Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 948135 (CVE-2025-0434, CVE-2025-0435, CVE-2025-0436, CVE-2025-0437, CVE-2025-0438, CVE-2025-0439, CVE-2025-0440, CVE-2025-0441, CVE-2025-0442, CVE-2025-0443, CVE-2025-0446, CVE-2025-0447, CVE-2025-0448) - <www-client/chromium-132.0.6834.83, <www-client/google-chrome-132.0.6834.83, www-client/microsoft-edge, www-client/opera: multiple vulnerabilities
Summary: <www-client/chromium-132.0.6834.83, <www-client/google-chrome-132.0.6834.83, ...
Status: CONFIRMED
Alias: CVE-2025-0434, CVE-2025-0435, CVE-2025-0436, CVE-2025-0437, CVE-2025-0438, CVE-2025-0439, CVE-2025-0440, CVE-2025-0441, CVE-2025-0442, CVE-2025-0443, CVE-2025-0446, CVE-2025-0447, CVE-2025-0448
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal
Assignee: Gentoo Security
URL: https://chromereleases.googleblog.com...
Whiteboard:
Keywords:
Depends on: 948141
Blocks:
  Show dependency tree
 
Reported: 2025-01-15 07:46 UTC by Matt Jolly
Modified: 2025-01-16 09:23 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Matt Jolly gentoo-dev 2025-01-15 07:46:58 UTC
Chromium has been updated to Chrome 132.0.6834.83 for Linux.

This update includes 16 security fixes. Below, we highlight fixes that were contributed by external researchers. Please see the Chrome Security Page for more information.

[$7000][374627491] High CVE-2025-0434: Out of bounds memory access in V8. Reported by ddme on 2024-10-21
[$7000][379652406] High CVE-2025-0435: Inappropriate implementation in Navigation. Reported by Alesandro Ortiz on 2024-11-18
[$3000][382786791] High CVE-2025-0436: Integer overflow in Skia. Reported by Han Zheng (HexHive) on 2024-12-08
[$2000][378623799] High CVE-2025-0437: Out of bounds read in Metrics. Reported by Xiantong Hou of Wuheng Lab and Pisanbao on 2024-11-12
[TBD][384186539] High CVE-2025-0438: Stack buffer overflow in Tracing. Reported by Han Zheng (HexHive) on 2024-12-15
[$5000][371247941] Medium CVE-2025-0439: Race in Frames. Reported by Hafiizh on 2024-10-03
[$5000][40067914] Medium CVE-2025-0440: Inappropriate implementation in Fullscreen. Reported by Umar Farooq on 2023-07-22
[$2000][368628042] Medium CVE-2025-0441: Inappropriate implementation in Fenced Frames. Reported by someoneverycurious on 2024-09-21
[$2000][40940854] Medium CVE-2025-0442: Inappropriate implementation in Payments. Reported by Ahmed ElMasry on 2023-11-08
[$1000][376625003] Medium CVE-2025-0443: Insufficient data validation in Extensions. Reported by Anonymous on 2024-10-31
[$1000][359949844] Low CVE-2025-0446: Inappropriate implementation in Extensions. Reported by Hafiizh on 2024-08-15
[$1000][375550814] Low CVE-2025-0447: Inappropriate implementation in Navigation. Reported by Khiem Tran (@duckhiem) on 2024-10-25
[$1000][377948403] Low CVE-2025-0448: Inappropriate implementation in Compositing. Reported by Dahyeon Park on 2024-11-08
[389761478] Various fixes from internal audits, fuzzing and other initiatives
Comment 1 Larry the Git Cow gentoo-dev 2025-01-15 08:15:04 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=2519df5a397fa61275198326b450cdafc8f02d30

commit 2519df5a397fa61275198326b450cdafc8f02d30
Author:     Matt Jolly <kangie@gentoo.org>
AuthorDate: 2025-01-15 07:55:13 +0000
Commit:     Matt Jolly <kangie@gentoo.org>
CommitDate: 2025-01-15 08:01:14 +0000

    www-client/google-chrome: automated update (132.0.6834.83)
    
    Bug: https://bugs.gentoo.org/948135
    Signed-off-by: Matt Jolly <kangie@gentoo.org>

 www-client/google-chrome/Manifest                                       | 2 +-
 ...-chrome-131.0.6778.264.ebuild => google-chrome-132.0.6834.83.ebuild} | 0
 2 files changed, 1 insertion(+), 1 deletion(-)

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=d4dfddaabb474a7abb6dfe00d5449bfaae1b0422

commit d4dfddaabb474a7abb6dfe00d5449bfaae1b0422
Author:     Matt Jolly <kangie@gentoo.org>
AuthorDate: 2025-01-15 07:50:20 +0000
Commit:     Matt Jolly <kangie@gentoo.org>
CommitDate: 2025-01-15 07:51:03 +0000

    www-client/chromium: promote 132.0.6834.83 to stable subslot
    
    Bug: https://bugs.gentoo.org/948135
    Signed-off-by: Matt Jolly <kangie@gentoo.org>

 www-client/chromium/chromium-132.0.6834.83.ebuild | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)