (Issue #536)
* Fixed a bug in the number-up code (Issue #539)
* Fixed a regression in leading whitespace handling (Issue #540)
* Fixed a bug in numbered heading support (Issue #543)
* Fixed a bug with setting the header on the first page (Issue #544)
* Fixed paths in the HTMLDOC snap (Issue #545)
- update to 1.9.20:
* Fix a regression that caused spaces to disappear between some words
* Fix resolution of relative links within a document
- includes changes from 1.9.19:
* Add support for file method in links
* Update markdown support code to mmd
* Fix hyperlinks to subfolders
* Fix export of UTF-8 HTML
* Fix handling of whitespace-only nodes
* Fix case sensitivity of link targets
</description>
<package>htmldoc</package>
</patchinfo>

View File

@@ -0,0 +1,61 @@
<patchinfo>
<issue tracker="cve" id="2026-2319"/>
<issue tracker="cve" id="2026-2322"/>
<issue tracker="cve" id="2026-2313"/>
<issue tracker="cve" id="2026-2318"/>
<issue tracker="cve" id="2026-2441"/>
<issue tracker="cve" id="2026-2316"/>
<issue tracker="bnc" id="1258185">VUL-0: CVE-2026-2441: chromium: Use after free in CSS (fixed in 145.0.7632.75)</issue>
<issue tracker="cve" id="2026-2323"/>
<issue tracker="cve" id="2026-2321"/>
<issue tracker="cve" id="2026-2317"/>
<issue tracker="bnc" id="1258116">VUL-0: chromium: release 145.0.7632.45</issue>
<issue tracker="cve" id="2026-2315"/>
<issue tracker="cve" id="2026-2320"/>
<issue tracker="cve" id="2026-2314"/>
<issue tracker="bnc" id="1258199">chromium desktop icon shows @@MENUNAME</issue>
<packager>oertel</packager>
<rating>important</rating>
<category>security</category>
<summary>Security update for chromium</summary>
<description>This update for chromium fixes the following issues:
Changes in chromium:
- more fixes for desktop file, some variables were lowercased,
further adaptions in INSTALL script (boo#1258199)
- also copy rollup into third_party/node/node_modules
- stay on llvm-10 for swiftshader but bring a similar patch
- drop use of rollup binaries and use rollup-3.x which does not
use prebuilt binaries (that fail at least on older ppc64le)
follow the approach of the debian packaging
- update/resync ppc64le patches from fedora
- fix INSTALL.sh again to replace the tags in desktop file,
appdata and manpage (boo#1258199)
- Chromium 145.0.7632.75:
* CVE-2026-2441: Use after free in CSS (boo#1258185)
- Chromium 145.0.7632.67:
* Revert a change in url_fixer that may have caused crashes
- Chromium 145.0.7632.45 (boo#1258116)
* jpeg-xl support has been readded
* CVE-2026-2313: Use after free in CSS
* CVE-2026-2314: Heap buffer overflow in Codecs
* CVE-2026-2315: Inappropriate implementation in WebGPU
* CVE-2026-2316: Insufficient policy enforcement in Frames
* CVE-2026-2317: Inappropriate implementation in Animation
* CVE-2026-2318: Inappropriate implementation in PictureInPicture
* CVE-2026-2319: Race in DevTools
* CVE-2026-2320: Inappropriate implementation in File input
* CVE-2026-2321: Use after free in Ozone
* CVE-2026-2322: Inappropriate implementation in File input
* CVE-2026-2323: Inappropriate implementation in Downloads
</description>
<package>chromium</package>
</patchinfo>