Upstream information

CVE-2024-2886 at MITRE

Description

Use after free in WebCodecs in Google Chrome prior to 123.0.6312.86 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)

Upstream Security Advisories:

SUSE information

Overall state of this security issue: Resolved

This issue is currently rated as having moderate severity.

SUSE Bugzilla entry: 1222035 [RESOLVED / DUPLICATE]

SUSE Security Advisories:

List of released packages

Product(s) Fixed package version(s) References
openSUSE Leap 15.5 NonFree
  • opera >= 109.0.5097.38-lp155.3.42.1
Patchnames:
openSUSE-2024-109
openSUSE Leap 15.6 NonFree
  • opera >= 109.0.5097.45-lp156.2.3.1
Patchnames:
openSUSE-2024-122
openSUSE Tumbleweed
  • chromedriver >= 124.0.6367.201-1.1
  • chromium >= 124.0.6367.201-1.1
  • nodejs-electron >= 28.2.10-1.1
  • nodejs-electron-devel >= 28.2.10-1.1
  • nodejs-electron-doc >= 28.2.10-1.1
Patchnames:
openSUSE Tumbleweed GA chromedriver-124.0.6367.201-1.1
openSUSE Tumbleweed GA nodejs-electron-28.2.10-1.1


SUSE Timeline for this CVE

CVE page created: Tue Mar 26 23:00:14 2024
CVE page last modified: Mon Jun 10 12:40:08 2024