--------------------------------------------------------------------------------
Fedora EPEL Update Notification
FEDORA-EPEL-2026-bb07e73593
2026-08-22 00:49:04.157857+00:00
--------------------------------------------------------------------------------

Name        : chromium
Product     : Fedora EPEL 10.2
Version     : 151.0.7922.169
Release     : 1.el10_2
URL         : http://www.chromium.org/Home
Summary     : A WebKit (Blink) powered web browser that Google doesn't want you 
to use
Description :
Chromium is an open-source web browser, powered by WebKit (Blink).

--------------------------------------------------------------------------------
Update Information:

chromium security release 151.0.7922.169
  * CVE-2026-76034: Buffer overflow in WebGL
  * CVE-2026-76036: Buffer overflow in Dawn
  * CVE-2026-76033: Inappropriate implementation in CORS
  * CVE-2026-76037: Link following in CredentialProvider
  * CVE-2026-76044: Race condition in USB
  * CVE-2026-76039: Incorrect reference resolution in Core
  * CVE-2026-76040: Use after free in Browser
  * CVE-2026-76035: Inappropriate implementation in Media
  * CVE-2026-76042: Use of uninitialized resource in GPU
  * CVE-2026-76046: Buffer overflow in ANGLE
  * CVE-2026-76043: Incorrect calculation in V8
  * CVE-2026-76041: Information leak in Skia
  * CVE-2026-76047: Type confusion in V8
  * CVE-2026-76038: Type confusion in V8
  * CVE-2026-76045: Use after free in WebGL
--------------------------------------------------------------------------------
ChangeLog:

* Thu Aug 20 2026 Than Ngo <[email protected]> - 151.0.7922.169-1
- Update to 151.0.7922.169
  * CVE-2026-76034: Buffer overflow in WebGL
  * CVE-2026-76036: Buffer overflow in Dawn
  * CVE-2026-76033: Inappropriate implementation in CORS
  * CVE-2026-76037: Link following in CredentialProvider
  * CVE-2026-76044: Race condition in USB
  * CVE-2026-76039: Incorrect reference resolution in Core
  * CVE-2026-76040: Use after free in Browser
  * CVE-2026-76035: Inappropriate implementation in Media
  * CVE-2026-76042: Use of uninitialized resource in GPU
  * CVE-2026-76046: Buffer overflow in ANGLE
  * CVE-2026-76043: Incorrect calculation in V8
  * CVE-2026-76041: Information leak in Skia
  * CVE-2026-76047: Type confusion in V8
  * CVE-2026-76038: Type confusion in V8
  * CVE-2026-76045: Use after free in WebGL
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #2519415 - CVE-2026-76044 chromium: Google Chrome: Arbitrary code 
execution due to a race condition in USB [epel-all]
        https://bugzilla.redhat.com/show_bug.cgi?id=2519415
  [ 2 ] Bug #2519416 - CVE-2026-76044 chromium: Google Chrome: Arbitrary code 
execution due to a race condition in USB [fedora-all]
        https://bugzilla.redhat.com/show_bug.cgi?id=2519416
  [ 3 ] Bug #2519424 - CVE-2026-76040 chromium: chromium-browser: Arbitrary 
code execution via use-after-free vulnerability [epel-all]
        https://bugzilla.redhat.com/show_bug.cgi?id=2519424
  [ 4 ] Bug #2519425 - CVE-2026-76040 chromium: chromium-browser: Arbitrary 
code execution via use-after-free vulnerability [fedora-all]
        https://bugzilla.redhat.com/show_bug.cgi?id=2519425
  [ 5 ] Bug #2519426 - CVE-2026-76036 chromium: Dawn in Google Chrome: 
Arbitrary code execution via crafted HTML page [epel-all]
        https://bugzilla.redhat.com/show_bug.cgi?id=2519426
  [ 6 ] Bug #2519427 - CVE-2026-76036 chromium: Dawn in Google Chrome: 
Arbitrary code execution via crafted HTML page [fedora-all]
        https://bugzilla.redhat.com/show_bug.cgi?id=2519427
  [ 7 ] Bug #2519429 - CVE-2026-76043 chromium: Google Chrome V8: Arbitrary 
code execution via incorrect calculation in HTML processing [fedora-all]
        https://bugzilla.redhat.com/show_bug.cgi?id=2519429
  [ 8 ] Bug #2519430 - CVE-2026-76043 chromium: Google Chrome V8: Arbitrary 
code execution via incorrect calculation in HTML processing [epel-all]
        https://bugzilla.redhat.com/show_bug.cgi?id=2519430
  [ 9 ] Bug #2519438 - CVE-2026-76042 chromium: Google Chrome: Information 
disclosure via uninitialized resource in GPU [epel-all]
        https://bugzilla.redhat.com/show_bug.cgi?id=2519438
  [ 10 ] Bug #2519441 - CVE-2026-76042 chromium: Google Chrome: Information 
disclosure via uninitialized resource in GPU [fedora-all]
        https://bugzilla.redhat.com/show_bug.cgi?id=2519441
  [ 11 ] Bug #2519443 - CVE-2026-76041 chromium: Chromium: Information leak 
allows web origin policy bypass [fedora-all]
        https://bugzilla.redhat.com/show_bug.cgi?id=2519443
  [ 12 ] Bug #2519446 - CVE-2026-76041 chromium: Chromium: Information leak 
allows web origin policy bypass [epel-all]
        https://bugzilla.redhat.com/show_bug.cgi?id=2519446
  [ 13 ] Bug #2519447 - CVE-2026-76038 chromium: V8: Remote code execution via 
type confusion in crafted HTML. [epel-all]
        https://bugzilla.redhat.com/show_bug.cgi?id=2519447
  [ 14 ] Bug #2519451 - CVE-2026-76038 chromium: V8: Remote code execution via 
type confusion in crafted HTML. [fedora-all]
        https://bugzilla.redhat.com/show_bug.cgi?id=2519451
  [ 15 ] Bug #2519452 - CVE-2026-76037 chromium: Google Chrome: Arbitrary Code 
Execution via Link Following [epel-all]
        https://bugzilla.redhat.com/show_bug.cgi?id=2519452
  [ 16 ] Bug #2519454 - CVE-2026-76037 chromium: Google Chrome: Arbitrary Code 
Execution via Link Following [fedora-all]
        https://bugzilla.redhat.com/show_bug.cgi?id=2519454
  [ 17 ] Bug #2519457 - CVE-2026-76039 chromium: Chromium: Information 
disclosure via incorrect reference resolution [epel-all]
        https://bugzilla.redhat.com/show_bug.cgi?id=2519457
  [ 18 ] Bug #2519458 - CVE-2026-76039 chromium: Chromium: Information 
disclosure via incorrect reference resolution [fedora-all]
        https://bugzilla.redhat.com/show_bug.cgi?id=2519458
--------------------------------------------------------------------------------

This update can be installed with the "yum" update programs.  Use
su -c 'yum update chromium' at the command line.
For more information, refer to "YUM", available at
https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux/7\
/html/System_Administrators_Guide/ch-yum.html

All packages are signed with the Fedora EPEL GPG key.  More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------

-- 
_______________________________________________
epel-package-announce mailing list -- 
[email protected]
To unsubscribe send an email to 
[email protected]
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/[email protected]
Do not reply to spam, report it: 
https://forge.fedoraproject.org/infra/tickets/issues/new

Reply via email to