Overview
Request 841893 accepted
- Remove vdpau->vaapi bridge as it breaks a lot:
(fixes welcome by someone else than me)
* chromium-vaapi-fix.patch
- Fix cookiemonster:
* fix-invalid-end-iterator-usage-in-CookieMonster.patch
- Update to 86.0.4240.75 bsc#1177408:
* CVE-2020-15967: Use after free in payments.
* CVE-2020-15968: Use after free in Blink.
* CVE-2020-15969: Use after free in WebRTC.
* CVE-2020-15970: Use after free in NFC.
* CVE-2020-15971: Use after free in printing.
* CVE-2020-15972: Use after free in audio.
* CVE-2020-15990: Use after free in autofill.
* CVE-2020-15991: Use after free in password manager.
* CVE-2020-15973: Insufficient policy enforcement in extensions.
* CVE-2020-15974: Integer overflow in Blink.
* CVE-2020-15975: Integer overflow in SwiftShader.
* CVE-2020-15976: Use after free in WebXR.
* CVE-2020-6557: Inappropriate implementation in networking.
* CVE-2020-15977: Insufficient data validation in dialogs.
* CVE-2020-15978: Insufficient data validation in navigation.
* CVE-2020-15979: Inappropriate implementation in V8.
* CVE-2020-15980: Insufficient policy enforcement in Intents.
* CVE-2020-15981: Out of bounds read in audio.
* CVE-2020-15982: Side-channel information leakage in cache.
* CVE-2020-15983: Insufficient data validation in webUI.
* CVE-2020-15984: Insufficient policy enforcement in Omnibox.
* CVE-2020-15985: Inappropriate implementation in Blink.
Request History
msmeissn created request
- Remove vdpau->vaapi bridge as it breaks a lot:
(fixes welcome by someone else than me)
* chromium-vaapi-fix.patch
- Fix cookiemonster:
* fix-invalid-end-iterator-usage-in-CookieMonster.patch
- Update to 86.0.4240.75 bsc#1177408:
* CVE-2020-15967: Use after free in payments.
* CVE-2020-15968: Use after free in Blink.
* CVE-2020-15969: Use after free in WebRTC.
* CVE-2020-15970: Use after free in NFC.
* CVE-2020-15971: Use after free in printing.
* CVE-2020-15972: Use after free in audio.
* CVE-2020-15990: Use after free in autofill.
* CVE-2020-15991: Use after free in password manager.
* CVE-2020-15973: Insufficient policy enforcement in extensions.
* CVE-2020-15974: Integer overflow in Blink.
* CVE-2020-15975: Integer overflow in SwiftShader.
* CVE-2020-15976: Use after free in WebXR.
* CVE-2020-6557: Inappropriate implementation in networking.
* CVE-2020-15977: Insufficient data validation in dialogs.
* CVE-2020-15978: Insufficient data validation in navigation.
* CVE-2020-15979: Inappropriate implementation in V8.
* CVE-2020-15980: Insufficient policy enforcement in Intents.
* CVE-2020-15981: Out of bounds read in audio.
* CVE-2020-15982: Side-channel information leakage in cache.
* CVE-2020-15983: Insufficient data validation in webUI.
* CVE-2020-15984: Insufficient policy enforcement in Omnibox.
* CVE-2020-15985: Inappropriate implementation in Blink.
licensedigger accepted review
ok
maintbot added chromium as a reviewer
Submission for chromium by someone who is not maintainer in the devel project (network:chromium). Please review
maintbot accepted review
ok
factory-auto accepted review
Check script succeeded
msmeissn accepted review
ok
msmeissn approved review
ok
atopt moved maintenance target to openSUSE:Maintenance:14554
atopt accepted request
accepted request 841893:Thanks!
For information about the update, see https://build.opensuse.org/project/maintenance_incidents/openSUSE:Maintenance
network:chromium/chromium@a98ecaa55f5e0fe1bc06319716e81d5c -> openSUSE:Leap:15.2:Update/chromium
expected origin is 'None' (unchanged)