openSUSE-SU-2026:21624-1: important: Security update for chromium
| Newsgroups | gmane.linux.suse.security.announce |
|---|---|
| Message-ID | <[email protected]> |
openSUSE security update: security update for chromium
-------------------------------------------------------------
Announcement ID: openSUSE-SU-2026:21624-1
Rating: important
References:
* bsc#1275913
Cross-References:
* CVE-2026-76017
* CVE-2026-76018
* CVE-2026-76019
* CVE-2026-76020
* CVE-2026-76021
* CVE-2026-76022
* CVE-2026-76023
Affected Products:
openSUSE Leap 16.0
-------------------------------------------------------------
An update that solves 7 vulnerabilities and has one bug fix can now be installed.
Description:
This update for chromium fixes the following issues:
Changes in chromium:
- Chromium 151.0.7922.173 (boo#1275913):
* CVE-2026-76017: Use after free in Chromoting
* CVE-2026-76018: Privilege elevation in Import
* CVE-2026-76019: Incorrect authorization in Workers
* CVE-2026-76020: Race condition in V8
* CVE-2026-76021: Use after free in DOM.
* CVE-2026-76022: Buffer overflow in Network
* CVE-2026-76023: Improper resource control in Linux Toolkit Theming
Patch instructions:
To install this openSUSE security update use the suse recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 16.0
zypper in -t patch openSUSE-Leap-16.0-packagehub-525=1
Package List:
- openSUSE Leap 16.0:
chromedriver-151.0.7922.173-bp160.1.1
chromium-151.0.7922.173-bp160.1.1
References:
* https://www.suse.com/security/cve/CVE-2026-76017.html
* https://www.suse.com/security/cve/CVE-2026-76018.html
* https://www.suse.com/security/cve/CVE-2026-76019.html
* https://www.suse.com/security/cve/CVE-2026-76020.html
* https://www.suse.com/security/cve/CVE-2026-76021.html
* https://www.suse.com/security/cve/CVE-2026-76022.html
* https://www.suse.com/security/cve/CVE-2026-76023.html