public inbox for git-commits@fedoraproject.org
help / color / mirror / Atom feed
* [rpms/chromium] epel9-next: - Update to 147.0.7727.101
@ 2026-08-07 16:08 Than Ngo
  0 siblings, 0 replies; only message in thread
From: Than Ngo @ 2026-08-07 16:08 UTC (permalink / raw)
  To: git-commits

          A new commit has been pushed.

          Repo   : rpms/chromium
          Branch : epel9-next
          Commit : 3584fa8ec735e81bcd7df882d50293ea4667321b
          Author : Than Ngo <than@redhat.com>
          Date   : 2026-04-16T16:04:07+02:00
          Stats  : +36/-2 in 2 file(s)
          URL    : https://src.fedoraproject.org/rpms/chromium/c/3584fa8ec735e81bcd7df882d50293ea4667321b?branch=epel9-next

          Log:
          - Update to 147.0.7727.101
* Critical CVE-2026-6296: Heap buffer overflow in ANGLE
* Critical CVE-2026-6297: Use after free in Proxy
* Critical CVE-2026-6298: Heap buffer overflow in Skia
* Critical CVE-2026-6299: Use after free in Prerender
* Critical CVE-2026-6358: Use after free in XR
* High CVE-2026-6359: Use after free in Video
* High CVE-2026-6300: Use after free in CSS
* High CVE-2026-6301: Type Confusion in Turbofan
* High CVE-2026-6302: Use after free in Video
* High CVE-2026-6303: Use after free in Codecs
* High CVE-2026-6304: Use after free in Graphite
* High CVE-2026-6305: Heap buffer overflow in PDFium
* High CVE-2026-6306: Heap buffer overflow in PDFium
* High CVE-2026-6307: Type Confusion in Turbofan
* High CVE-2026-6308: Out of bounds read in Media
* High CVE-2026-6309: Use after free in Viz
* High CVE-2026-6360: Use after free in FileSystem
* High CVE-2026-6310: Use after free in Dawn
* High CVE-2026-6311: Uninitialized Use in Accessibility
* High CVE-2026-6312: Insufficient policy enforcement in Passwords
* High CVE-2026-6313: Insufficient policy enforcement in CORS
* High CVE-2026-6314: Out of bounds write in GPU
* High CVE-2026-6315: Use after free in Permissions
* High CVE-2026-6316: Use after free in Forms
* High CVE-2026-6361: Heap buffer overflow in PDFium
* High CVE-2026-6362: Use after free in Codecs
* High CVE-2026-6317: Use after free in Cast
* Medium CVE-2026-6363: Type Confusion in V8
* Medium CVE-2026-6318: Use after free in Codecs
* Medium CVE-2026-6319: Use after free in Payments
* Medium CVE-2026-6364: Out of bounds read in Skia

---
diff --git a/chromium.spec b/chromium.spec
index b56c83b..74fe266 100644
--- a/chromium.spec
+++ b/chromium.spec
@@ -262,7 +262,7 @@
 %endif
 
 Name:	chromium
-Version: 147.0.7727.55
+Version: 147.0.7727.101
 Release: 1%{?dist}
 Summary: A WebKit (Blink) powered web browser that Google doesn't want you to use
 Url: http://www.chromium.org/Home
@@ -1857,6 +1857,40 @@ fi
 %endif
 
 %changelog
+* Wed Apr 15 2026 Than Ngo <than@redhat.com> - 147.0.7727.101-1
+- Update to 147.0.7727.101
+  * Critical CVE-2026-6296: Heap buffer overflow in ANGLE
+  * Critical CVE-2026-6297: Use after free in Proxy
+  * Critical CVE-2026-6298: Heap buffer overflow in Skia
+  * Critical CVE-2026-6299: Use after free in Prerender
+  * Critical CVE-2026-6358: Use after free in XR
+  * High CVE-2026-6359: Use after free in Video
+  * High CVE-2026-6300: Use after free in CSS
+  * High CVE-2026-6301: Type Confusion in Turbofan
+  * High CVE-2026-6302: Use after free in Video
+  * High CVE-2026-6303: Use after free in Codecs
+  * High CVE-2026-6304: Use after free in Graphite
+  * High CVE-2026-6305: Heap buffer overflow in PDFium
+  * High CVE-2026-6306: Heap buffer overflow in PDFium
+  * High CVE-2026-6307: Type Confusion in Turbofan
+  * High CVE-2026-6308: Out of bounds read in Media
+  * High CVE-2026-6309: Use after free in Viz
+  * High CVE-2026-6360: Use after free in FileSystem
+  * High CVE-2026-6310: Use after free in Dawn
+  * High CVE-2026-6311: Uninitialized Use in Accessibility
+  * High CVE-2026-6312: Insufficient policy enforcement in Passwords
+  * High CVE-2026-6313: Insufficient policy enforcement in CORS
+  * High CVE-2026-6314: Out of bounds write in GPU
+  * High CVE-2026-6315: Use after free in Permissions
+  * High CVE-2026-6316: Use after free in Forms
+  * High CVE-2026-6361: Heap buffer overflow in PDFium
+  * High CVE-2026-6362: Use after free in Codecs
+  * High CVE-2026-6317: Use after free in Cast
+  * Medium CVE-2026-6363: Type Confusion in V8
+  * Medium CVE-2026-6318: Use after free in Codecs
+  * Medium CVE-2026-6319: Use after free in Payments
+  * Medium CVE-2026-6364: Out of bounds read in Skia
+
 * Thu Apr 09 2026 Than Ngo <than@redhat.com> - 147.0.7727.55-1
 - Update to 147.0.7727.55
   * Critical CVE-2026-5858: Heap buffer overflow in WebML

diff --git a/sources b/sources
index 2227a0e..bf44dd0 100644
--- a/sources
+++ b/sources
@@ -1,4 +1,4 @@
 SHA512 (rollup-linux-arm64-gnu-4.22.4.tgz) = 01d3d1a0d8b734a54ba2508dfd2a7817837577df1ce120671cc2a82ee886e915e0a19e2c965b1eb868a8b33ba69cf1a63ccd8eeea6805ff20975e0d4f1fdba03
 SHA512 (rollup-linux-powerpc64le-gnu-4.22.4.tgz) = dda5422bdc5f596d68190a53b182493c5e9b7e959f85b46785d97285a936662c852c369acb3d043f98fd5754552c003196658a4c37d2f70c91c98de1be13e83a
 SHA512 (node-v22.22.0-stripped.tar.gz) = f32a8a73063b3c78cbacf941e11dd529ebcf2618b3ba661966312e49ee9870c43a3acf256e8d331a4b0b621b16a501810c02a3ad763c75884cc250addca8e106
-SHA512 (chromium-147.0.7727.55-clean.tar.xz) = 9f1b946656ef607b722f1eb0ff6495df5ced53811e26016b8b36eef3daf9864a8230f3efb5a8d30048287c7bfd68feccdab7b030a467a3e835588a47e949bede
+SHA512 (chromium-147.0.7727.101-clean.tar.xz) = 86044f16b5124dcb90d939666dbeed422fc285e7df2f8807aed75b64a39c37f6a0f0db00e014b5bfba12dd40b14a8c9d148f26ccbad1f16f3c1d5c7c7eaa713c

^ permalink raw reply related	[flat|nested] only message in thread

only message in thread, other threads:[~2026-08-07 16:08 UTC | newest]

Thread overview: (only message) (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-08-07 16:08 [rpms/chromium] epel9-next: - Update to 147.0.7727.101 Than Ngo

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox