-------------------------------------------------------------------------------- Fedora EPEL Update Notification FEDORA-EPEL-2026-bb07e73593 2026-08-22 00:49:04.157857+00:00 --------------------------------------------------------------------------------
Name : chromium Product : Fedora EPEL 10.2 Version : 151.0.7922.169 Release : 1.el10_2 URL : http://www.chromium.org/Home Summary : A WebKit (Blink) powered web browser that Google doesn't want you to use Description : Chromium is an open-source web browser, powered by WebKit (Blink). -------------------------------------------------------------------------------- Update Information: chromium security release 151.0.7922.169 * CVE-2026-76034: Buffer overflow in WebGL * CVE-2026-76036: Buffer overflow in Dawn * CVE-2026-76033: Inappropriate implementation in CORS * CVE-2026-76037: Link following in CredentialProvider * CVE-2026-76044: Race condition in USB * CVE-2026-76039: Incorrect reference resolution in Core * CVE-2026-76040: Use after free in Browser * CVE-2026-76035: Inappropriate implementation in Media * CVE-2026-76042: Use of uninitialized resource in GPU * CVE-2026-76046: Buffer overflow in ANGLE * CVE-2026-76043: Incorrect calculation in V8 * CVE-2026-76041: Information leak in Skia * CVE-2026-76047: Type confusion in V8 * CVE-2026-76038: Type confusion in V8 * CVE-2026-76045: Use after free in WebGL -------------------------------------------------------------------------------- ChangeLog: * Thu Aug 20 2026 Than Ngo <[email protected]> - 151.0.7922.169-1 - Update to 151.0.7922.169 * CVE-2026-76034: Buffer overflow in WebGL * CVE-2026-76036: Buffer overflow in Dawn * CVE-2026-76033: Inappropriate implementation in CORS * CVE-2026-76037: Link following in CredentialProvider * CVE-2026-76044: Race condition in USB * CVE-2026-76039: Incorrect reference resolution in Core * CVE-2026-76040: Use after free in Browser * CVE-2026-76035: Inappropriate implementation in Media * CVE-2026-76042: Use of uninitialized resource in GPU * CVE-2026-76046: Buffer overflow in ANGLE * CVE-2026-76043: Incorrect calculation in V8 * CVE-2026-76041: Information leak in Skia * CVE-2026-76047: Type confusion in V8 * CVE-2026-76038: Type confusion in V8 * CVE-2026-76045: Use after free in WebGL -------------------------------------------------------------------------------- References: [ 1 ] Bug #2519415 - CVE-2026-76044 chromium: Google Chrome: Arbitrary code execution due to a race condition in USB [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2519415 [ 2 ] Bug #2519416 - CVE-2026-76044 chromium: Google Chrome: Arbitrary code execution due to a race condition in USB [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2519416 [ 3 ] Bug #2519424 - CVE-2026-76040 chromium: chromium-browser: Arbitrary code execution via use-after-free vulnerability [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2519424 [ 4 ] Bug #2519425 - CVE-2026-76040 chromium: chromium-browser: Arbitrary code execution via use-after-free vulnerability [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2519425 [ 5 ] Bug #2519426 - CVE-2026-76036 chromium: Dawn in Google Chrome: Arbitrary code execution via crafted HTML page [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2519426 [ 6 ] Bug #2519427 - CVE-2026-76036 chromium: Dawn in Google Chrome: Arbitrary code execution via crafted HTML page [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2519427 [ 7 ] Bug #2519429 - CVE-2026-76043 chromium: Google Chrome V8: Arbitrary code execution via incorrect calculation in HTML processing [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2519429 [ 8 ] Bug #2519430 - CVE-2026-76043 chromium: Google Chrome V8: Arbitrary code execution via incorrect calculation in HTML processing [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2519430 [ 9 ] Bug #2519438 - CVE-2026-76042 chromium: Google Chrome: Information disclosure via uninitialized resource in GPU [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2519438 [ 10 ] Bug #2519441 - CVE-2026-76042 chromium: Google Chrome: Information disclosure via uninitialized resource in GPU [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2519441 [ 11 ] Bug #2519443 - CVE-2026-76041 chromium: Chromium: Information leak allows web origin policy bypass [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2519443 [ 12 ] Bug #2519446 - CVE-2026-76041 chromium: Chromium: Information leak allows web origin policy bypass [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2519446 [ 13 ] Bug #2519447 - CVE-2026-76038 chromium: V8: Remote code execution via type confusion in crafted HTML. [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2519447 [ 14 ] Bug #2519451 - CVE-2026-76038 chromium: V8: Remote code execution via type confusion in crafted HTML. [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2519451 [ 15 ] Bug #2519452 - CVE-2026-76037 chromium: Google Chrome: Arbitrary Code Execution via Link Following [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2519452 [ 16 ] Bug #2519454 - CVE-2026-76037 chromium: Google Chrome: Arbitrary Code Execution via Link Following [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2519454 [ 17 ] Bug #2519457 - CVE-2026-76039 chromium: Chromium: Information disclosure via incorrect reference resolution [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2519457 [ 18 ] Bug #2519458 - CVE-2026-76039 chromium: Chromium: Information disclosure via incorrect reference resolution [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2519458 -------------------------------------------------------------------------------- This update can be installed with the "yum" update programs. Use su -c 'yum update chromium' at the command line. For more information, refer to "YUM", available at https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux/7\ /html/System_Administrators_Guide/ch-yum.html All packages are signed with the Fedora EPEL GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ epel-package-announce mailing list -- [email protected] To unsubscribe send an email to [email protected] Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/[email protected] Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
