openSUSE-SU-2026:0281-1: critical: Security update for chromium

[email protected]
Newsgroups gmane.linux.suse.security.announce
Message-ID <[email protected]>
   openSUSE Security Update: Security update for chromium
______________________________________________________________________________

Announcement ID:    openSUSE-SU-2026:0281-1
Rating:             critical
References:         #1274549 
Cross-References:   CVE-2026-19137 CVE-2026-19138 CVE-2026-19139
                    CVE-2026-19140 CVE-2026-19141 CVE-2026-19142
                    CVE-2026-19143 CVE-2026-19144 CVE-2026-19145
                    CVE-2026-19146 CVE-2026-19147 CVE-2026-19148
                    CVE-2026-19149 CVE-2026-19150 CVE-2026-19151
                    CVE-2026-19152 CVE-2026-19153 CVE-2026-19154
                    CVE-2026-19155 CVE-2026-19156 CVE-2026-19157
                    CVE-2026-19158 CVE-2026-19159 CVE-2026-19160
                    CVE-2026-19161 CVE-2026-19162 CVE-2026-19163
                    CVE-2026-19164 CVE-2026-19165 CVE-2026-19166
                    CVE-2026-19167 CVE-2026-19168 CVE-2026-19169
                    CVE-2026-19170 CVE-2026-19171 CVE-2026-19172
                    CVE-2026-19173 CVE-2026-19174 CVE-2026-19175
                    CVE-2026-19176 CVE-2026-19177
Affected Products:
                    openSUSE Backports SLE-15-SP7
______________________________________________________________________________

   An update that fixes 41 vulnerabilities is now available.

Description:

   This update for chromium fixes the following issues:

   - Chromium 151.0.7922.108 (boo#1274549):
     * CVE-2026-19137: Use after free in WebGL
     * CVE-2026-19149: Use after free in Aura
     * CVE-2026-19154: Use after free in Skia
     * CVE-2026-19157: Out of bounds write in ANGLE
     * CVE-2026-19170: Use after free in WebGL
     * CVE-2026-19172: Use after free in Views
     * CVE-2026-19169: Insufficient validation of untrusted input in
       Contextual Tasks
     * CVE-2026-19168: Inappropriate implementation in V8
     * CVE-2026-19138: Heap buffer overflow in CrashReporting
     * CVE-2026-19139: Race in CredentialProvider
     * CVE-2026-19140: Use after free in GPU
     * CVE-2026-19141: Use after free in Resources
     * CVE-2026-19142: Use after free in Views
     * CVE-2026-19143: Insufficient validation of untrusted input in WebAPKs
     * CVE-2026-19144: Use after free in HTML
     * CVE-2026-19145: Use after free in Translate
     * CVE-2026-19146: Uninitialized Use in GPU
     * CVE-2026-19147: Use after free in Aura
     * CVE-2026-19148: Out of bounds write in GPU
     * CVE-2026-19150: Inappropriate implementation in V8
     * CVE-2026-19151: Use after free in V8
     * CVE-2026-19152: Inappropriate implementation in Navigation
     * CVE-2026-19153: Insufficient validation of untrusted input in Workers
     * CVE-2026-19155: Use after free in Payments
     * CVE-2026-19156: Heap buffer overflow in Base
     * CVE-2026-19158: Use after free in Views
     * CVE-2026-19159: Use after free in Views
     * CVE-2026-19160: Uninitialized Use in Skia
     * CVE-2026-19161: Uninitialized Use in Skia
     * CVE-2026-19162: Out of bounds write in V8
     * CVE-2026-19163: Use after free in Media
     * CVE-2026-19164: Insufficient validation of untrusted input in Codecs
     * CVE-2026-19165: Use after free in Extensions
     * CVE-2026-19166: Use after free in Web Authentication
     * CVE-2026-19167: Integer overflow in GPU
     * CVE-2026-19171: Use after free in Media
     * CVE-2026-19173: Out of bounds write in Skia
     * CVE-2026-19174: Integer overflow in V8
     * CVE-2026-19175: Use after free in Payments
     * CVE-2026-19176: Use after free in Skia
     * CVE-2026-19177: Insufficient validation of untrusted input in UI

   - Chromium 151.0.7922.75:
     * stability fix
     * pull in SKIA updates


Patch Instructions:

   To install this openSUSE Security Update use the SUSE recommended installation methods
   like YaST online_update or "zypper patch".

   Alternatively you can run the command listed for your product:

   - openSUSE Backports SLE-15-SP7:

      zypper in -t patch openSUSE-2026-281=1



Package List:

   - openSUSE Backports SLE-15-SP7 (aarch64 ppc64le x86_64):

      chromedriver-151.0.7922.108-bp157.2.202.1
      chromium-151.0.7922.108-bp157.2.202.1


References:

   https://www.suse.com/security/cve/CVE-2026-19137.html
   https://www.suse.com/security/cve/CVE-2026-19138.html
   https://www.suse.com/security/cve/CVE-2026-19139.html
   https://www.suse.com/security/cve/CVE-2026-19140.html
   https://www.suse.com/security/cve/CVE-2026-19141.html
   https://www.suse.com/security/cve/CVE-2026-19142.html
   https://www.suse.com/security/cve/CVE-2026-19143.html
   https://www.suse.com/security/cve/CVE-2026-19144.html
   https://www.suse.com/security/cve/CVE-2026-19145.html
   https://www.suse.com/security/cve/CVE-2026-19146.html
   https://www.suse.com/security/cve/CVE-2026-19147.html
   https://www.suse.com/security/cve/CVE-2026-19148.html
   https://www.suse.com/security/cve/CVE-2026-19149.html
   https://www.suse.com/security/cve/CVE-2026-19150.html
   https://www.suse.com/security/cve/CVE-2026-19151.html
   https://www.suse.com/security/cve/CVE-2026-19152.html
   https://www.suse.com/security/cve/CVE-2026-19153.html
   https://www.suse.com/security/cve/CVE-2026-19154.html
   https://www.suse.com/security/cve/CVE-2026-19155.html
   https://www.suse.com/security/cve/CVE-2026-19156.html
   https://www.suse.com/security/cve/CVE-2026-19157.html
   https://www.suse.com/security/cve/CVE-2026-19158.html
   https://www.suse.com/security/cve/CVE-2026-19159.html
   https://www.suse.com/security/cve/CVE-2026-19160.html
   https://www.suse.com/security/cve/CVE-2026-19161.html
   https://www.suse.com/security/cve/CVE-2026-19162.html
   https://www.suse.com/security/cve/CVE-2026-19163.html
   https://www.suse.com/security/cve/CVE-2026-19164.html
   https://www.suse.com/security/cve/CVE-2026-19165.html
   https://www.suse.com/security/cve/CVE-2026-19166.html
   https://www.suse.com/security/cve/CVE-2026-19167.html
   https://www.suse.com/security/cve/CVE-2026-19168.html
   https://www.suse.com/security/cve/CVE-2026-19169.html
   https://www.suse.com/security/cve/CVE-2026-19170.html
   https://www.suse.com/security/cve/CVE-2026-19171.html
   https://www.suse.com/security/cve/CVE-2026-19172.html
   https://www.suse.com/security/cve/CVE-2026-19173.html
   https://www.suse.com/security/cve/CVE-2026-19174.html
   https://www.suse.com/security/cve/CVE-2026-19175.html
   https://www.suse.com/security/cve/CVE-2026-19176.html
   https://www.suse.com/security/cve/CVE-2026-19177.html
   https://bugzilla.suse.com/1274549
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.