openSUSE-SU-2026:20332-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:20332-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/openSUSE-SU-2026:20332-1
Upstream
CVE (28)
Related
Published
2026-08-31T08:39:48Z
Modified
2026-09-02T18:27:35Z
Summary
Security update for chromium
Details

This update for chromium fixes the following issues:

Changes in chromium:

  • Chromium 145.0.7632.159 (boo#1259213)

    • CVE-2026-3536: Integer overflow in ANGLE
    • CVE-2026-3537: Object lifecycle issue in PowerVR
    • CVE-2026-3538: Integer overflow in Skia
    • CVE-2026-3539: Object lifecycle issue in DevTools
    • CVE-2026-3540: Inappropriate implementation in WebAudio
    • CVE-2026-3541: Inappropriate implementation in CSS
    • CVE-2026-3542: Inappropriate implementation in WebAssembly
    • CVE-2026-3543: Inappropriate implementation in V8
    • CVE-2026-3544: Heap buffer overflow in WebCodecs
    • CVE-2026-3545: Insufficient data validation in Navigation
  • Chromium 145.0.7632.116 (boo#1258733):

    • CVE-2026-3061: Out of bounds read in Media
    • CVE-2026-3062: Out of bounds read and write in Tint
    • CVE-2026-3063: Inappropriate implementation in DevTools
  • Chromium 145.0.7632.109 (boo#1258438):

    • CVE-2026-2648: Heap buffer overflow in PDFium
    • CVE-2026-2649: Integer overflow in V8
    • CVE-2026-2650: Heap buffer overflow in Media
  • more fixes for desktop file, some variables were lowercased, further adaptions in INSTALL script (boo#1258199)

  • also copy rollup into third_party/node/node_modules

  • stay on llvm-10 for swiftshader but bring a similar patch

  • drop use of rollup binaries and use rollup-3.x which does not use prebuilt binaries (that fail at least on older ppc64le) follow the approach of the debian packaging

  • update/resync ppc64le patches from fedora

  • fix INSTALL.sh again to replace the tags in desktop file, appdata and manpage (boo#1258199)

  • Chromium 145.0.7632.75:

    • CVE-2026-2441: Use after free in CSS (boo#1258185)
  • Chromium 145.0.7632.67:

    • Revert a change in url_fixer that may have caused crashes
  • Chromium 145.0.7632.45 (boo#1258116)

    • jpeg-xl support has been readded
    • CVE-2026-2313: Use after free in CSS
    • CVE-2026-2314: Heap buffer overflow in Codecs
    • CVE-2026-2315: Inappropriate implementation in WebGPU
    • CVE-2026-2316: Insufficient policy enforcement in Frames
    • CVE-2026-2317: Inappropriate implementation in Animation
    • CVE-2026-2318: Inappropriate implementation in PictureInPicture
    • CVE-2026-2319: Race in DevTools
    • CVE-2026-2320: Inappropriate implementation in File input
    • CVE-2026-2321: Use after free in Ozone
    • CVE-2026-2322: Inappropriate implementation in File input
    • CVE-2026-2323: Inappropriate implementation in Downloads
References

Affected packages

openSUSE:Leap 16.0 / chromium

Package

Name
chromium
Purl
pkg:rpm/opensuse/chromium&distro=openSUSE%20Leap%2016.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
145.0.7632.159-bp160.1.1

Ecosystem specific

{
    "binaries":  [
        {
            "chromedriver":  "145.0.7632.159-bp160.1.1",
            "chromium":  "145.0.7632.159-bp160.1.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:20332-1.json"