Date: Fri, 19 Dec 2025 09:10:39 +0000 From: Robert Nagy <rnagy@FreeBSD.org> To: ports-committers@FreeBSD.org, dev-commits-ports-all@FreeBSD.org, dev-commits-ports-main@FreeBSD.org Subject: git: 847395f50083 - main - security/vuxml: add www/*chromium < 143.0.7499.146 Message-ID: <6945168f.3d1fb.6b0158ae@gitrepo.freebsd.org>
index | next in thread | raw e-mail
The branch main has been updated by rnagy: URL: https://cgit.FreeBSD.org/ports/commit/?id=847395f500831a397fffd5be2fa5ce895d7f303c commit 847395f500831a397fffd5be2fa5ce895d7f303c Author: Robert Nagy <rnagy@FreeBSD.org> AuthorDate: 2025-12-19 09:01:39 +0000 Commit: Robert Nagy <rnagy@FreeBSD.org> CommitDate: 2025-12-19 09:10:23 +0000 security/vuxml: add www/*chromium < 143.0.7499.146 Obtained from: https://chromereleases.googleblog.com/2025/12/stable-channel-update-for-desktop_16.html --- security/vuxml/vuln/2025.xml | 35 +++++++++++++++++++++++++++++++++++ 1 file changed, 35 insertions(+) diff --git a/security/vuxml/vuln/2025.xml b/security/vuxml/vuln/2025.xml index 8b88ed7f17bc..8daf847a93d7 100644 --- a/security/vuxml/vuln/2025.xml +++ b/security/vuxml/vuln/2025.xml @@ -1,3 +1,38 @@ + <vuln vid="f99e70c2-dcb8-11f0-a15a-a8a1599412c6"> + <topic>chromium -- multiple security fixes</topic> + <affects> + <package> + <name>chromium</name> + <range><lt>143.0.7499.146</lt></range> + </package> + <package> + <name>ungoogled-chromium</name> + <range><lt>143.0.7499.146</lt></range> + </package> + </affects> + <description> + <body xmlns="http://www.w3.org/1999/xhtml"> + <p>Chrome Releases reports:</p> + <blockquote cite="https://chromereleases.googleblog.com/2025/12/stable-channel-update-for-desktop_16.html"> + <p>This update includes 2 security fixes:</p> + <ul> + <li>[448294721] High CVE-2025-14765: Use after free in WebGPU. Reported by Anonymous on 2025-09-30</li> + <li>[466786677] High CVE-2025-14766: Out of bounds read and write in V8. Reported by Shaheen Fazim on 2025-12-08</li> + </ul> + </blockquote> + </body> + </description> + <references> + <cvename>CVE-2025-14765</cvename> + <cvename>CVE-2025-14766</cvename> + <url>https://chromereleases.googleblog.com/2025/12/stable-channel-update-for-desktop_16.html</url> + </references> + <dates> + <discovery>2025-12-16</discovery> + <entry>2025-12-19</entry> + </dates> + </vuln> + <vuln vid="eca46635-db51-11f0-9b8d-40a6b7c3b3b8"> <topic>step-certificates -- Authorization Bypass in ACME and SCEP Provisioners</topic> <affects>home | help
Want to link to this message? Use this
URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?6945168f.3d1fb.6b0158ae>
