File chromium-ffmpeg-extra.changes of Package chromium-ffmpeg-extra
937
1
-------------------------------------------------------------------
2
Sun Jul 16 07:54:55 UTC 2023 - Carsten Ziepke <kieltux@gmail.com>
3
4
- Rebase chromium 114.0.5735.198 for use as chromium-ffmpeg-extra
5
6
-------------------------------------------------------------------
7
Tue Jun 27 07:39:29 UTC 2023 - Andreas Stieger <andreas.stieger@gmx.de>
8
9
- Chromium 114.0.5735.198 (boo#1212755):
10
* CVE-2023-3420: Type Confusion in V8
11
* CVE-2023-3421: Use after free in Media
12
* CVE-2023-3422: Use after free in Guest View
13
14
-------------------------------------------------------------------
15
Sun Jun 25 09:54:37 UTC 2023 - Callum Farmer <gmbr3@opensuse.org>
16
17
- Install Qt5 library & prepare for Qt6 in 115
18
19
-------------------------------------------------------------------
20
Wed Jun 14 05:23:16 UTC 2023 - Andreas Stieger <andreas.stieger@gmx.de>
21
22
- Chromium 114.0.5735.133 (boo#1212302):
23
* CVE-2023-3214: Use after free in Autofill payments
24
* CVE-2023-3215: Use after free in WebRTC
25
* CVE-2023-3216: Type Confusion in V8
26
* CVE-2023-3217: Use after free in WebXR
27
* Various fixes from internal audits, fuzzing and other initiatives
28
29
-------------------------------------------------------------------
30
Wed Jun 7 18:13:06 UTC 2023 - Andreas Stieger <Andreas.Stieger@gmx.de>
31
32
- Fix Leap 15.4 build - chromium-114-revert-av1enc-lp154.patch
33
34
-------------------------------------------------------------------
35
Tue Jun 6 05:34:13 UTC 2023 - Andreas Stieger <andreas.stieger@gmx.de>
36
37
- Chromium 114.0.5735.106 (boo#1212044):
38
* CVE-2023-3079: Type Confusion in V8
39
40
-------------------------------------------------------------------
41
Sun Jun 4 18:52:01 UTC 2023 - Callum Farmer <gmbr3@opensuse.org>
42
43
- Chromium 114.0.5735.90 (boo#1211843):
44
* CSS text-wrap: balance is available
45
* Cookies partitioned by top level site (CHIPS)
46
* New Popover API
47
- Security fixes:
48
* CVE-2023-2929: Out of bounds write in Swiftshader
49
* CVE-2023-2930: Use after free in Extensions
50
* CVE-2023-2931: Use after free in PDF
51
* CVE-2023-2932: Use after free in PDF
52
* CVE-2023-2933: Use after free in PDF
53
* CVE-2023-2934: Out of bounds memory access in Mojo
54
* CVE-2023-2935: Type Confusion in V8
55
* CVE-2023-2936: Type Confusion in V8
56
* CVE-2023-2937: Inappropriate implementation in Picture In Picture
57
* CVE-2023-2938: Inappropriate implementation in Picture In Picture
58
* CVE-2023-2939: Insufficient data validation in Installer
59
* CVE-2023-2940: Inappropriate implementation in Downloads
60
* CVE-2023-2941: Inappropriate implementation in Extensions API
61
- Drop patches:
62
* chromium-103-VirtualCursor-std-layout.patch
63
* chromium-113-system-zlib.patch
64
* chromium-113-workaround_clang_bug-structured_binding.patch
65
- Add patches
66
* chromium-114-workaround_clang_bug-structured_binding.patch
67
* chromium-114-lld-argument.patch
68
69
-------------------------------------------------------------------
70
Tue May 30 21:53:45 UTC 2023 - Callum Farmer <gmbr3@opensuse.org>
71
72
- Un-bundle zlib again
73
- Remove un-needed patches:
74
* chromium-112-default-comparison-operators.patch
75
* chromium-109-clang-lp154.patch
76
* chromium-clang-nomerge.patch
77
* chromium-ffmpeg-lp152.patch
78
* chromium-lp151-old-drm.patch
79
- Added patches:
80
* chromium-113-system-zlib.patch
81
82
-------------------------------------------------------------------
83
Sun May 28 21:32:03 UTC 2023 - Andreas Stieger <andreas.stieger@gmx.de>
84
85
- build with llvm15 on Leap
86
87
-------------------------------------------------------------------
88
Tue May 16 21:16:23 UTC 2023 - Andreas Stieger <Andreas.Stieger@gmx.de>
89
90
- Chromium 113.0.5672.126 (boo#1211442):
91
* CVE-2023-2721: Use after free in Navigation
92
* CVE-2023-2722: Use after free in Autofill UI
93
* CVE-2023-2723: Use after free in DevTools
94
* CVE-2023-2724: Type Confusion in V8
95
* CVE-2023-2725: Use after free in Guest View
96
* CVE-2023-2726: Inappropriate implementation in WebApp Installs
97
* Various fixes from internal audits, fuzzing and other initiatives
98
99
-------------------------------------------------------------------
100
Tue May 9 19:14:20 UTC 2023 - Andreas Stieger <Andreas.Stieger@gmx.de>
101
102
- Chromium 113.0.5672.92 (boo#1211211)
103
- Multiple security fixes (boo#1211036):
104
* CVE-2023-2459: Inappropriate implementation in Prompts
105
* CVE-2023-2460: Insufficient validation of untrusted input in Extensions
106
* CVE-2023-2461: Use after free in OS Inputs
107
* CVE-2023-2462: Inappropriate implementation in Prompts
108
* CVE-2023-2463: Inappropriate implementation in Full Screen Mode
109
* CVE-2023-2464: Inappropriate implementation in PictureInPicture
110
* CVE-2023-2465: Inappropriate implementation in CORS
111
* CVE-2023-2466: Inappropriate implementation in Prompts
112
* CVE-2023-2467: Inappropriate implementation in Prompts
113
* CVE-2023-2468: Inappropriate implementation in PictureInPicture
114
- drop chromium-94-sql-no-assert.patch
115
- drop no-location-leap151.patch
116
- add chromium-113-webview-namespace.patch
117
- add chromium-113-webauth-include-variant.patch
118
- add chromium-113-typename.patch
119
- add chromium-113-workaround_clang_bug-structured_binding.patch
120
121
-------------------------------------------------------------------
122
Wed Apr 19 19:55:51 UTC 2023 - Andreas Stieger <Andreas.Stieger@gmx.de>
123
124
- Chromium 112.0.5615.165 (boo#1210618):
125
* CVE-2023-2133: Out of bounds memory access in Service Worker API
126
* CVE-2023-2134: Out of bounds memory access in Service Worker API
127
* CVE-2023-2135: Use after free in DevTools
128
* CVE-2023-2136: Integer overflow in Skia
129
* CVE-2023-2137: Heap buffer overflow in sqlite
130
- drop chromium-112-feed_protos.patch
131
132
-------------------------------------------------------------------
133
Sun Apr 16 02:10:30 UTC 2023 - Andreas Stieger <andreas.stieger@gmx.de>
134
135
- Fix Leap 15.4 build failures from default comparison operators
136
defined outside of the class definition, a C++20 feature
137
adding chromium-112-default-comparison-operators.patch
138
139
-------------------------------------------------------------------
140
Sat Apr 15 10:49:51 UTC 2023 - Andreas Stieger <andreas.stieger@gmx.de>
141
142
- Chromium 112.0.5615.121:
143
* CVE-2023-2033: Type Confusion in V8 (boo#1210478)
144
145
-------------------------------------------------------------------
146
Fri Apr 7 07:57:40 UTC 2023 - Andreas Stieger <andreas.stieger@gmx.de>
147
148
- Revert a breaking change with chromium-112-feed_protos.patch
149
150
-------------------------------------------------------------------
151
Tue Apr 4 22:38:23 UTC 2023 - Andreas Stieger <andreas.stieger@gmx.de>
152
153
- Chromium 112.0.5615.49
154
* CSS now supports nesting rules.
155
* The algorithm to set the initial focus on <dialog> elements was updated.
156
* No-op fetch() handlers on service workers are skipped from now on to make navigations faster
157
* The setter for document.domain is now deprecated.
158
* The recorder in devtools can now record with pierce selectors.
159
* Security fixes (boo#1210126):
160
* CVE-2023-1810: Heap buffer overflow in Visuals
161
* CVE-2023-1811: Use after free in Frames
162
* CVE-2023-1812: Out of bounds memory access in DOM Bindings
163
* CVE-2023-1813: Inappropriate implementation in Extensions
164
* CVE-2023-1814: Insufficient validation of untrusted input in Safe Browsing
165
* CVE-2023-1815: Use after free in Networking APIs
166
* CVE-2023-1816: Incorrect security UI in Picture In Picture
167
* CVE-2023-1817: Insufficient policy enforcement in Intents
168
* CVE-2023-1818: Use after free in Vulkan
169
* CVE-2023-1819: Out of bounds read in Accessibility
170
* CVE-2023-1820: Heap buffer overflow in Browser History
171
* CVE-2023-1821: Inappropriate implementation in WebShare
172
* CVE-2023-1822: Incorrect security UI in Navigation
173
* CVE-2023-1823: Inappropriate implementation in FedCM
174
-------------------------------------------------------------------
175
Sun Apr 2 10:10:49 UTC 2023 - Carsten Ziepke <kieltux@gmail.com>
176
177
- Use gcc11/gcc11-c++ for openSUSE Leap, use gcc12/gcc12-c++
178
for openSUSE Tumbleweed, because fails with gcc13/gcc13-c++
179
180
-------------------------------------------------------------------
181
Thu Jul 14 16:38:50 UTC 2022 - Carsten Ziepke <kieltux@gmail.com>
182
183
- Rebase chromium 103.0.5060.114 for use as chromium-ffmpeg-extra
184
- Fixes problems with audio and youtube video playback
185
186
-------------------------------------------------------------------
187
Sat Jul 9 12:52:33 UTC 2022 - Andreas Stieger <andreas.stieger@gmx.de>
188
189
- Chromium 103.0.5060.114 (boo#1201216)
190
* CVE-2022-2294: Heap buffer overflow in WebRTC
191
* CVE-2022-2295: Type Confusion in V8
192
* CVE-2022-2296: Use after free in Chrome OS Shell
193
194
-------------------------------------------------------------------
195
Thu Jul 7 18:07:43 UTC 2022 - Andreas Stieger <andreas.stieger@gmx.de>
196
197
- Chromium 103.0.5060.66
198
* no upstream release notes
199
200
-------------------------------------------------------------------
201
Sat Jun 25 10:43:48 UTC 2022 - Callum Farmer <gmbr3@opensuse.org>
202
203
- Chromium 103.0.5060.53 (boo#1200783)
204
* CVE-2022-2156: Use after free in Base
205
* CVE-2022-2157: Use after free in Interest groups
206
* CVE-2022-2158: Type Confusion in V8
207
* CVE-2022-2160: Insufficient policy enforcement in DevTools
208
* CVE-2022-2161: Use after free in WebApp Provider
209
* CVE-2022-2162: Insufficient policy enforcement in File System API
210
* CVE-2022-2163: Use after free in Cast UI and Toolbar
211
* CVE-2022-2164: Inappropriate implementation in Extensions API
212
* CVE-2022-2165: Insufficient data validation in URL formatting
213
- Added patches:
214
* chromium-103-FrameLoadRequest-type.patch
215
* chromium-103-SubstringSetMatcher-packed.patch
216
* chromium-103-VirtualCursor-std-layout.patch
217
* chromium-103-compiler.patch
218
- Removed patches:
219
* chromium-102-compiler.patch
220
* chromium-91-sql-standard-layout-type.patch
221
* chromium-101-libxml-unbundle.patch
222
* chromium-102-fenced_frame_utils-include.patch
223
* chromium-102-swiftshader-template-instantiation.patch
224
* chromium-102-symbolize-include.patch
225
* chromium-97-arm-tflite-cast.patch
226
* chromium-97-ScrollView-reference.patch
227
228
-------------------------------------------------------------------
229
Fri Jun 10 15:35:20 UTC 2022 - Andreas Stieger <andreas.stieger@gmx.de>
230
231
- Chromium 102.0.5005.115 (boo#1200423)
232
* CVE-2022-2007: Use after free in WebGPU
233
* CVE-2022-2008: Out of bounds memory access in WebGL
234
* CVE-2022-2010: Out of bounds read in compositing
235
* CVE-2022-2011: Use after free in ANGLE
236
237
-------------------------------------------------------------------
238
Wed Jun 8 13:40:43 UTC 2022 - Callum Farmer <gmbr3@opensuse.org>
239
240
- Switch to GTK4 on TW and Leap 15.4+ (boo#1200139)
241
242
-------------------------------------------------------------------
243
Wed Jun 1 09:43:54 UTC 2022 - Callum Farmer <gmbr3@opensuse.org>
244
245
- Disable ARM control flow integrity, it causes build issues
246
at the moment
247
- Try a different SVG (black logo on GNOME)
248
- Removed patches:
249
* chromium-third_party-symbolize-missing-include.patch
250
(replaced by chromium-102-symbolize-include.patch)
251
252
-------------------------------------------------------------------
253
Fri May 27 19:40:42 UTC 2022 - Callum Farmer <gmbr3@opensuse.org>
254
255
- Chromium 102.0.5001.61 (boo#1199893)
256
* CVE-2022-1853: Use after free in Indexed DB
257
* CVE-2022-1854: Use after free in ANGLE
258
* CVE-2022-1855: Use after free in Messaging
259
* CVE-2022-1856: Use after free in User Education
260
* CVE-2022-1857: Insufficient policy enforcement in File System API
261
* CVE-2022-1858: Out of bounds read in DevTools
262
* CVE-2022-1859: Use after free in Performance Manager
263
* CVE-2022-1860: Use after free in UI Foundations
264
* CVE-2022-1861: Use after free in Sharing
265
* CVE-2022-1862: Inappropriate implementation in Extensions
266
* CVE-2022-1863: Use after free in Tab Groups
267
* CVE-2022-1864: Use after free in WebApp Installs
268
* CVE-2022-1865: Use after free in Bookmarks
269
* CVE-2022-1866: Use after free in Tablet Mode
270
* CVE-2022-1867: Insufficient validation of untrusted input in Data Transfer
271
* CVE-2022-1868: Inappropriate implementation in Extensions API
272
* CVE-2022-1869: Type Confusion in V8
273
* CVE-2022-1870: Use after free in App Service
274
* CVE-2022-1871: Insufficient policy enforcement in File System API
275
* CVE-2022-1872: Insufficient policy enforcement in Extensions API
276
* CVE-2022-1873: Insufficient policy enforcement in COOP
277
* CVE-2022-1874: Insufficient policy enforcement in Safe Browsing
278
* CVE-2022-1875: Inappropriate implementation in PDF
279
* CVE-2022-1876: Heap buffer overflow in DevTools
280
- Added patches:
281
* chromium-102-compiler.patch
282
* chromium-102-fenced_frame_utils-include.patch
283
* chromium-102-regex_pattern-array.patch
284
* chromium-102-swiftshader-template-instantiation.patch
285
* chromium-102-symbolize-include.patch
286
* ffmpeg-new-channel-layout.patch
287
- Removed patches:
288
* chromium-100-compiler.patch
289
* chromium-80-QuicStreamSendBuffer-deleted-move-constructor.patch
290
* chromium-95-quiche-include.patch
291
* chromium-fix-swiftshader-template.patch
292
* chromium-missing-include-tuple.patch
293
* chromium-webrtc-stats-missing-vector.patch
294
* chromium-101-segmentation_platform-type.patch
295
296
-------------------------------------------------------------------
297
Sun May 15 09:03:28 UTC 2022 - Andreas Stieger <andreas.stieger@gmx.de>
298
299
- Chromium 101.0.4951.67
300
* fixes for other platforms
301
302
-------------------------------------------------------------------
303
Wed May 11 06:33:01 UTC 2022 - Andreas Stieger <andreas.stieger@gmx.de>
304
305
- Chromium 101.0.4951.64 (boo#1199409)
306
* CVE-2022-1633: Use after free in Sharesheet
307
* CVE-2022-1634: Use after free in Browser UI
308
* CVE-2022-1635: Use after free in Permission Prompts
309
* CVE-2022-1636: Use after free in Performance APIs
310
* CVE-2022-1637: Inappropriate implementation in Web Contents
311
* CVE-2022-1638: Heap buffer overflow in V8 Internationalization
312
* CVE-2022-1639: Use after free in ANGLE
313
* CVE-2022-1640: Use after free in Sharing
314
* CVE-2022-1641: Use after free in Web UI Diagnostics
315
316
-------------------------------------------------------------------
317
Wed May 4 09:34:58 UTC 2022 - Callum Farmer <gmbr3@opensuse.org>
318
319
- Chromium 101.0.4951.54 (boo#1199118)
320
- Chromium 101.0.4951.41 (boo#1198917)
321
* CVE-2022-1477: Use after free in Vulkan
322
* CVE-2022-1478: Use after free in SwiftShader
323
* CVE-2022-1479: Use after free in ANGLE
324
* CVE-2022-1480: Use after free in Device API
325
* CVE-2022-1481: Use after free in Sharing
326
* CVE-2022-1482: Inappropriate implementation in WebGL
327
* CVE-2022-1483: Heap buffer overflow in WebGPU
328
* CVE-2022-1484: Heap buffer overflow in Web UI Settings
329
* CVE-2022-1485: Use after free in File System API
330
* CVE-2022-1486: Type Confusion in V8
331
* CVE-2022-1487: Use after free in Ozone
332
* CVE-2022-1488: Inappropriate implementation in Extensions API
333
* CVE-2022-1489: Out of bounds memory access in UI Shelf
334
* CVE-2022-1490: Use after free in Browser Switcher
335
* CVE-2022-1491: Use after free in Bookmarks
336
* CVE-2022-1492: Insufficient data validation in Blink Editing
337
* CVE-2022-1493: Use after free in Dev Tools
338
* CVE-2022-1494: Insufficient data validation in Trusted Types
339
* CVE-2022-1495: Incorrect security UI in Downloads
340
* CVE-2022-1496: Use after free in File Manager
341
* CVE-2022-1497: Inappropriate implementation in Input
342
* CVE-2022-1498: Inappropriate implementation in HTML Parser
343
* CVE-2022-1499: Inappropriate implementation in WebAuthentication
344
* CVE-2022-1500: Insufficient data validation in Dev Tools
345
* CVE-2022-1501: Inappropriate implementation in iframe
346
- Added patches:
347
* chromium-101-libxml-unbundle.patch
348
* chromium-101-segmentation_platform-type.patch
349
- Removed patches:
350
* chromium-100-SCTHashdanceMetadata-move.patch
351
* chromium-100-GLImplementationParts-constexpr.patch
352
* chromium-100-macro-typo.patch
353
354
-------------------------------------------------------------------
355
Sun Apr 24 05:23:26 UTC 2022 - Carsten Ziepke <kieltux@gmail.com>
356
357
- Rebase chromium 100.0.4896.127 for use as chromium-ffmpeg-extra
358
359
-------------------------------------------------------------------
360
Thu Apr 21 10:04:22 UTC 2022 - Callum Farmer <gmbr3@opensuse.org>
361
362
- Fixes for go 1.18
363
364
-------------------------------------------------------------------
365
Fri Apr 15 07:29:35 UTC 2022 - Andreas Stieger <andreas.stieger@gmx.de>
366
367
- Chromium 100.0.4896.127 (boo#1198509)
368
* CVE-2022-1364: Type Confusion in V8
369
* Various fixes from internal audits, fuzzing and other initiatives
370
371
-------------------------------------------------------------------
372
Tue Apr 12 05:02:45 UTC 2022 - Andreas Stieger <andreas.stieger@gmx.de>
373
374
- Chromium 100.0.4896.88 (boo#1198361)
375
* CVE-2022-1305: Use after free in storage
376
* CVE-2022-1306: Inappropriate implementation in compositing
377
* CVE-2022-1307: Inappropriate implementation in full screen
378
* CVE-2022-1308: Use after free in BFCache
379
* CVE-2022-1309: Insufficient policy enforcement in developer tools
380
* CVE-2022-1310: Use after free in regular expressions
381
* CVE-2022-1311: Use after free in Chrome OS shell
382
* CVE-2022-1312: Use after free in storage
383
* CVE-2022-1313: Use after free in tab groups
384
* CVE-2022-1314: Type Confusion in V8
385
* Various fixes from internal audits, fuzzing and other initiatives
386
387
-------------------------------------------------------------------
388
Sun Apr 10 13:52:31 UTC 2022 - Callum Farmer <gmbr3@opensuse.org>
389
390
- Patches for GCC 12:
391
* chromium-fix-swiftshader-template.patch
392
* chromium-missing-include-tuple.patch
393
* chromium-webrtc-stats-missing-vector.patch
394
395
-------------------------------------------------------------------
396
Tue Apr 5 02:11:03 UTC 2022 - Andreas Stieger <andreas.stieger@gmx.de>
397
398
- Chromium 100.0.4896.75:
399
* CVE-2022-1232: Type Confusion in V8 (boo#1198053)
400
401
-------------------------------------------------------------------
402
Wed Mar 30 16:25:44 UTC 2022 - Callum Farmer <gmbr3@opensuse.org>
403
404
- Chromium 100.0.4896.60 (boo#1197680)
405
* CVE-2022-1125: Use after free in Portals
406
* CVE-2022-1127: Use after free in QR Code Generator
407
* CVE-2022-1128: Inappropriate implementation in Web Share API
408
* CVE-2022-1129: Inappropriate implementation in Full Screen Mode
409
* CVE-2022-1130: Insufficient validation of untrusted input in WebOTP
410
* CVE-2022-1131: Use after free in Cast UI
411
* CVE-2022-1132: Inappropriate implementation in Virtual Keyboard
412
* CVE-2022-1133: Use after free in WebRTC
413
* CVE-2022-1134: Type Confusion in V8
414
* CVE-2022-1135: Use after free in Shopping Cart
415
* CVE-2022-1136: Use after free in Tab Strip
416
* CVE-2022-1137: Inappropriate implementation in Extensions
417
* CVE-2022-1138: Inappropriate implementation in Web Cursor
418
* CVE-2022-1139: Inappropriate implementation in Background Fetch API
419
* CVE-2022-1141: Use after free in File Manager
420
* CVE-2022-1142: Heap buffer overflow in WebUI
421
* CVE-2022-1143: Heap buffer overflow in WebUI
422
* CVE-2022-1144: Use after free in WebUI
423
* CVE-2022-1145: Use after free in Extensions
424
* CVE-2022-1146: Inappropriate implementation in Resource Timing
425
- Added patches:
426
* chromium-100-compiler.patch
427
* chromium-100-GLImplementationParts-constexpr.patch
428
* chromium-100-InMilliseconds-constexpr.patch
429
* chromium-100-SCTHashdanceMetadata-move.patch
430
* chromium-100-macro-typo.patch
431
- Removed patches:
432
* chromium-98-compiler.patch
433
* chromium-86-nearby-explicit.patch
434
* chromium-glibc-2.34.patch
435
* chromium-v8-missing-utility-include.patch
436
* chromium-99-AutofillAssistantModelExecutor-NoDestructor.patch
437
438
-------------------------------------------------------------------
439
Tue Mar 29 09:23:28 UTC 2022 - Andreas Schwab <schwab@suse.de>
440
441
- Update disk constraints
442
443
-------------------------------------------------------------------
444
Sat Mar 26 15:10:15 UTC 2022 - Andreas Stieger <andreas.stieger@gmx.de>
445
446
- Chromium 99.0.4844.84:
447
* CVE-2022-1096: Type Confusion in V8 (boo#1197552)
448
449
-------------------------------------------------------------------
450
Mon Mar 21 05:07:25 UTC 2022 - Andreas Stieger <andreas.stieger@gmx.de>
451
452
- Chromium 99.0.4844.82:
453
* Fix potential problem in Hangouts (boo#1197332)
454
455
-------------------------------------------------------------------
456
Wed Mar 16 09:36:49 UTC 2022 - Andreas Stieger <andreas.stieger@gmx.de>
457
458
- Chromium 99.0.4844.74 (boo#1197163)
459
* CVE-2022-0971: Use after free in Blink Layout
460
* CVE-2022-0972: Use after free in Extensions
461
* CVE-2022-0973: Use after free in Safe Browsing
462
* CVE-2022-0974: Use after free in Splitscreen
463
* CVE-2022-0975: Use after free in ANGLE
464
* CVE-2022-0976: Heap buffer overflow in GPU
465
* CVE-2022-0977: Use after free in Browser UI
466
* CVE-2022-0978: Use after free in ANGLE
467
* CVE-2022-0979: Use after free in Safe Browsing
468
* CVE-2022-0980: Use after free in New Tab Page
469
* Various fixes from internal audits, fuzzing and other initiatives
470
471
-------------------------------------------------------------------
472
Fri Mar 4 10:46:36 UTC 2022 - Callum Farmer <gmbr3@opensuse.org>
473
474
- Chromium 99.0.4844.51 (boo#1196641)
475
* CVE-2022-0789: Heap buffer overflow in ANGLE
476
* CVE-2022-0790: Use after free in Cast UI
477
* CVE-2022-0791: Use after free in Omnibox
478
* CVE-2022-0792: Out of bounds read in ANGLE
479
* CVE-2022-0793: Use after free in Views
480
* CVE-2022-0794: Use after free in WebShare
481
* CVE-2022-0795: Type Confusion in Blink Layout
482
* CVE-2022-0796: Use after free in Media
483
* CVE-2022-0797: Out of bounds memory access in Mojo
484
* CVE-2022-0798: Use after free in MediaStream
485
* CVE-2022-0799: Insufficient policy enforcement in Installer
486
* CVE-2022-0800: Heap buffer overflow in Cast UI
487
* CVE-2022-0801: Inappropriate implementation in HTML parser
488
* CVE-2022-0802: Inappropriate implementation in Full screen mode
489
* CVE-2022-0803: Inappropriate implementation in Permissions
490
* CVE-2022-0804: Inappropriate implementation in Full screen mode
491
* CVE-2022-0805: Use after free in Browser Switcher
492
* CVE-2022-0806: Data leak in Canvas
493
* CVE-2022-0807: Inappropriate implementation in Autofill
494
* CVE-2022-0808: Use after free in Chrome OS Shell
495
* CVE-2022-0809: Out of bounds memory access in WebXR
496
- Removed patches:
497
* chromium-96-EnumTable-crash.patch
498
* chromium-89-missing-cstring-header.patch
499
* chromium-95-libyuv-aarch64.patch
500
* chromium-95-libyuv-arm.patch
501
* chromium-98-MiraclePtr-gcc-ice.patch
502
* chromium-98-WaylandFrameManager-check.patch
503
- Added patches:
504
* chromium-97-arm-tflite-cast.patch
505
* chromium-98-gtk4-build.patch
506
* chromium-99-AutofillAssistantModelExecutor-NoDestructor.patch
507
* chromium-98-EnumTable-crash.patch
508
* chromium-third_party-symbolize-missing-include.patch
509
* chromium-v8-missing-utility-include.patch
510
511
-------------------------------------------------------------------
512
Tue Feb 15 19:13:43 UTC 2022 - Andreas Stieger <andreas.stieger@gmx.de>
513
514
- Chromium 98.0.4758.102 (boo#1195986)
515
* CVE-2022-0603: Use after free in File Manager
516
* CVE-2022-0604: Heap buffer overflow in Tab Groups
517
* CVE-2022-0605: Use after free in Webstore API
518
* CVE-2022-0606: Use after free in ANGLE
519
* CVE-2022-0607: Use after free in GPU
520
* CVE-2022-0608: Integer overflow in Mojo
521
* CVE-2022-0609: Use after free in Animation
522
* CVE-2022-0610: Inappropriate implementation in Gamepad API
523
* Various fixes from internal audits, fuzzing and other initiatives
524
525
-------------------------------------------------------------------
526
Thu Feb 3 19:35:46 UTC 2022 - Andreas Stieger <andreas.stieger@gmx.de>
527
528
- Chromium 98.0.4758.80 (boo#1195420)
529
* CVE-2022-0452: Use after free in Safe Browsing
530
* CVE-2022-0453: Use after free in Reader Mode
531
* CVE-2022-0454: Heap buffer overflow in ANGLE
532
* CVE-2022-0455: Inappropriate implementation in Full Screen Mode
533
* CVE-2022-0456: Use after free in Web Search
534
* CVE-2022-0457: Type Confusion in V8
535
* CVE-2022-0459: Use after free in Screen Capture
536
* CVE-2022-0460: Use after free in Window Dialog
537
* CVE-2022-0461: Policy bypass in COOP
538
* CVE-2022-0462: Inappropriate implementation in Scroll
539
* CVE-2022-0463: Use after free in Accessibility
540
* CVE-2022-0464: Use after free in Accessibility
541
* CVE-2022-0465: Use after free in Extensions
542
* CVE-2022-0466: Inappropriate implementation in Extensions Platform
543
* CVE-2022-0467: Inappropriate implementation in Pointer Lock
544
* CVE-2022-0468: Use after free in Payments
545
* CVE-2022-0469: Use after free in Cast
546
* CVE-2022-0470: Out of bounds memory access in V8
547
* Various fixes from internal audits, fuzzing and other initiatives
548
- drop upstreamed patches:
549
* chromium-97-Point-constexpr.patch
550
- add patches:
551
* chromium-98-MiraclePtr-gcc-ice.patch
552
* chromium-98-WaylandFrameManager-check.patch
553
- change chromium-97-compiler.patch to chromium-98-compiler.patch
554
555
-------------------------------------------------------------------
556
Fri Jan 21 06:43:25 UTC 2022 - Andreas Stieger <andreas.stieger@gmx.de>
557
558
- Chromium 97.0.4692.99 (boo#1194919):
559
* CVE-2022-0289: Use after free in Safe browsing
560
* CVE-2022-0290: Use after free in Site isolation
561
* CVE-2022-0291: Inappropriate implementation in Storage
562
* CVE-2022-0292: Inappropriate implementation in Fenced Frames
563
* CVE-2022-0293: Use after free in Web packaging
564
* CVE-2022-0294: Inappropriate implementation in Push messaging
565
* CVE-2022-0295: Use after free in Omnibox
566
* CVE-2022-0296: Use after free in Printing
567
* CVE-2022-0297: Use after free in Vulkan
568
* CVE-2022-0298: Use after free in Scheduling
569
* CVE-2022-0300: Use after free in Text Input Method Editor
570
* CVE-2022-0301: Heap buffer overflow in DevTools
571
* CVE-2022-0302: Use after free in Omnibox
572
* CVE-2022-0303: Race in GPU Watchdog
573
* CVE-2022-0304: Use after free in Bookmarks
574
* CVE-2022-0305: Inappropriate implementation in Service Worker API
575
* CVE-2022-0306: Heap buffer overflow in PDFium
576
* CVE-2022-0307: Use after free in Optimization Guide
577
* CVE-2022-0308: Use after free in Data Transfer
578
* CVE-2022-0309: Inappropriate implementation in Autofill
579
* CVE-2022-0310: Heap buffer overflow in Task Manager
580
* CVE-2022-0311: Heap buffer overflow in Task Manager
581
* Various fixes from internal audits, fuzzing and other initiatives
582
- drop upstreamed patches:
583
* fix-tag-dragging-in-Mutter.patch
584
* fix-tag-dragging-in-KWin.patch
585
586
-------------------------------------------------------------------
587
Thu Jan 20 09:46:50 UTC 2022 - Callum Farmer <gmbr3@opensuse.org>
588
589
- Revert chromium-94-ffmpeg-roll.patch on TW: fix moved to
590
FFmpeg
591
592
-------------------------------------------------------------------
593
Sun Jan 16 12:05:13 UTC 2022 - Carsten Ziepke <kieltux@gmail.com>
594
595
- Rebase chromium 97.0.4692.71 for use as chromium-ffmpeg-extra
596
- Use gcc10 instead of gcc 11
597
598
Tue Jan 11 20:00:16 UTC 2022 - Callum Farmer <gmbr3@opensuse.org>
599
600
- Chromium 97.0.4692.71 (boo#1194331):
601
* CVE-2022-0096: Use after free in Storage
602
* CVE-2022-0097: Inappropriate implementation in DevTools
603
* CVE-2022-0098: Use after free in Screen Capture
604
* CVE-2022-0099: Use after free in Sign-in
605
* CVE-2022-0100: Heap buffer overflow in Media streams API
606
* CVE-2022-0101: Heap buffer overflow in Bookmarks
607
* CVE-2022-0102: Type Confusion in V8
608
* CVE-2022-0103: Use after free in SwiftShader
609
* CVE-2022-0104: Heap buffer overflow in ANGLE
610
* CVE-2022-0105: Use after free in PDF
611
* CVE-2022-0106: Use after free in Autofill
612
* CVE-2022-0107: Use after free in File Manager API
613
* CVE-2022-0108: Inappropriate implementation in Navigation
614
* CVE-2022-0109: Inappropriate implementation in Autofill
615
* CVE-2022-0110: Incorrect security UI in Autofill
616
* CVE-2022-0111: Inappropriate implementation in Navigation
617
* CVE-2022-0112: Incorrect security UI in Browser UI
618
* CVE-2022-0113: Inappropriate implementation in Blink
619
* CVE-2022-0114: Out of bounds memory access in Web Serial
620
* CVE-2022-0115: Uninitialized Use in File API
621
* CVE-2022-0116: Inappropriate implementation in Compositing
622
* CVE-2022-0117: Policy bypass in Service Workers
623
* CVE-2022-0118: Inappropriate implementation in WebShare
624
* CVE-2022-0120: Inappropriate implementation in Passwords
625
- Removed patches:
626
* chromium-96-CommandLine-include.patch
627
* chromium-96-RestrictedCookieManager-tuple.patch
628
* chromium-96-DrmRenderNodePathFinder-include.patch
629
* chromium-96-CouponDB-include.patch
630
* chromium-96-freetype-unbundle.patch
631
* chromium-96-compiler.patch
632
* chromium-vaapi.patch
633
* chromium-86-nearby-include.patch
634
- Added patches:
635
* chromium-97-compiler.patch
636
* chromium-97-Point-constexpr.patch
637
* chromium-97-ScrollView-reference.patch
638
* chromium-95-libyuv-arm.patch
639
* fix-tag-dragging-in-KWin.patch
640
* fix-tag-dragging-in-Mutter.patch
641
642
-------------------------------------------------------------------
643
Thu Dec 30 15:30:19 UTC 2021 - Callum Farmer <gmbr3@opensuse.org>
644
645
- Revert wayland fixes because it doesn't handle GPU correctly
646
(boo#1194182)
647
648
-------------------------------------------------------------------
649
Thu Dec 30 08:38:17 UTC 2021 - Martin Liška <mliska@suse.cz>
650
651
- Use GCC 11, but disable LTO (boo#1194055).
652
653
-------------------------------------------------------------------
654
Wed Dec 29 12:23:48 UTC 2021 - Callum Farmer <gmbr3@opensuse.org>
655
656
- Use our own copy of the wrapper so that we can use the fixes
657
for Wayland
658
659
-------------------------------------------------------------------
660
Sun Dec 26 23:02:18 UTC 2021 - Callum Farmer <gmbr3@opensuse.org>
661
662
- Define GNU_SOURCE and fix the below patched issues
663
- Removed patches:
664
* chromium-86-f_seal.patch
665
* chromium-90-fseal.patch
666
667
-------------------------------------------------------------------
668
Fri Dec 24 11:24:13 UTC 2021 - Callum Farmer <gmbr3@opensuse.org>
669
670
- Added patches:
671
* chromium-96-freetype-unbundle.patch
672
* chromium-96-EnumTable-crash.patch
673
- Unbundle freetype on TW
674
- Unbundle icu on 15.4
675
- Disable lto and update _constraints on aarch64
676
- Remove MEIPreload: it gets installed through component updater
677
678
-------------------------------------------------------------------
679
Wed Dec 15 10:54:35 UTC 2021 - Callum Farmer <gmbr3@opensuse.org>
680
681
- Revert to gcc10 on TW: gcc11 is entirely broken
682
- No auto thread LTO: linker crash on ARM
683
684
-------------------------------------------------------------------
685
Tue Dec 14 15:24:47 UTC 2021 - Andreas Stieger <andreas.stieger@gmx.de>
686
687
- Chromium 96.0.4664.110 (boo#1193713):
688
* CVE-2021-4098: Insufficient data validation in Mojo
689
* CVE-2021-4099: Use after free in Swiftshader
690
* CVE-2021-4100: Object lifecycle issue in ANGLE
691
* CVE-2021-4101: Heap buffer overflow in Swiftshader
692
* CVE-2021-4102: Use after free in V8
693
694
-------------------------------------------------------------------
695
Thu Dec 9 09:49:23 UTC 2021 - Callum Farmer <gmbr3@opensuse.org>
696
697
- Lord of the Browsers: The Two Compilers:
698
* Go back to GCC
699
* GCC: LTO removes needed assembly symbols
700
* Clang: issues with libstdc++
701
- Chromium 96.0.4664.93 (boo#1193519):
702
* CVE-2021-4052: Use after free in web apps
703
* CVE-2021-4053: Use after free in UI
704
* CVE-2021-4079: Out of bounds write in WebRTC
705
* CVE-2021-4054: Incorrect security UI in autofill
706
* CVE-2021-4078: Type confusion in V8
707
* CVE-2021-4055: Heap buffer overflow in extensions
708
* CVE-2021-4056: Type Confusion in loader
709
* CVE-2021-4057: Use after free in file API
710
* CVE-2021-4058: Heap buffer overflow in ANGLE
711
* CVE-2021-4059: Insufficient data validation in loader
712
* CVE-2021-4061: Type Confusion in V8
713
* CVE-2021-4062: Heap buffer overflow in BFCache
714
* CVE-2021-4063: Use after free in developer tools
715
* CVE-2021-4064: Use after free in screen capture
716
* CVE-2021-4065: Use after free in autofill
717
* CVE-2021-4066: Integer underflow in ANGLE
718
* CVE-2021-4067: Use after free in window manager
719
* CVE-2021-4068: Insufficient validation of untrusted input in new tab page
720
- Chromium 96.0.4664.45 (boo#1192734):
721
* CVE-2021-38007: Type Confusion in V8
722
* CVE-2021-38008: Use after free in media
723
* CVE-2021-38009: Inappropriate implementation in cache
724
* CVE-2021-38006: Use after free in storage foundation
725
* CVE-2021-38005: Use after free in loader
726
* CVE-2021-38010: Inappropriate implementation in service workers
727
* CVE-2021-38011: Use after free in storage foundation
728
* CVE-2021-38012: Type Confusion in V8
729
* CVE-2021-38013: Heap buffer overflow in fingerprint recognition
730
* CVE-2021-38014: Out of bounds write in Swiftshader
731
* CVE-2021-38015: Inappropriate implementation in input
732
* CVE-2021-38016: Insufficient policy enforcement in background fetch
733
* CVE-2021-38017: Insufficient policy enforcement in iframe sandbox
734
* CVE-2021-38018: Inappropriate implementation in navigation
735
* CVE-2021-38019: Insufficient policy enforcement in CORS
736
* CVE-2021-38020: Insufficient policy enforcement in contacts picker
737
* CVE-2021-38021: Inappropriate implementation in referrer
738
* CVE-2021-38022: Inappropriate implementation in WebAuthentication
739
- Removed old patches:
740
* chromium-95-compiler.patch
741
* chromium-95-BitstreamReader-namespace.patch
742
* chromium-95-system-zlib.patch
743
* chromium-older-harfbuzz.patch
744
* pipewire-do-not-typecheck-the-portal-session_handle.patch
745
- Removed build breaking patches:
746
* chromium-93-EnumTable-crash.patch
747
- Added patches:
748
* chromium-96-compiler.patch
749
* chromium-96-CommandLine-include.patch
750
* chromium-96-RestrictedCookieManager-tuple.patch
751
* chromium-96-DrmRenderNodePathFinder-include.patch
752
* chromium-96-CouponDB-include.patch
753
- Changed patches:
754
* gcc-enable-lto.patch: see above
755
756
-------------------------------------------------------------------
757
Fri Nov 19 09:32:39 UTC 2021 - Callum Farmer <gmbr3@opensuse.org>
758
759
- Ensure newer libs and LLVM is used on Leap (boo#1192310)
760
761
-------------------------------------------------------------------
762
Wed Nov 17 10:08:55 UTC 2021 - Steve Kowalik <steven.kowalik@suse.com>
763
764
- Explicitly BuildRequire python3-six.
765
766
-------------------------------------------------------------------
767
Wed Nov 10 20:03:53 UTC 2021 - Carsten Ziepke <kieltux@gmail.com>
768
769
- Chromium 95.0.4638.69 (boo#1192184):
770
* CVE-2021-37997: Use after free in Sign-In
771
* CVE-2021-37998: Use after free in Garbage Collection
772
* CVE-2021-37999: Insufficient data validation in New Tab Page
773
* CVE-2021-38000: Insufficient validation of untrusted input in Intents
774
* CVE-2021-38001: Type Confusion in V8
775
* CVE-2021-38002: Use after free in Web Transport
776
* CVE-2021-38003: Inappropriate implementation in V8
777
- Chromium 95.0.4638.54 (boo#1191844):
778
* CVE-2021-37981: Heap buffer overflow in Skia
779
* CVE-2021-37982: Use after free in Incognito
780
* CVE-2021-37983: Use after free in Dev Tools
781
* CVE-2021-37984: Heap buffer overflow in PDFium
782
* CVE-2021-37985: Use after free in V8
783
* CVE-2021-37986: Heap buffer overflow in Settings
784
* CVE-2021-37987: Use after free in Network APIs
785
* CVE-2021-37988: Use after free in Profiles
786
* CVE-2021-37989: Inappropriate implementation in Blink
787
* CVE-2021-37990: Inappropriate implementation in WebView
788
* CVE-2021-37991: Race in V8
789
* CVE-2021-37992: Out of bounds read in WebAudio
790
* CVE-2021-37993: Use after free in PDF Accessibility
791
* CVE-2021-37996: Insufficient validation of untrusted input in Downloads
792
* CVE-2021-37994: Inappropriate implementation in iFrame Sandbox
793
* CVE-2021-37995: Inappropriate implementation in WebApp Installer
794
- Added patches:
795
* chromium-95-BitstreamReader-namespace.patch
796
* chromium-95-compiler.patch
797
* chromium-95-libyuv-aarch64.patch
798
* chromium-95-quiche-include.patch
799
* chromium-95-system-zlib.patch
800
- Removed patches:
801
* chromium-94-compiler.patch
802
* chromium-91-libyuv-aarch64.patch
803
* chromium-90-ruy-include.patch
804
* chromium-94-CustomSpaces-include.patch
805
806
-------------------------------------------------------------------
807
Sat Oct 9 05:32:48 UTC 2021 - Carsten Ziepke <kieltux@gmail.com>
808
809
- Removed patches:
810
* chromium-94-ffmpeg-roll.patch
811
812
-------------------------------------------------------------------
813
Fri Oct 8 19:46:13 UTC 2021 - Carsten Ziepke <kieltux@gmail.com>
814
815
- Chromium 94.0.4606.81 (boo#1191463):
816
* CVE-2021-37977: Use after free in Garbage Collection
817
* CVE-2021-37978: Heap buffer overflow in Blink
818
* CVE-2021-37979: Heap buffer overflow in WebRTC
819
* CVE-2021-37980: Inappropriate implementation in Sandbox
820
- Re-add after accidental deletion:
821
* chromium-93-InkDropHost-crash.patch
822
- Chromium 94.0.4606.54 (boo#1190765):
823
* CVE-2021-37956: Use after free in Offline use
824
* CVE-2021-37957: Use after free in WebGPU
825
* CVE-2021-37958: Inappropriate implementation in Navigation
826
* CVE-2021-37959: Use after free in Task Manager
827
* CVE-2021-37960: Inappropriate implementation in Blink graphics
828
* CVE-2021-37961: Use after free in Tab Strip
829
* CVE-2021-37962: Use after free in Performance Manager
830
* CVE-2021-37963: Side-channel information leakage in DevTools
831
* CVE-2021-37964: Inappropriate implementation in ChromeOS Networking
832
* CVE-2021-37965: Inappropriate implementation in Background Fetch API
833
* CVE-2021-37966: Inappropriate implementation in Compositing
834
* CVE-2021-37967: Inappropriate implementation in Background Fetch API
835
* CVE-2021-37968: Inappropriate implementation in Background Fetch API
836
* CVE-2021-37969: Inappropriate implementation in Google Updater
837
* CVE-2021-37970: Use after free in File System API
838
* CVE-2021-37971: Incorrect security UI in Web Browser UI
839
* CVE-2021-37972: Out of bounds read in libjpeg-turbo
840
- Chromium 94.0.4606.61 (boo#1191166):
841
* CVE-2021-37973: Use after free in Portals
842
- Chromium 94.0.4606.71 (boo#1191204):
843
* CVE-2021-37974 : Use after free in Safe Browsing
844
* CVE-2021-37975 : Use after free in V8
845
* CVE-2021-37976 : Information leak in core
846
- Added patches:
847
* chromium-94-CustomSpaces-include.patch
848
* chromium-94-sql-no-assert.patch
849
* chromium-older-harfbuzz.patch
850
* chromium-94-ffmpeg-roll.patch
851
* chromium-94-compiler.patch
852
- Removed patches:
853
* chromium-freetype-2.11.patch
854
* chromium-93-ContextSet-permissive.patch
855
* chromium-93-ClassProperty-include.patch
856
* chromium-93-BluetoothLowEnergyScanFilter-include.patch
857
* chromium-93-HashPasswordManager-include.patch
858
* chromium-93-pdfium-include.patch
859
* chromium-93-DevToolsEmbedderMessageDispatcher-include.patch
860
* chromium-93-FormForest-constexpr.patch
861
* chromium-93-ScopedTestDialogAutoConfirm-include.patch
862
* chromium-93-InkDropHost-crash.patch
863
* chromium-91-compiler.patch
864
* chromium-glibc-2.33.patch
865
* chromium-shim_headers.patch
866
867
-------------------------------------------------------------------
868
Fri Sep 24 17:16:41 UTC 2021 - Carsten Ziepke <kieltux@gmail.com>
869
870
- Add patch to fix Leap 15.2 build:
871
* chromium-ffmpeg-lp152.patch
872
- Change system-libdrm.patch: add to unbundle instead of changing
873
header path
874
875
-------------------------------------------------------------------
876
Sun Sep 19 19:41:03 UTC 2021 - Carsten Ziepke <kieltux@gmail.com>
877
878
- Update to 93.0.4577.82
879
Branch of https://build.opensuse.org/project/show/network:chromium
880
- Drop conditional build for libffmpeg, we want it here definitely
881
882
-------------------------------------------------------------------
883
Tue Oct 16 05:18:00 UTC 2018 - avvissu@yandex.by
884
885
- Add chromium-old-glibc.patch
886
887
-------------------------------------------------------------------
888
Fri Sep 21 20:49:51 UTC 2018 - fisiu@opensuse.org
889
890
- Update to 69.0.3497.100.
891
892
-------------------------------------------------------------------
893
Sat Mar 24 00:09:38 UTC 2018 - fisiu@opensuse.org
894
895
- Make symlink to allow Opera find libffmpeg.so.
896
897
-------------------------------------------------------------------
898
Fri Feb 2 23:21:51 UTC 2018 - fisiu@opensuse.org
899
900
- Update to 64.0.3282.134
901
- Drop fix-gn-bootstrap.diff: fixed upstream.
902
- Drop fix-gn-bootstrap.diff: build with gcc7.
903
- Add chromium-angle.patch: fix build issue.
904
- Add chromium-memcpy.patch: fix build issue.
905
906
-------------------------------------------------------------------
907
Mon Oct 16 15:42:17 UTC 2017 - avvissu@yandex.by
908
909
- Update to 61.0.3163.100
910
911
-------------------------------------------------------------------
912
Fri Jun 23 20:05:27 UTC 2017 - avvissu@yandex.by
913
914
- Update to 59.0.3071.104
915
916
-------------------------------------------------------------------
917
Fri Apr 28 05:04:38 UTC 2017 - avvissu@yandex.by
918
919
- Update to 58.0.3029.81
920
921
-------------------------------------------------------------------
922
Tue Apr 11 05:24:41 UTC 2017 - avvissu@yandex.by
923
924
- Use a custom toolchain
925
926
-------------------------------------------------------------------
927
Wed Apr 5 17:08:12 UTC 2017 - avvissu@yandex.by
928
929
- Remove --verbose flag
930
- Add chromium-fix-gn-bootstrap.patch
931
932
-------------------------------------------------------------------
933
Wed Mar 29 14:01:10 UTC 2017 - avvissu@yandex.by
934
935
- Initial release
936
937