[Git][security-tracker-team/security-tracker][master] Track fixes for chromium via unstable
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Wed Jul 22 22:20:57 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
270e38bd by Salvatore Bonaccorso at 2026-07-22T23:19:44+02:00
Track fixes for chromium via unstable
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -2865,40 +2865,40 @@ CVE-2026-54441
- mbedtls 3.6.7-2
[trixie] - mbedtls <no-dsa> (Minor issue; can be fixed via point releases)
CVE-2026-16420 (Type Confusion in WebAudio in Google Chrome prior to 150.0.7871.182 al ...)
- - chromium <unfixed>
+ - chromium 150.0.7871.181-1
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2026-16421 (Inappropriate implementation in WebAudio in Google Chrome prior to 150 ...)
- - chromium <unfixed>
+ - chromium 150.0.7871.181-1
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2026-16413 (Out of bounds write in ANGLE in Google Chrome prior to 150.0.7871.182 ...)
- - chromium <unfixed>
+ - chromium 150.0.7871.181-1
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2026-16414 (Insufficient validation of untrusted input in Chromecast in Google Chr ...)
- - chromium <unfixed>
+ - chromium 150.0.7871.181-1
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2026-16415 (Insufficient validation of untrusted input in Extensions in Google Chr ...)
- - chromium <unfixed>
+ - chromium 150.0.7871.181-1
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2026-16416 (Integer overflow in Chromecast in Google Chrome prior to 150.0.7871.18 ...)
- - chromium <unfixed>
+ - chromium 150.0.7871.181-1
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2026-16417 (Uninitialized Use in Skia in Google Chrome prior to 150.0.7871.182 all ...)
- - chromium <unfixed>
+ - chromium 150.0.7871.181-1
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2026-16418 (Stack buffer overflow in V8 in Google Chrome prior to 150.0.7871.182 a ...)
- - chromium <unfixed>
+ - chromium 150.0.7871.181-1
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2026-16419 (Out of bounds read and write in ANGLE in Google Chrome on Android prio ...)
- - chromium <unfixed>
+ - chromium 150.0.7871.181-1
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2026-16422 (Insufficient validation of untrusted input in Certificate in Google Ch ...)
- - chromium <unfixed>
+ - chromium 150.0.7871.181-1
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2026-16423 (Use after free in UI in Google Chrome prior to 150.0.7871.182 allowed ...)
- - chromium <unfixed>
+ - chromium 150.0.7871.181-1
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2026-16424 (Use after free in GPU in Google Chrome on Android prior to 150.0.7871. ...)
- - chromium <unfixed>
+ - chromium 150.0.7871.181-1
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2026-9499 (An out-of-bounds read (buffer over-read) vulnerability exists in QText ...)
- qt6-5compat <unfixed>
@@ -7343,25 +7343,25 @@ CVE-2026-14266
NOTE: depending on 7zip. Mark this version as fixed version.
NOTE: https://www.zerodayinitiative.com/advisories/ZDI-26-444/
CVE-2026-15899 (Use after free in CameraCapture in Google Chrome on Mac prior to 150.0 ...)
- - chromium <unfixed>
+ - chromium 150.0.7871.181-1
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2026-15900 (Use after free in GPU in Google Chrome on Android prior to 150.0.7871. ...)
- - chromium <unfixed>
+ - chromium 150.0.7871.181-1
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2026-15901 (Use after free in Network in Google Chrome prior to 150.0.7871.128 all ...)
- - chromium <unfixed>
+ - chromium 150.0.7871.181-1
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2026-15902 (Use after free in Cast in Google Chrome prior to 150.0.7871.128 allowe ...)
- - chromium <unfixed>
+ - chromium 150.0.7871.181-1
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2026-15903 (Out of bounds read and write in V8 in Google Chrome prior to 150.0.787 ...)
- - chromium <unfixed>
+ - chromium 150.0.7871.181-1
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2026-15904 (Use after free in Ozone in Google Chrome on Linux prior to 150.0.7871. ...)
- - chromium <unfixed>
+ - chromium 150.0.7871.181-1
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2026-15905 (Use after free in Aura in Google Chrome prior to 150.0.7871.128 allowe ...)
- - chromium <unfixed>
+ - chromium 150.0.7871.181-1
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2026-59173 (Uncontrolled Resource Consumption vulnerability in Apache Traffic Serv ...)
- trafficserver <unfixed> (bug #1142387)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/270e38bd614ffa17dcaf239f20aa26b88acf6017
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/270e38bd614ffa17dcaf239f20aa26b88acf6017
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260722/1dfb3aed/attachment.htm>
More information about the debian-security-tracker-commits
mailing list