Bug 1807341

Summary: chromium-browser: Out of bounds memory access in streams
Product: [Other] Security Response Reporter: Dhananjay Arunesh <darunesh>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED DUPLICATE QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: erack, nsl, tcallawa, tpopela, yaneti
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: chromium-browser 80.0.3987.122 Doc Type: No Doc Update
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2020-02-26 14:24:55 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1807354, 1807355, 1807361    
Bug Blocks: 1807352    

Description Dhananjay Arunesh 2020-02-26 07:12:58 UTC
Out of bounds memory access in streams.

Comment 1 Dhananjay Arunesh 2020-02-26 07:14:58 UTC
External References:

https://chromereleases.googleblog.com/2020/02/stable-channel-update-for-desktop_24.html

Comment 2 Dhananjay Arunesh 2020-02-26 07:41:23 UTC
Created chromium tracking bugs for this issue:

Affects: epel-all [bug 1807355]
Affects: fedora-all [bug 1807354]

Comment 4 Nicholas Luedtke 2020-02-26 13:33:52 UTC
I think the CVE was mis-typed. This should be CVE-2020-6407.

Comment 5 Nicholas Luedtke 2020-02-26 13:37:19 UTC
That would make it a duplicate of https://bugzilla.redhat.com/show_bug.cgi?id=1807381

Comment 6 Tomas Hoger 2020-02-26 14:24:55 UTC
Right, I was just investigating this and also came to a conclusion that a typo was made when filing this bug and it's a dupe of CVE-2020-6407.

*** This bug has been marked as a duplicate of bug 1807381 ***