Upstream information

CVE-2024-2886 at MITRE


Use after free in WebCodecs in Google Chrome prior to 123.0.6312.86 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)

Upstream Security Advisories:

SUSE information

Overall state of this security issue: Resolved

This issue is currently rated as having moderate severity.

SUSE Bugzilla entry: 1222035 [RESOLVED / DUPLICATE]

SUSE Security Advisories:

List of released packages

Product(s) Fixed package version(s) References
openSUSE Leap 15.5 NonFree
  • opera >= 109.0.5097.38-lp155.3.42.1
openSUSE Tumbleweed
  • chromedriver >= 124.0.6367.201-1.1
  • chromium >= 124.0.6367.201-1.1
  • nodejs-electron >= 28.2.10-1.1
  • nodejs-electron-devel >= 28.2.10-1.1
  • nodejs-electron-doc >= 28.2.10-1.1
openSUSE Tumbleweed GA chromedriver-124.0.6367.201-1.1
openSUSE Tumbleweed GA nodejs-electron-28.2.10-1.1

SUSE Timeline for this CVE

CVE page created: Tue Mar 26 23:00:14 2024
CVE page last modified: Tue May 14 00:40:11 2024