public inbox for git-commits@fedoraproject.org
help / color / mirror / Atom feed
From: Than Ngo <than@redhat.com>
To: git-commits@fedoraproject.org
Subject: [rpms/chromium] epel9-next: - Update to 146.0.7680.153
Date: Fri, 07 Aug 2026 16:08:49 GMT [thread overview]
Message-ID: <178611892976.1.9626867222730662779.rpms-chromium-ea40ae404c7a@fedoraproject.org> (raw)
A new commit has been pushed.
Repo : rpms/chromium
Branch : epel9-next
Commit : ea40ae404c7a3d04d86d3d6610ecb5616f02db84
Author : Than Ngo <than@redhat.com>
Date : 2026-03-20T15:56:17+01:00
Stats : +31/-1 in 2 file(s)
URL : https://src.fedoraproject.org/rpms/chromium/c/ea40ae404c7a3d04d86d3d6610ecb5616f02db84?branch=epel9-next
Log:
- Update to 146.0.7680.153
* CVE-2026-4439: Out of bounds memory access in WebGL
* CVE-2026-4440: Out of bounds read and write in WebGL
* CVE-2026-4441: Use after free in Base
* CVE-2026-4442: Heap buffer overflow in CSS
* CVE-2026-4443: Heap buffer overflow in WebAudio
* CVE-2026-4444: Stack buffer overflow in WebRTC
* CVE-2026-4445: Use after free in WebRTC
* CVE-2026-4446: Use after free in WebRTC
* CVE-2026-4447: Inappropriate implementation in V8
* CVE-2026-4448: Heap buffer overflow in ANGLE
* CVE-2026-4449: Use after free in Blink
* CVE-2026-4450: Out of bounds write in V8
* CVE-2026-4451: Insufficient validation of untrusted input in Navigation
* CVE-2026-4452: Integer overflow in ANGLE
* CVE-2026-4453: Integer overflow in Dawn
* CVE-2026-4454: Use after free in Network
* CVE-2026-4455: Heap buffer overflow in PDFium
* CVE-2026-4456: Use after free in Digital Credentials API
* CVE-2026-4457: Type Confusion in V8
* CVE-2026-4458: Use after free in Extensions
* CVE-2026-4459: Out of bounds read and write in WebAudio
* CVE-2026-4460: Out of bounds read in Skia
* CVE-2026-4461: Inappropriate implementation in V8
* CVE-2026-4462: Out of bounds read in Blink
* CVE-2026-4463: Heap buffer overflow in WebRTC
* CVE-2026-4464: Integer overflow in ANGLE
---
diff --git a/chromium.spec b/chromium.spec
index 896e39b..4cc8e65 100644
--- a/chromium.spec
+++ b/chromium.spec
@@ -262,7 +262,7 @@
%endif
Name: chromium
-Version: 146.0.7680.80
+Version: 146.0.7680.153
Release: 1%{?dist}
Summary: A WebKit (Blink) powered web browser that Google doesn't want you to use
Url: http://www.chromium.org/Home
@@ -1859,6 +1859,35 @@ fi
%endif
%changelog
+* Fri Mar 20 2026 Than Ngo <than@redhat.com> - 146.0.7680.153-1
+- Update to 146.0.7680.153
+ * CVE-2026-4439: Out of bounds memory access in WebGL
+ * CVE-2026-4440: Out of bounds read and write in WebGL
+ * CVE-2026-4441: Use after free in Base
+ * CVE-2026-4442: Heap buffer overflow in CSS
+ * CVE-2026-4443: Heap buffer overflow in WebAudio
+ * CVE-2026-4444: Stack buffer overflow in WebRTC
+ * CVE-2026-4445: Use after free in WebRTC
+ * CVE-2026-4446: Use after free in WebRTC
+ * CVE-2026-4447: Inappropriate implementation in V8
+ * CVE-2026-4448: Heap buffer overflow in ANGLE
+ * CVE-2026-4449: Use after free in Blink
+ * CVE-2026-4450: Out of bounds write in V8
+ * CVE-2026-4451: Insufficient validation of untrusted input in Navigation
+ * CVE-2026-4452: Integer overflow in ANGLE
+ * CVE-2026-4453: Integer overflow in Dawn
+ * CVE-2026-4454: Use after free in Network
+ * CVE-2026-4455: Heap buffer overflow in PDFium
+ * CVE-2026-4456: Use after free in Digital Credentials API
+ * CVE-2026-4457: Type Confusion in V8
+ * CVE-2026-4458: Use after free in Extensions
+ * CVE-2026-4459: Out of bounds read and write in WebAudio
+ * CVE-2026-4460: Out of bounds read in Skia
+ * CVE-2026-4461: Inappropriate implementation in V8
+ * CVE-2026-4462: Out of bounds read in Blink
+ * CVE-2026-4463: Heap buffer overflow in WebRTC
+ * CVE-2026-4464: Integer overflow in ANGLE
+
* Sat Mar 14 2026 Than Ngo <than@redhat.com> - 146.0.7680.80-1
- Update to 146.0.7680.80
* CVE-2026-3909: Out of bounds write in Skia
diff --git a/sources b/sources
index 7d61e9b..171197f 100644
--- a/sources
+++ b/sources
@@ -2,3 +2,4 @@ SHA512 (rollup-linux-arm64-gnu-4.22.4.tgz) = 01d3d1a0d8b734a54ba2508dfd2a7817837
SHA512 (rollup-linux-powerpc64le-gnu-4.22.4.tgz) = dda5422bdc5f596d68190a53b182493c5e9b7e959f85b46785d97285a936662c852c369acb3d043f98fd5754552c003196658a4c37d2f70c91c98de1be13e83a
SHA512 (node-v22.22.0-stripped.tar.gz) = f32a8a73063b3c78cbacf941e11dd529ebcf2618b3ba661966312e49ee9870c43a3acf256e8d331a4b0b621b16a501810c02a3ad763c75884cc250addca8e106
SHA512 (chromium-146.0.7680.80-clean.tar.xz) = 511abd7e50f824274593113863c0d10cbe9222b1996e3e60a3ba6f3ea93bae4545d3ad49d951031f892bafef32732758da6602f845eaab251a36342298e2812e
+SHA512 (chromium-146.0.7680.153-clean.tar.xz) = 0a0d331447abe4df28f1d9e25a67810bfdecd39aa9679233628cbcab239025a35cb98e49939bf3184df6fae04e41453f7125d24b07dbde584e06ac88f71c8ef0
reply other threads:[~2026-08-07 16:08 UTC|newest]
Thread overview: [no followups] expand[flat|nested] mbox.gz Atom feed
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=178611892976.1.9626867222730662779.rpms-chromium-ea40ae404c7a@fedoraproject.org \
--to=than@redhat.com \
--cc=git-commits@fedoraproject.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox