public inbox for git-commits@fedoraproject.org
help / color / mirror / Atom feed
From: Than Ngo <than@redhat.com>
To: git-commits@fedoraproject.org
Subject: [rpms/chromium] epel9-next: - Update to 148.0.7778.96
Date: Fri, 07 Aug 2026 16:08:59 GMT	[thread overview]
Message-ID: <178611893996.1.13160682954600545940.rpms-chromium-8db3c4a88b3b@fedoraproject.org> (raw)

         A new commit has been pushed.

         Repo   : rpms/chromium
         Branch : epel9-next
         Commit : 8db3c4a88b3bf58f6ecf9551f0133585e97820d0
         Author : Than Ngo <than@redhat.com>
         Date   : 2026-05-06T22:00:49+02:00
         Stats  : +127/-0 in 1 file(s)
         URL    : https://src.fedoraproject.org/rpms/chromium/c/8db3c4a88b3bf58f6ecf9551f0133585e97820d0?branch=epel9-next

         Log:
         - Update to 148.0.7778.96
* CVE-2026-7896: Integer overflow in Blink
* CVE-2026-7897: Use after free in Mobile
* CVE-2026-7898: Use after free in Chromoting
* CVE-2026-7899: Out of bounds read and write in V8
* CVE-2026-7900: Heap buffer overflow in ANGLE
* CVE-2026-7901: Use after free in ANGLE
* CVE-2026-7902: Out of bounds memory access in V8
* CVE-2026-7903: Integer overflow in ANGLE
* CVE-2026-7904: Out of bounds read in Fonts
* CVE-2026-7905: Insufficient validation of untrusted input in Media
* CVE-2026-7906: Use after free in SVG
* CVE-2026-7907: Use after free in DOM
* CVE-2026-7908: Use after free in Fullscreen
* CVE-2026-7909: Inappropriate implementation in ServiceWorker
* CVE-2026-7910: Use after free in Views
* CVE-2026-7911: Use after free in Aura
* CVE-2026-7912: Integer overflow in GPU
* CVE-2026-7913: Insufficient policy enforcement in DevTools
* CVE-2026-7914: Type Confusion in Accessibility
* CVE-2026-7915: Insufficient data validation in DevTools
* CVE-2026-7916: Insufficient data validation in InterestGroups
* CVE-2026-7917: Use after free in Fullscreen
* CVE-2026-7918: Use after free in GPU
* CVE-2026-7919: Use after free in Aura
* CVE-2026-7920: Use after free in Skia
* CVE-2026-7921: Use after free in Passwords
* CVE-2026-7922: Use after free in ServiceWorker
* CVE-2026-7923: Out of bounds write in Skia
* CVE-2026-7924: Uninitialized Use in Dawn
* CVE-2026-7925: Use after free in Chromoting
* CVE-2026-7926: Use after free in PresentationAPI
* CVE-2026-7927: Type Confusion in Runtime
* CVE-2026-7928: Use after free in WebRTC
* CVE-2026-7929: Use after free in MediaRecording
* CVE-2026-7930: Insufficient validation of untrusted input in Cookies
* CVE-2026-7931: Insufficient validation of untrusted input in iOS
* CVE-2026-7932: Insufficient policy enforcement in Downloads
* CVE-2026-7933: Out of bounds read in WebCodecs
* CVE-2026-7934: Insufficient validation of untrusted input in Popup Blocker
* CVE-2026-7935: Inappropriate implementation in Speech
* CVE-2026-7936: Object lifecycle issue in V8
* CVE-2026-7937: Insufficient policy enforcement in DevTools
* CVE-2026-7938: Use after free in CSS
* CVE-2026-7939: Inappropriate implementation in SanitizerAPI
* CVE-2026-7940: Use after free in V8
* CVE-2026-7941: Insufficient validation of untrusted input in Mobile
* CVE-2026-7942: Integer overflow in ANGLE
* CVE-2026-7943: Insufficient validation of untrusted input in ANGLE
* CVE-2026-7944: Insufficient validation of untrusted input in Persistent Cache
* CVE-2026-7945: Insufficient validation of untrusted input in COOP
* CVE-2026-7946: Insufficient policy enforcement in WebUI
* CVE-2026-7947: Insufficient validation of untrusted input in Network
* CVE-2026-7948: Race in Chromoting
* CVE-2026-7949: Out of bounds read in Skia
* CVE-2026-7950: Out of bounds read and write in GFX
* CVE-2026-7951: Out of bounds write in WebRTC
* CVE-2026-7952: Insufficient policy enforcement in Extensions
* CVE-2026-7953: Insufficient validation of untrusted input in Omnibox
* CVE-2026-7954: Race in Shared Storage
* CVE-2026-7955: Uninitialized Use in GPU
* CVE-2026-7956: Use after free in Navigation
* CVE-2026-7957: Out of bounds write in Media
* CVE-2026-7958: Inappropriate implementation in ServiceWorker
* CVE-2026-7959: Inappropriate implementation in Navigation
* CVE-2026-7960: Race in Speech
* CVE-2026-7961: Insufficient validation of untrusted input in Permissions
* CVE-2026-7962: Insufficient policy enforcement in DirectSockets
* CVE-2026-7963: Inappropriate implementation in ServiceWorker
* CVE-2026-7964: Insufficient validation of untrusted input in FileSystem
* CVE-2026-7965: Insufficient validation of untrusted input in DevTools
* CVE-2026-7966: Insufficient validation of untrusted input in SiteIsolation
* CVE-2026-7967: Insufficient validation of untrusted input in Navigation
* CVE-2026-7968: Insufficient validation of untrusted input in CORS
* CVE-2026-7969: Integer overflow in Network
* CVE-2026-7970: Use after free in TopChrome
* CVE-2026-7971: Inappropriate implementation in ORB
* CVE-2026-7972: Uninitialized Use in GPU
* CVE-2026-7973: Integer overflow in Dawn
* CVE-2026-7974: Use after free in Blink
* CVE-2026-7975: Use after free in DevTools
* CVE-2026-7976: Use after free in Views
* CVE-2026-7977: Inappropriate implementation in Canvas
* CVE-2026-7978: Inappropriate implementation in Companion
* CVE-2026-7979: Inappropriate implementation in Media
* CVE-2026-7980: Use after free in WebAudio
* CVE-2026-7981: Out of bounds read in Codecs
* CVE-2026-7982: Uninitialized Use in WebCodecs
* CVE-2026-7983: Out of bounds read in Dawn
* CVE-2026-7984: Use after free in ReadingMode
* CVE-2026-7985: Use after free in GPU
* CVE-2026-7986: Insufficient policy enforcement in Autofill
* CVE-2026-7987: Use after free in WebRTC
* CVE-2026-7988: Type Confusion in WebRTC
* CVE-2026-7989: Insufficient data validation in DataTransfer
* CVE-2026-7990: Insufficient validation of untrusted input in Updater
* CVE-2026-7991: Use after free in UI
* CVE-2026-7992: Insufficient validation of untrusted input in UI
* CVE-2026-7993: Insufficient validation of untrusted input in Payments
* CVE-2026-7994: Inappropriate implementation in Chromoting
* CVE-2026-7995: Out of bounds read in AdFilter
* CVE-2026-7996: Insufficient validation of untrusted input in SSL
* CVE-2026-7997: Insufficient validation of untrusted input in Updater
* CVE-2026-7998: Insufficient validation of untrusted input in Dialog
* CVE-2026-7999: Inappropriate implementation in V8
* CVE-2026-8000: Insufficient validation of untrusted input in ChromeDriver
* CVE-2026-8001: Use after free in Printing
* CVE-2026-8002: Use after free in Audio
* CVE-2026-8003: Insufficient validation of untrusted input in TabGroups
* CVE-2026-8004: Insufficient policy enforcement in DevTools
* CVE-2026-8005: Insufficient validation of untrusted input in Cast
* CVE-2026-8006: Insufficient policy enforcement in DevTools
* CVE-2026-8007: Insufficient validation of untrusted input in Cast
* CVE-2026-8008: Inappropriate implementation in DevTools
* CVE-2026-8009: Inappropriate implementation in Cast
* CVE-2026-8010: Insufficient validation of untrusted input in SiteIsolation
* CVE-2026-8011: Insufficient policy enforcement in Search
* CVE-2026-8012: Inappropriate implementation in MHTML
* CVE-2026-8013: Insufficient validation of untrusted input in FedCM
* CVE-2026-8014: Inappropriate implementation in Preload
* CVE-2026-8015: Inappropriate implementation in Media
* CVE-2026-8016: Use after free in WebRTC
* CVE-2026-8017: Side-channel information leakage in Media
* CVE-2026-8018: Insufficient policy enforcement in DevTools
* CVE-2026-8019: Insufficient policy enforcement in WebApp
* CVE-2026-8020: Uninitialized Use in GPU
* CVE-2026-8021: Script injection in UI
* CVE-2026-8022: Inappropriate implementation in MHTML

---
diff --git a/chromium.spec b/chromium.spec
index 9b66486..ad12858 100644
--- a/chromium.spec
+++ b/chromium.spec
@@ -1877,6 +1877,133 @@ fi
 %changelog
 * Wed May 06 2026 Than Ngo <than@redhat.com> - 148.0.7778.96-1
 - Update to 148.0.7778.96
+   * CVE-2026-7896: Integer overflow in Blink
+   * CVE-2026-7897: Use after free in Mobile
+   * CVE-2026-7898: Use after free in Chromoting
+   * CVE-2026-7899: Out of bounds read and write in V8
+   * CVE-2026-7900: Heap buffer overflow in ANGLE
+   * CVE-2026-7901: Use after free in ANGLE
+   * CVE-2026-7902: Out of bounds memory access in V8
+   * CVE-2026-7903: Integer overflow in ANGLE
+   * CVE-2026-7904: Out of bounds read in Fonts
+   * CVE-2026-7905: Insufficient validation of untrusted input in Media
+   * CVE-2026-7906: Use after free in SVG
+   * CVE-2026-7907: Use after free in DOM
+   * CVE-2026-7908: Use after free in Fullscreen
+   * CVE-2026-7909: Inappropriate implementation in ServiceWorker
+   * CVE-2026-7910: Use after free in Views
+   * CVE-2026-7911: Use after free in Aura
+   * CVE-2026-7912: Integer overflow in GPU
+   * CVE-2026-7913: Insufficient policy enforcement in DevTools
+   * CVE-2026-7914: Type Confusion in Accessibility
+   * CVE-2026-7915: Insufficient data validation in DevTools
+   * CVE-2026-7916: Insufficient data validation in InterestGroups
+   * CVE-2026-7917: Use after free in Fullscreen
+   * CVE-2026-7918: Use after free in GPU
+   * CVE-2026-7919: Use after free in Aura
+   * CVE-2026-7920: Use after free in Skia
+   * CVE-2026-7921: Use after free in Passwords
+   * CVE-2026-7922: Use after free in ServiceWorker
+   * CVE-2026-7923: Out of bounds write in Skia
+   * CVE-2026-7924: Uninitialized Use in Dawn
+   * CVE-2026-7925: Use after free in Chromoting
+   * CVE-2026-7926: Use after free in PresentationAPI
+   * CVE-2026-7927: Type Confusion in Runtime
+   * CVE-2026-7928: Use after free in WebRTC
+   * CVE-2026-7929: Use after free in MediaRecording
+   * CVE-2026-7930: Insufficient validation of untrusted input in Cookies
+   * CVE-2026-7931: Insufficient validation of untrusted input in iOS
+   * CVE-2026-7932: Insufficient policy enforcement in Downloads
+   * CVE-2026-7933: Out of bounds read in WebCodecs
+   * CVE-2026-7934: Insufficient validation of untrusted input in Popup Blocker
+   * CVE-2026-7935: Inappropriate implementation in Speech
+   * CVE-2026-7936: Object lifecycle issue in V8
+   * CVE-2026-7937: Insufficient policy enforcement in DevTools
+   * CVE-2026-7938: Use after free in CSS
+   * CVE-2026-7939: Inappropriate implementation in SanitizerAPI
+   * CVE-2026-7940: Use after free in V8
+   * CVE-2026-7941: Insufficient validation of untrusted input in Mobile
+   * CVE-2026-7942: Integer overflow in ANGLE
+   * CVE-2026-7943: Insufficient validation of untrusted input in ANGLE
+   * CVE-2026-7944: Insufficient validation of untrusted input in Persistent Cache
+   * CVE-2026-7945: Insufficient validation of untrusted input in COOP
+   * CVE-2026-7946: Insufficient policy enforcement in WebUI
+   * CVE-2026-7947: Insufficient validation of untrusted input in Network
+   * CVE-2026-7948: Race in Chromoting
+   * CVE-2026-7949: Out of bounds read in Skia
+   * CVE-2026-7950: Out of bounds read and write in GFX
+   * CVE-2026-7951: Out of bounds write in WebRTC
+   * CVE-2026-7952: Insufficient policy enforcement in Extensions
+   * CVE-2026-7953: Insufficient validation of untrusted input in Omnibox
+   * CVE-2026-7954: Race in Shared Storage
+   * CVE-2026-7955: Uninitialized Use in GPU
+   * CVE-2026-7956: Use after free in Navigation
+   * CVE-2026-7957: Out of bounds write in Media
+   * CVE-2026-7958: Inappropriate implementation in ServiceWorker
+   * CVE-2026-7959: Inappropriate implementation in Navigation
+   * CVE-2026-7960: Race in Speech
+   * CVE-2026-7961: Insufficient validation of untrusted input in Permissions
+   * CVE-2026-7962: Insufficient policy enforcement in DirectSockets
+   * CVE-2026-7963: Inappropriate implementation in ServiceWorker
+   * CVE-2026-7964: Insufficient validation of untrusted input in FileSystem
+   * CVE-2026-7965: Insufficient validation of untrusted input in DevTools
+   * CVE-2026-7966: Insufficient validation of untrusted input in SiteIsolation
+   * CVE-2026-7967: Insufficient validation of untrusted input in Navigation
+   * CVE-2026-7968: Insufficient validation of untrusted input in CORS
+   * CVE-2026-7969: Integer overflow in Network
+   * CVE-2026-7970: Use after free in TopChrome
+   * CVE-2026-7971: Inappropriate implementation in ORB
+   * CVE-2026-7972: Uninitialized Use in GPU
+   * CVE-2026-7973: Integer overflow in Dawn
+   * CVE-2026-7974: Use after free in Blink
+   * CVE-2026-7975: Use after free in DevTools
+   * CVE-2026-7976: Use after free in Views
+   * CVE-2026-7977: Inappropriate implementation in Canvas
+   * CVE-2026-7978: Inappropriate implementation in Companion
+   * CVE-2026-7979: Inappropriate implementation in Media
+   * CVE-2026-7980: Use after free in WebAudio
+   * CVE-2026-7981: Out of bounds read in Codecs
+   * CVE-2026-7982: Uninitialized Use in WebCodecs
+   * CVE-2026-7983: Out of bounds read in Dawn
+   * CVE-2026-7984: Use after free in ReadingMode
+   * CVE-2026-7985: Use after free in GPU
+   * CVE-2026-7986: Insufficient policy enforcement in Autofill
+   * CVE-2026-7987: Use after free in WebRTC
+   * CVE-2026-7988: Type Confusion in WebRTC
+   * CVE-2026-7989: Insufficient data validation in DataTransfer
+   * CVE-2026-7990: Insufficient validation of untrusted input in Updater
+   * CVE-2026-7991: Use after free in UI
+   * CVE-2026-7992: Insufficient validation of untrusted input in UI
+   * CVE-2026-7993: Insufficient validation of untrusted input in Payments
+   * CVE-2026-7994: Inappropriate implementation in Chromoting
+   * CVE-2026-7995: Out of bounds read in AdFilter
+   * CVE-2026-7996: Insufficient validation of untrusted input in SSL
+   * CVE-2026-7997: Insufficient validation of untrusted input in Updater
+   * CVE-2026-7998: Insufficient validation of untrusted input in Dialog
+   * CVE-2026-7999: Inappropriate implementation in V8
+   * CVE-2026-8000: Insufficient validation of untrusted input in ChromeDriver
+   * CVE-2026-8001: Use after free in Printing
+   * CVE-2026-8002: Use after free in Audio
+   * CVE-2026-8003: Insufficient validation of untrusted input in TabGroups
+   * CVE-2026-8004: Insufficient policy enforcement in DevTools
+   * CVE-2026-8005: Insufficient validation of untrusted input in Cast
+   * CVE-2026-8006: Insufficient policy enforcement in DevTools
+   * CVE-2026-8007: Insufficient validation of untrusted input in Cast
+   * CVE-2026-8008: Inappropriate implementation in DevTools
+   * CVE-2026-8009: Inappropriate implementation in Cast
+   * CVE-2026-8010: Insufficient validation of untrusted input in SiteIsolation
+   * CVE-2026-8011: Insufficient policy enforcement in Search
+   * CVE-2026-8012: Inappropriate implementation in MHTML
+   * CVE-2026-8013: Insufficient validation of untrusted input in FedCM
+   * CVE-2026-8014: Inappropriate implementation in Preload
+   * CVE-2026-8015: Inappropriate implementation in Media
+   * CVE-2026-8016: Use after free in WebRTC
+   * CVE-2026-8017: Side-channel information leakage in Media
+   * CVE-2026-8018: Insufficient policy enforcement in DevTools
+   * CVE-2026-8019: Insufficient policy enforcement in WebApp
+   * CVE-2026-8020: Uninitialized Use in GPU
+   * CVE-2026-8021: Script injection in UI
+   * CVE-2026-8022: Inappropriate implementation in MHTML
 - Remove old remoting-no-tests patch
 - Remove fix_GL_native_pixmap_import_support_reset_in_GpuInit patch
 - Fix build error causing by sanitizer defines in GN

             reply	other threads:[~2026-08-07 16:08 UTC|newest]

Thread overview: 2+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-07 16:08 Than Ngo [this message]
  -- strict thread matches above, loose matches on Subject: below --
2026-08-07 16:08 [rpms/chromium] epel9-next: - Update to 148.0.7778.96 Than Ngo

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=178611893996.1.13160682954600545940.rpms-chromium-8db3c4a88b3b@fedoraproject.org \
    --to=than@redhat.com \
    --cc=git-commits@fedoraproject.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox