Fedora Linux 9173 Published by

Fedora 41 has been updated to include a new version of the Chromium browser, version 140.0.7339.207. This update addresses security issues, including side-channel information leakage and integer overflow in V8. The update can be installed using the "dnf" command, and all packages are signed with the Fedora Project GPG key. This update is a response to bug #2397767, which reported vulnerabilities CVE-2025-10890, CVE-2025-10891, and CVE-2025-10892 in Chromium's V8 engine.

Fedora 41 Update: chromium-140.0.7339.207-1.fc41




[SECURITY] Fedora 41 Update: chromium-140.0.7339.207-1.fc41


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2025-0b264b890c
2025-09-29 01:05:06.085849+00:00
--------------------------------------------------------------------------------

Name : chromium
Product : Fedora 41
Version : 140.0.7339.207
Release : 1.fc41
URL : http://www.chromium.org/Home
Summary : A WebKit (Blink) powered web browser that Google doesn't want you to use
Description :
Chromium is an open-source web browser, powered by WebKit (Blink).

--------------------------------------------------------------------------------
Update Information:

Update to 140.0.7339.207
* CVE-2025-10890: Side-channel information leakage in V8
* CVE-2025-10891: Integer overflow in V8
* CVE-2025-10892: Integer overflow in V8
--------------------------------------------------------------------------------
ChangeLog:

* Wed Sep 24 2025 Than Ngo [than@redhat.com] - 140.0.7339.207-1
- Update to 140.0.7339.207
* CVE-2025-10890: Side-channel information leakage in V8
* CVE-2025-10891: Integer overflow in V8
* CVE-2025-10892: Integer overflow in V8
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2397767 - CVE-2025-10890, CVE-2025-10891, CVE-2025-10892 - chromium: Side-channel information leakage and Ingter overflow in V8 [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2397767
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2025-0b264b890c' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------

--