{"schema_version":"1.7.3","id":"openSUSE-SU-2022:0125-1","published":"2022-05-06T07:28:22Z","modified":"2026-02-04T02:26:44.904738Z","related":["CVE-2022-1477","CVE-2022-1478","CVE-2022-1479","CVE-2022-1480","CVE-2022-1481","CVE-2022-1482","CVE-2022-1483","CVE-2022-1484","CVE-2022-1485","CVE-2022-1486","CVE-2022-1487","CVE-2022-1488","CVE-2022-1489","CVE-2022-1490","CVE-2022-1491","CVE-2022-1492","CVE-2022-1493","CVE-2022-1494","CVE-2022-1495","CVE-2022-1496","CVE-2022-1497","CVE-2022-1498","CVE-2022-1499","CVE-2022-1500","CVE-2022-1501"],"upstream":["CVE-2022-1477","CVE-2022-1478","CVE-2022-1479","CVE-2022-1480","CVE-2022-1481","CVE-2022-1482","CVE-2022-1483","CVE-2022-1484","CVE-2022-1485","CVE-2022-1486","CVE-2022-1487","CVE-2022-1488","CVE-2022-1489","CVE-2022-1490","CVE-2022-1491","CVE-2022-1492","CVE-2022-1493","CVE-2022-1494","CVE-2022-1495","CVE-2022-1496","CVE-2022-1497","CVE-2022-1498","CVE-2022-1499","CVE-2022-1500","CVE-2022-1501"],"summary":"Security update for chromium","details":"This update for chromium fixes the following issues:\n\nChromium 101.0.4951.54 (boo#1199118)\n\nChromium 101.0.4951.41 (boo#1198917):\n\n* CVE-2022-1477: Use after free in Vulkan\n* CVE-2022-1478: Use after free in SwiftShader\n* CVE-2022-1479: Use after free in ANGLE\n* CVE-2022-1480: Use after free in Device API\n* CVE-2022-1481: Use after free in Sharing\n* CVE-2022-1482: Inappropriate implementation in WebGL\n* CVE-2022-1483: Heap buffer overflow in WebGPU\n* CVE-2022-1484: Heap buffer overflow in Web UI Settings\n* CVE-2022-1485: Use after free in File System API\n* CVE-2022-1486: Type Confusion in V8\n* CVE-2022-1487: Use after free in Ozone\n* CVE-2022-1488: Inappropriate implementation in Extensions API\n* CVE-2022-1489: Out of bounds memory access in UI Shelf\n* CVE-2022-1490: Use after free in Browser Switcher\n* CVE-2022-1491: Use after free in Bookmarks\n* CVE-2022-1492: Insufficient data validation in Blink Editing\n* CVE-2022-1493: Use after free in Dev Tools\n* CVE-2022-1494: Insufficient data validation in Trusted Types\n* CVE-2022-1495: Incorrect security UI in Downloads\n* CVE-2022-1496: Use after free in File Manager\n* CVE-2022-1497: Inappropriate implementation in Input\n* CVE-2022-1498: Inappropriate implementation in HTML Parser\n* CVE-2022-1499: Inappropriate implementation in WebAuthentication\n* CVE-2022-1500: Insufficient data validation in Dev Tools\n* CVE-2022-1501: Inappropriate implementation in iframe\n","affected":[{"package":{"name":"chromium","ecosystem":"SUSE:Package Hub 15 SP3","purl":"pkg:rpm/suse/chromium&distro=SUSE%20Package%20Hub%2015%20SP3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"101.0.4951.54-bp153.2.88.1"}]}],"ecosystem_specific":{"binaries":[{"chromedriver":"101.0.4951.54-bp153.2.88.1","chromium":"101.0.4951.54-bp153.2.88.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2022:0125-1.json"}},{"package":{"name":"chromium","ecosystem":"openSUSE:Leap 15.3","purl":"pkg:rpm/opensuse/chromium&distro=openSUSE%20Leap%2015.3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"101.0.4951.54-bp153.2.88.1"}]}],"ecosystem_specific":{"binaries":[{"chromedriver":"101.0.4951.54-bp153.2.88.1","chromium":"101.0.4951.54-bp153.2.88.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2022:0125-1.json"}}],"references":[{"type":"ADVISORY","url":"https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/MHFVFF55YYOTI45WJ3YWL3TU4PVSG5ZU/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1198917"},{"type":"REPORT","url":"https://bugzilla.suse.com/1199118"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-1477"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-1478"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-1479"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-1480"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-1481"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-1482"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-1483"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-1484"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-1485"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-1486"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-1487"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-1488"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-1489"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-1490"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-1491"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-1492"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-1493"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-1494"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-1495"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-1496"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-1497"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-1498"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-1499"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-1500"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-1501"}]}