openSUSE-SU-2026:0293-1: critical: Security update for chromium
| Newsgroups | gmane.linux.suse.security.announce |
|---|---|
| Message-ID | <[email protected]> |
openSUSE Security Update: Security update for chromium
______________________________________________________________________________
Announcement ID: openSUSE-SU-2026:0293-1
Rating: critical
References: #1274759 #1275706
Cross-References: CVE-2026-76033 CVE-2026-76034 CVE-2026-76035
CVE-2026-76036 CVE-2026-76037 CVE-2026-76038
CVE-2026-76039 CVE-2026-76040 CVE-2026-76041
CVE-2026-76042 CVE-2026-76043 CVE-2026-76044
CVE-2026-76045 CVE-2026-76046 CVE-2026-76047
Affected Products:
openSUSE Backports SLE-15-SP7
______________________________________________________________________________
An update that fixes 15 vulnerabilities is now available.
Description:
This update for chromium fixes the following issues:
- Chromium 151.0.7922.169 (boo#1275706):
* CVE-2026-76034: Buffer overflow in WebGL
* CVE-2026-76036: Buffer overflow in Dawn
* CVE-2026-76033: Inappropriate implementation in CORS
* CVE-2026-76037: Link following in CredentialProvider
* CVE-2026-76044: Race condition in USB
* CVE-2026-76039: Incorrect reference resolution in Core
* CVE-2026-76040: Use after free in Browser
* CVE-2026-76035: Inappropriate implementation in Media
* CVE-2026-76042: Use of uninitialized resource in GPU
* CVE-2026-76046: Buffer overflow in ANGLE
* CVE-2026-76043: Incorrect calculation in V8
* CVE-2026-76041: Information leak in Skia
* CVE-2026-76047: Type confusion in V8
* CVE-2026-76038: Type confusion in V8
* CVE-2026-76045: Use after free in WebGL
Patch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Backports SLE-15-SP7:
zypper in -t patch openSUSE-2026-293=1
Package List:
- openSUSE Backports SLE-15-SP7 (aarch64 ppc64le x86_64):
chromedriver-151.0.7922.169-bp157.2.208.1
chromium-151.0.7922.169-bp157.2.208.1
References:
https://www.suse.com/security/cve/CVE-2026-76033.html
https://www.suse.com/security/cve/CVE-2026-76034.html
https://www.suse.com/security/cve/CVE-2026-76035.html
https://www.suse.com/security/cve/CVE-2026-76036.html
https://www.suse.com/security/cve/CVE-2026-76037.html
https://www.suse.com/security/cve/CVE-2026-76038.html
https://www.suse.com/security/cve/CVE-2026-76039.html
https://www.suse.com/security/cve/CVE-2026-76040.html
https://www.suse.com/security/cve/CVE-2026-76041.html
https://www.suse.com/security/cve/CVE-2026-76042.html
https://www.suse.com/security/cve/CVE-2026-76043.html
https://www.suse.com/security/cve/CVE-2026-76044.html
https://www.suse.com/security/cve/CVE-2026-76045.html
https://www.suse.com/security/cve/CVE-2026-76046.html
https://www.suse.com/security/cve/CVE-2026-76047.html
https://bugzilla.suse.com/1274759
https://bugzilla.suse.com/1275706