Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 904394 (CVE-2023-2033) - <www-client/chromium-112.0.5615.121 <www-client/google-chrome-112.0.5615.121 <www-client/microsoft-edge-112.0.1722.48: Type Confusion in V8. Exploit exists.
Summary: <www-client/chromium-112.0.5615.121 <www-client/google-chrome-112.0.5615.121 ...
Status: IN_PROGRESS
Alias: CVE-2023-2033
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal major (vote)
Assignee: Gentoo Security
URL:
Whiteboard: A2 [glsa]
Keywords:
Depends on: 904531 904838
Blocks:
  Show dependency tree
 
Reported: 2023-04-16 08:39 UTC by gentoo
Modified: 2023-05-30 02:42 UTC (History)
4 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description gentoo 2023-04-16 08:39:32 UTC
See https://chromereleases.googleblog.com/2023/04/stable-channel-update-for-desktop_14.html

112.0.5615.121 includes 2 security fixes.

[$NA][1432210] High CVE-2023-2033: Type Confusion in V8. Reported by Clément Lecigne of Google's Threat Analysis Group on 2023-04-11

Google is aware that an exploit for CVE-2023-2033 exists in the wild.

[1433131] Various fixes from internal audits, fuzzing and other initiatives
Comment 1 Stephan Hartmann (RETIRED) gentoo-dev 2023-04-18 16:14:40 UTC
commit ab1afa59edfdc62871a325e5f75aa0bd2c2b89e0
Author: Mike Gilbert <floppym@gentoo.org>
Date:   Tue Apr 18 11:17:50 2023 -0400

    www-client/chromium: add 112.0.5615.121

    Signed-off-by: Mike Gilbert <floppym@gentoo.org>
Comment 2 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2023-05-30 00:04:37 UTC
GLSA request filed.