{"id":"openSUSE-SU-2026:20332-1","summary":"Security update for chromium","details":"This update for chromium fixes the following issues:\n\nChanges in chromium:\n\n- Chromium 145.0.7632.159 (boo#1259213)\n  * CVE-2026-3536: Integer overflow in ANGLE\n  * CVE-2026-3537: Object lifecycle issue in PowerVR\n  * CVE-2026-3538: Integer overflow in Skia\n  * CVE-2026-3539: Object lifecycle issue in DevTools\n  * CVE-2026-3540: Inappropriate implementation in WebAudio\n  * CVE-2026-3541: Inappropriate implementation in CSS\n  * CVE-2026-3542: Inappropriate implementation in WebAssembly\n  * CVE-2026-3543: Inappropriate implementation in V8\n  * CVE-2026-3544: Heap buffer overflow in WebCodecs\n  * CVE-2026-3545: Insufficient data validation in Navigation\n\n- Chromium 145.0.7632.116 (boo#1258733):\n  * CVE-2026-3061: Out of bounds read in Media\n  * CVE-2026-3062: Out of bounds read and write in Tint\n  * CVE-2026-3063: Inappropriate implementation in DevTools\n\n- Chromium 145.0.7632.109 (boo#1258438):\n  * CVE-2026-2648: Heap buffer overflow in PDFium\n  * CVE-2026-2649: Integer overflow in V8\n  * CVE-2026-2650: Heap buffer overflow in Media\n\n- more fixes for desktop file, some variables were lowercased,\n  further adaptions in INSTALL script (boo#1258199)\n\n- also copy rollup into third_party/node/node_modules\n- stay on llvm-10 for swiftshader but bring a similar patch\n\n- drop use of rollup binaries and use rollup-3.x which does not\n  use prebuilt binaries (that fail at least on older ppc64le)\n  follow the approach of the debian packaging\n\n- update/resync ppc64le patches from fedora\n\n- fix INSTALL.sh again to replace the tags in desktop file,\n  appdata and manpage (boo#1258199)\n\n- Chromium 145.0.7632.75:\n  * CVE-2026-2441: Use after free in CSS (boo#1258185)\n\n- Chromium 145.0.7632.67:\n  * Revert a change in url_fixer that may have caused crashes\n\n- Chromium 145.0.7632.45 (boo#1258116)\n  * jpeg-xl support has been readded\n  * CVE-2026-2313: Use after free in CSS\n  * CVE-2026-2314: Heap buffer overflow in Codecs\n  * CVE-2026-2315: Inappropriate implementation in WebGPU\n  * CVE-2026-2316: Insufficient policy enforcement in Frames\n  * CVE-2026-2317: Inappropriate implementation in Animation\n  * CVE-2026-2318: Inappropriate implementation in PictureInPicture\n  * CVE-2026-2319: Race in DevTools\n  * CVE-2026-2320: Inappropriate implementation in File input\n  * CVE-2026-2321: Use after free in Ozone\n  * CVE-2026-2322: Inappropriate implementation in File input\n  * CVE-2026-2323: Inappropriate implementation in Downloads\n","modified":"2026-09-02T18:27:35.766047487Z","published":"2026-08-31T08:39:48Z","related":["CVE-2026-2313","CVE-2026-2314","CVE-2026-2315","CVE-2026-2316","CVE-2026-2317","CVE-2026-2318","CVE-2026-2319","CVE-2026-2320","CVE-2026-2321","CVE-2026-2322","CVE-2026-2323","CVE-2026-2441","CVE-2026-2648","CVE-2026-2649","CVE-2026-2650","CVE-2026-3061","CVE-2026-3062","CVE-2026-3063","CVE-2026-3536","CVE-2026-3537","CVE-2026-3538","CVE-2026-3539","CVE-2026-3540","CVE-2026-3541","CVE-2026-3542","CVE-2026-3543","CVE-2026-3544","CVE-2026-3545"],"upstream":["CVE-2026-2313","CVE-2026-2314","CVE-2026-2315","CVE-2026-2316","CVE-2026-2317","CVE-2026-2318","CVE-2026-2319","CVE-2026-2320","CVE-2026-2321","CVE-2026-2322","CVE-2026-2323","CVE-2026-2441","CVE-2026-2648","CVE-2026-2649","CVE-2026-2650","CVE-2026-3061","CVE-2026-3062","CVE-2026-3063","CVE-2026-3536","CVE-2026-3537","CVE-2026-3538","CVE-2026-3539","CVE-2026-3540","CVE-2026-3541","CVE-2026-3542","CVE-2026-3543","CVE-2026-3544","CVE-2026-3545"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258116"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258185"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258199"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258438"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258733"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259213"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-2313"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-2314"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-2315"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-2316"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-2317"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-2318"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-2319"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-2320"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-2321"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-2322"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-2323"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-2441"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-2648"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-2649"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-2650"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-3061"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-3062"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-3063"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-3536"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-3537"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-3538"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-3539"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-3540"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-3541"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-3542"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-3543"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-3544"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-3545"}],"affected":[{"package":{"name":"chromium","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/chromium&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"145.0.7632.159-bp160.1.1"}]}],"ecosystem_specific":{"binaries":[{"chromedriver":"145.0.7632.159-bp160.1.1","chromium":"145.0.7632.159-bp160.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:20332-1.json"}}],"schema_version":"1.9.0"}