Bug 1182358 (CVE-2021-21149)

Summary: VUL-0: CVE-2021-21149,CVE-2021-21150,CVE-2021-21151,CVE-2021-21152,CVE-2021-21153,CVE-2021-21154,CVE-2021-21155,CVE-2021-21156,CVE-2021-21157: chromium: Update to 88.0.4324.182
Product: [openSUSE] openSUSE Distribution Reporter: Alexandros Toptsoglou <atoptsoglou>
Component: SecurityAssignee: Callum Farmer <gmbr3>
Status: RESOLVED FIXED QA Contact: E-mail List <qa-bugs>
Severity: Major    
Priority: P3 - Medium CC: meissner
Version: Leap 15.2   
Target Milestone: ---   
Hardware: Other   
OS: Other   
Whiteboard:
Found By: --- Services Priority:
Business Priority: Blocker: ---
Marketing QA Status: --- IT Deployment: ---

Description Alexandros Toptsoglou 2021-02-17 10:28:48 UTC
CVE-2021-21149: Stack overflow in Data Transfer.
CVE-2021-21150: Use after free in Downloads.
CVE-2021-21151: Use after free in Payments.
CVE-2021-21152: Heap buffer overflow in Media.
CVE-2021-21153: Stack overflow in GPU Process. 
CVE-2021-21154: Heap buffer overflow in Tab Strip. 
CVE-2021-21155: Heap buffer overflow in Tab Strip.
CVE-2021-21156: Heap buffer overflow in V8.
CVE-2021-21157: Use after free in Web Sockets.
Comment 2 Callum Farmer 2021-02-17 10:47:06 UTC
ok
Comment 3 OBSbugzilla Bot 2021-02-17 12:40:07 UTC
This is an autogenerated message for OBS integration:
This bug (1182358) was mentioned in
https://build.opensuse.org/request/show/873105 15.2 / chromium
https://build.opensuse.org/request/show/873109 Factory / chromium
https://build.opensuse.org/request/show/873110 Backports:SLE-15-SP3 / chromium
Comment 4 Marcus Meissner 2021-02-19 16:50:46 UTC
Leap 15.2 chromium update fails in openqa:_

https://openqa.opensuse.org/tests/1634828#step/chromium/21

host unreachable is new from chromium
Comment 5 OBSbugzilla Bot 2021-03-05 13:40:15 UTC
This is an autogenerated message for OBS integration:
This bug (1182358) was mentioned in
https://build.opensuse.org/request/show/877006 15.2 / chromium
Comment 6 Swamp Workflow Management 2021-03-08 11:17:24 UTC
openSUSE-SU-2021:0392-1: An update that fixes 42 vulnerabilities is now available.

Category: security (important)
Bug References: 1182233,1182358,1182775
CVE References: CVE-2020-27844,CVE-2021-21149,CVE-2021-21150,CVE-2021-21151,CVE-2021-21152,CVE-2021-21153,CVE-2021-21154,CVE-2021-21155,CVE-2021-21156,CVE-2021-21157,CVE-2021-21159,CVE-2021-21160,CVE-2021-21161,CVE-2021-21162,CVE-2021-21163,CVE-2021-21164,CVE-2021-21165,CVE-2021-21166,CVE-2021-21167,CVE-2021-21168,CVE-2021-21169,CVE-2021-21170,CVE-2021-21171,CVE-2021-21172,CVE-2021-21173,CVE-2021-21174,CVE-2021-21175,CVE-2021-21176,CVE-2021-21177,CVE-2021-21178,CVE-2021-21179,CVE-2021-21180,CVE-2021-21181,CVE-2021-21182,CVE-2021-21183,CVE-2021-21184,CVE-2021-21185,CVE-2021-21186,CVE-2021-21187,CVE-2021-21188,CVE-2021-21189,CVE-2021-21190
JIRA References: 
Sources used:
openSUSE Leap 15.2 (src):    chromium-89.0.4389.72-lp152.2.77.1
Comment 7 Swamp Workflow Management 2021-03-09 23:18:03 UTC
openSUSE-SU-2021:0401-1: An update that fixes 42 vulnerabilities is now available.

Category: security (important)
Bug References: 1182233,1182358,1182775
CVE References: CVE-2020-27844,CVE-2021-21149,CVE-2021-21150,CVE-2021-21151,CVE-2021-21152,CVE-2021-21153,CVE-2021-21154,CVE-2021-21155,CVE-2021-21156,CVE-2021-21157,CVE-2021-21159,CVE-2021-21160,CVE-2021-21161,CVE-2021-21162,CVE-2021-21163,CVE-2021-21164,CVE-2021-21165,CVE-2021-21166,CVE-2021-21167,CVE-2021-21168,CVE-2021-21169,CVE-2021-21170,CVE-2021-21171,CVE-2021-21172,CVE-2021-21173,CVE-2021-21174,CVE-2021-21175,CVE-2021-21176,CVE-2021-21177,CVE-2021-21178,CVE-2021-21179,CVE-2021-21180,CVE-2021-21181,CVE-2021-21182,CVE-2021-21183,CVE-2021-21184,CVE-2021-21185,CVE-2021-21186,CVE-2021-21187,CVE-2021-21188,CVE-2021-21189,CVE-2021-21190
JIRA References: 
Sources used:
openSUSE Backports SLE-15-SP2 (src):    chromium-89.0.4389.72-bp152.2.62.1
Comment 8 Callum Farmer 2021-03-13 11:42:26 UTC
done via 89.0.4389.72
Comment 9 Swamp Workflow Management 2021-03-15 23:17:01 UTC
openSUSE-SU-2021:0413-1: An update that fixes 10 vulnerabilities is now available.

Category: security (important)
Bug References: 1182358
CVE References: CVE-2021-21148,CVE-2021-21149,CVE-2021-21150,CVE-2021-21151,CVE-2021-21152,CVE-2021-21153,CVE-2021-21154,CVE-2021-21155,CVE-2021-21156,CVE-2021-21157
JIRA References: 
Sources used:
openSUSE Leap 15.2:NonFree (src):    opera-74.0.3911.203-lp152.2.37.1
Comment 10 OBSbugzilla Bot 2021-12-15 09:41:17 UTC
This is an autogenerated message for OBS integration:
This bug (1182358) was mentioned in
https://build.opensuse.org/request/show/940663 Backports:SLE-12-SP3 / chromium