Skip to content

chore: cherry-pick 17 changes from angle, chromium, webrtc#51906

Merged
jkleinsc merged 1 commit into
41-x-yfrom
security-backport/41-x-y/2026-06-06
Jun 8, 2026
Merged

chore: cherry-pick 17 changes from angle, chromium, webrtc#51906
jkleinsc merged 1 commit into
41-x-yfrom
security-backport/41-x-y/2026-06-06

Conversation

@VerteDinde

Copy link
Copy Markdown
Member

Backports the following changes:

Covers the security fixes from the Chrome 148.0.7778.178 stable release that were missing from the 41-x-y tree (Chromium 146.0.7680.216). Already in-tree and therefore not included: CVE-2026-9112, CVE-2026-9113 (ANGLE M146 merges), CVE-2026-9119 (WebRTC M146 merge).

For CVE-2026-9114 (QUIC use-after-free), the cherry-pick is the same hardening mitigation Chrome shipped on stable (ADVANCED_MEMORY_SAFETY_CHECKS() on the vulnerable class); the actual fix (7900197) landed on Chromium main on 2026-06-04 and has not shipped in any Chrome stable channel yet.

Intentionally not backported: 7765503 (CVE-2026-9123) touches only chromecast/media/, which Electron does not compile.

Notes: Security: backported fixes for CVE-2026-9110, CVE-2026-9111, CVE-2026-9114, CVE-2026-9115, CVE-2026-9116, CVE-2026-9117, CVE-2026-9118, CVE-2026-9120, CVE-2026-9121, CVE-2026-9122, CVE-2026-9124, CVE-2026-9126.

@VerteDinde VerteDinde requested a review from a team as a code owner June 6, 2026 06:29
@VerteDinde VerteDinde added semver/patch backwards-compatible bug fixes backport-check-skip Skip trop's backport validity checking 41-x-y labels Jun 6, 2026
@jkleinsc jkleinsc merged commit 944b4d7 into 41-x-y Jun 8, 2026
311 of 324 checks passed
@jkleinsc jkleinsc deleted the security-backport/41-x-y/2026-06-06 branch June 8, 2026 19:04
@release-clerk

release-clerk Bot commented Jun 8, 2026

Copy link
Copy Markdown

Release Notes Persisted

Security: backported fixes for CVE-2026-9110, CVE-2026-9111, CVE-2026-9114, CVE-2026-9115, CVE-2026-9116, CVE-2026-9117, CVE-2026-9118, CVE-2026-9120, CVE-2026-9121, CVE-2026-9122, CVE-2026-9124, CVE-2026-9126.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

41-x-y backport-check-skip Skip trop's backport validity checking security 🔒 semver/patch backwards-compatible bug fixes

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants