Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 949327 (CVE-2025-0444, CVE-2025-0445, CVE-2025-0451) - www-client/chromium, www-client/google-chrome, www-client/microsoft-edge, www-client/opera: multiple vulnerabilities
Summary: www-client/chromium, www-client/google-chrome, www-client/microsoft-edge, www...
Status: CONFIRMED
Alias: CVE-2025-0444, CVE-2025-0445, CVE-2025-0451
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal
Assignee: Gentoo Security
URL: https://chromereleases.googleblog.com...
Whiteboard:
Keywords:
Depends on: 949328
Blocks:
  Show dependency tree
 
Reported: 2025-02-05 08:31 UTC by Matt Jolly
Modified: 2025-02-05 08:40 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Matt Jolly gentoo-dev 2025-02-05 08:31:04 UTC
Chrome 133.0.6943.53 has been released for linux.

This update includes 12 security fixes. Below, we highlight fixes that were contributed by external researchers. Please see the Chrome Security Page for more information.

[$7000][390889644] High CVE-2025-0444: Use after free in Skia. Reported by Francisco Alonso (@revskills) on 2025-01-19

[TBD][392521083] High CVE-2025-0445: Use after free in V8. Reported by 303f06e3 on 2025-01-27

[$2000][40061026] Medium CVE-2025-0451: Inappropriate implementation in Extensions API. Reported by Vitor Torres and Alesandro Ortiz on 2022-09-18
Comment 1 Larry the Git Cow gentoo-dev 2025-02-05 08:40:39 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=c854a79130f47e985dfed10ede3e543d07b12dd8

commit c854a79130f47e985dfed10ede3e543d07b12dd8
Author:     Matt Jolly <kangie@gentoo.org>
AuthorDate: 2025-02-05 08:32:35 +0000
Commit:     Matt Jolly <kangie@gentoo.org>
CommitDate: 2025-02-05 08:39:43 +0000

    www-client/google-chrome: automated update (133.0.6943.53)
    
    Bug: https://bugs.gentoo.org/949327
    Signed-off-by: Matt Jolly <kangie@gentoo.org>

 www-client/google-chrome/Manifest                                       | 2 +-
 ...-chrome-132.0.6834.159.ebuild => google-chrome-133.0.6943.53.ebuild} | 0
 2 files changed, 1 insertion(+), 1 deletion(-)

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=7a25776cc5e94d8d7df780715148ec9c42c0814c

commit 7a25776cc5e94d8d7df780715148ec9c42c0814c
Author:     FoldCat <akane@maidagency.org>
AuthorDate: 2025-02-05 08:15:54 +0000
Commit:     Matt Jolly <kangie@gentoo.org>
CommitDate: 2025-02-05 08:39:42 +0000

    www-client/chromium: add 133.0.6943.53
    
    Signed-off-by: FoldCat <akane@maidagency.org>
    Closes: https://github.com/gentoo/gentoo/pull/40442
    Bug: https://bugs.gentoo.org/949327
    Signed-off-by: Matt Jolly <kangie@gentoo.org>

 www-client/chromium/Manifest                      |    2 +
 www-client/chromium/chromium-133.0.6943.53.ebuild | 1434 +++++++++++++++++++++
 2 files changed, 1436 insertions(+)