openSUSE-SU-2026:21609-1: critical: Security update for chromium
| Newsgroups | gmane.linux.suse.security.announce |
|---|---|
| Message-ID | <[email protected]> |
openSUSE security update: security update for chromium
-------------------------------------------------------------
Announcement ID: openSUSE-SU-2026:21609-1
Rating: critical
References:
* bsc#1275706
Cross-References:
* CVE-2026-76033
* CVE-2026-76034
* CVE-2026-76035
* CVE-2026-76036
* CVE-2026-76037
* CVE-2026-76038
* CVE-2026-76039
* CVE-2026-76040
* CVE-2026-76041
* CVE-2026-76042
* CVE-2026-76043
* CVE-2026-76044
* CVE-2026-76045
* CVE-2026-76046
* CVE-2026-76047
Affected Products:
openSUSE Leap 16.0
-------------------------------------------------------------
An update that solves 15 vulnerabilities and has one bug fix can now be installed.
Description:
This update for chromium fixes the following issues:
Changes in chromium:
- Chromium 151.0.7922.169 (boo#1275706):
* CVE-2026-76034: Buffer overflow in WebGL
* CVE-2026-76036: Buffer overflow in Dawn
* CVE-2026-76033: Inappropriate implementation in CORS
* CVE-2026-76037: Link following in CredentialProvider
* CVE-2026-76044: Race condition in USB
* CVE-2026-76039: Incorrect reference resolution in Core
* CVE-2026-76040: Use after free in Browser
* CVE-2026-76035: Inappropriate implementation in Media
* CVE-2026-76042: Use of uninitialized resource in GPU
* CVE-2026-76046: Buffer overflow in ANGLE
* CVE-2026-76043: Incorrect calculation in V8
* CVE-2026-76041: Information leak in Skia
* CVE-2026-76047: Type confusion in V8
* CVE-2026-76038: Type confusion in V8
* CVE-2026-76045: Use after free in WebGL
Patch instructions:
To install this openSUSE security update use the suse recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 16.0
zypper in -t patch openSUSE-Leap-16.0-packagehub-510=1
Package List:
- openSUSE Leap 16.0:
chromedriver-151.0.7922.169-bp160.1.1
chromium-151.0.7922.169-bp160.1.1
References:
* https://www.suse.com/security/cve/CVE-2026-76033.html
* https://www.suse.com/security/cve/CVE-2026-76034.html
* https://www.suse.com/security/cve/CVE-2026-76035.html
* https://www.suse.com/security/cve/CVE-2026-76036.html
* https://www.suse.com/security/cve/CVE-2026-76037.html
* https://www.suse.com/security/cve/CVE-2026-76038.html
* https://www.suse.com/security/cve/CVE-2026-76039.html
* https://www.suse.com/security/cve/CVE-2026-76040.html
* https://www.suse.com/security/cve/CVE-2026-76041.html
* https://www.suse.com/security/cve/CVE-2026-76042.html
* https://www.suse.com/security/cve/CVE-2026-76043.html
* https://www.suse.com/security/cve/CVE-2026-76044.html
* https://www.suse.com/security/cve/CVE-2026-76045.html
* https://www.suse.com/security/cve/CVE-2026-76046.html
* https://www.suse.com/security/cve/CVE-2026-76047.html