[Git][security-tracker-team/security-tracker][master] Track fixes for chromium via unstable

Salvatore Bonaccorso (@carnil) carnil at debian.org
Wed Jul 22 22:20:57 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
270e38bd by Salvatore Bonaccorso at 2026-07-22T23:19:44+02:00
Track fixes for chromium via unstable

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -2865,40 +2865,40 @@ CVE-2026-54441
 	- mbedtls 3.6.7-2
 	[trixie] - mbedtls <no-dsa> (Minor issue; can be fixed via point releases)
 CVE-2026-16420 (Type Confusion in WebAudio in Google Chrome prior to 150.0.7871.182 al ...)
-	- chromium <unfixed>
+	- chromium 150.0.7871.181-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-16421 (Inappropriate implementation in WebAudio in Google Chrome prior to 150 ...)
-	- chromium <unfixed>
+	- chromium 150.0.7871.181-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-16413 (Out of bounds write in ANGLE in Google Chrome prior to 150.0.7871.182  ...)
-	- chromium <unfixed>
+	- chromium 150.0.7871.181-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-16414 (Insufficient validation of untrusted input in Chromecast in Google Chr ...)
-	- chromium <unfixed>
+	- chromium 150.0.7871.181-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-16415 (Insufficient validation of untrusted input in Extensions in Google Chr ...)
-	- chromium <unfixed>
+	- chromium 150.0.7871.181-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-16416 (Integer overflow in Chromecast in Google Chrome prior to 150.0.7871.18 ...)
-	- chromium <unfixed>
+	- chromium 150.0.7871.181-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-16417 (Uninitialized Use in Skia in Google Chrome prior to 150.0.7871.182 all ...)
-	- chromium <unfixed>
+	- chromium 150.0.7871.181-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-16418 (Stack buffer overflow in V8 in Google Chrome prior to 150.0.7871.182 a ...)
-	- chromium <unfixed>
+	- chromium 150.0.7871.181-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-16419 (Out of bounds read and write in ANGLE in Google Chrome on Android prio ...)
-	- chromium <unfixed>
+	- chromium 150.0.7871.181-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-16422 (Insufficient validation of untrusted input in Certificate in Google Ch ...)
-	- chromium <unfixed>
+	- chromium 150.0.7871.181-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-16423 (Use after free in UI in Google Chrome prior to 150.0.7871.182 allowed  ...)
-	- chromium <unfixed>
+	- chromium 150.0.7871.181-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-16424 (Use after free in GPU in Google Chrome on Android prior to 150.0.7871. ...)
-	- chromium <unfixed>
+	- chromium 150.0.7871.181-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-9499 (An out-of-bounds read (buffer over-read) vulnerability exists in QText ...)
 	- qt6-5compat <unfixed>
@@ -7343,25 +7343,25 @@ CVE-2026-14266
 	NOTE: depending on 7zip. Mark this version as fixed version.
 	NOTE: https://www.zerodayinitiative.com/advisories/ZDI-26-444/
 CVE-2026-15899 (Use after free in CameraCapture in Google Chrome on Mac prior to 150.0 ...)
-	- chromium <unfixed>
+	- chromium 150.0.7871.181-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-15900 (Use after free in GPU in Google Chrome on Android prior to 150.0.7871. ...)
-	- chromium <unfixed>
+	- chromium 150.0.7871.181-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-15901 (Use after free in Network in Google Chrome prior to 150.0.7871.128 all ...)
-	- chromium <unfixed>
+	- chromium 150.0.7871.181-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-15902 (Use after free in Cast in Google Chrome prior to 150.0.7871.128 allowe ...)
-	- chromium <unfixed>
+	- chromium 150.0.7871.181-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-15903 (Out of bounds read and write in V8 in Google Chrome prior to 150.0.787 ...)
-	- chromium <unfixed>
+	- chromium 150.0.7871.181-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-15904 (Use after free in Ozone in Google Chrome on Linux prior to 150.0.7871. ...)
-	- chromium <unfixed>
+	- chromium 150.0.7871.181-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-15905 (Use after free in Aura in Google Chrome prior to 150.0.7871.128 allowe ...)
-	- chromium <unfixed>
+	- chromium 150.0.7871.181-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-59173 (Uncontrolled Resource Consumption vulnerability in Apache Traffic Serv ...)
 	- trafficserver <unfixed> (bug #1142387)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/270e38bd614ffa17dcaf239f20aa26b88acf6017

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/270e38bd614ffa17dcaf239f20aa26b88acf6017
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260722/1dfb3aed/attachment.htm>


More information about the debian-security-tracker-commits mailing list