openSUSE Security Update: Security update for chromium ______________________________________________________________________________ Announcement ID: openSUSE-SU-2025:0301-1 Rating: important References: #1247981 Cross-References: CVE-2025-8879 CVE-2025-8880 CVE-2025-8881 CVE-2025-8882 CVE-2025-8901 Affected Products: openSUSE Backports SLE-15-SP7 ______________________________________________________________________________ An update that fixes 5 vulnerabilities is now available. Description: This update for chromium fixes the following issues: Chromium 139.0.7258.127 (boo#1247981): * CVE-2025-8879: Heap buffer overflow in libaom * CVE-2025-8880: Race in V8 * CVE-2025-8901: Out of bounds write in ANGLE * CVE-2025-8881: Inappropriate implementation in File Picker * CVE-2025-8882: Use after free in Aura * Various fixes from internal audits, fuzzing and other initiatives Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP7: zypper in -t patch openSUSE-2025-301=1 Package List: - openSUSE Backports SLE-15-SP7 (aarch64 ppc64le x86_64): chromedriver-139.0.7258.127-bp157.2.37.1 chromedriver-debuginfo-139.0.7258.127-bp157.2.37.1 chromium-139.0.7258.127-bp157.2.37.1 chromium-debuginfo-139.0.7258.127-bp157.2.37.1 References: https://www.suse.com/security/cve/CVE-2025-8879.html https://www.suse.com/security/cve/CVE-2025-8880.html https://www.suse.com/security/cve/CVE-2025-8881.html https://www.suse.com/security/cve/CVE-2025-8882.html https://www.suse.com/security/cve/CVE-2025-8901.html https://bugzilla.suse.com/1247981