Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 946253 (CVE-2024-12381, CVE-2024-12382) - <www-client/chromium-131.0.6778.139, <www-client/google-chrome-131.0.6778.139, <www-client/microsoft-edge-131.0.2903.99, <www-client/opera-115.0.5322.77: multiple vulnerabilities
Summary: <www-client/chromium-131.0.6778.139, <www-client/google-chrome-131.0.6778.139...
Status: CONFIRMED
Alias: CVE-2024-12381, CVE-2024-12382
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal
Assignee: Gentoo Security
URL: https://chromereleases.googleblog.com...
Whiteboard:
Keywords:
Depends on: 946261
Blocks:
  Show dependency tree
 
Reported: 2024-12-11 07:04 UTC by Matt Jolly
Modified: 2024-12-15 05:24 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Matt Jolly gentoo-dev 2024-12-11 07:04:32 UTC
The Stable channel has been updated to 131.0.6778.139 for Linux.

This update includes 3 security fixes.

High CVE-2024-12381: Type Confusion in V8. Reported by Seunghyun Lee (@0x10n) on 2024-12-02
High CVE-2024-12382: Use after free in Translate. Reported by lime(@limeSec_) from TIANGONG Team of Legendsec at QI-ANXIN Group on 2024-11-18
Comment 1 Larry the Git Cow gentoo-dev 2024-12-11 10:17:48 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=add469b663a6e5931874afd31bd4d72c4c255a0b

commit add469b663a6e5931874afd31bd4d72c4c255a0b
Author:     Matt Jolly <kangie@gentoo.org>
AuthorDate: 2024-12-11 07:06:48 +0000
Commit:     Matt Jolly <kangie@gentoo.org>
CommitDate: 2024-12-11 10:14:09 +0000

    www-client/google-chrome: automated update (131.0.6778.139)
    
    Bug: https://bugs.gentoo.org/946253
    Signed-off-by: Matt Jolly <kangie@gentoo.org>

 www-client/google-chrome/Manifest                                       | 2 +-
 ...chrome-131.0.6778.108.ebuild => google-chrome-131.0.6778.139.ebuild} | 0
 2 files changed, 1 insertion(+), 1 deletion(-)

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=1db7e50503a1d8229be0642e36aa82f336f79d41

commit 1db7e50503a1d8229be0642e36aa82f336f79d41
Author:     Matt Jolly <kangie@gentoo.org>
AuthorDate: 2024-12-11 04:00:39 +0000
Commit:     Matt Jolly <kangie@gentoo.org>
CommitDate: 2024-12-11 10:14:09 +0000

    www-client/chromium: add 131.0.6778.139
    
    Bug: https://bugs.gentoo.org/946253
    Signed-off-by: Matt Jolly <kangie@gentoo.org>

 www-client/chromium/Manifest                       |    2 +
 www-client/chromium/chromium-131.0.6778.139.ebuild | 1422 ++++++++++++++++++++
 2 files changed, 1424 insertions(+)