Skip to content

chore: cherry-pick 20 changes from angle, chromium, webrtc#51907

Merged
VerteDinde merged 1 commit into
40-x-yfrom
security-backport/40-x-y/2026-06-06
Jun 7, 2026
Merged

chore: cherry-pick 20 changes from angle, chromium, webrtc#51907
VerteDinde merged 1 commit into
40-x-yfrom
security-backport/40-x-y/2026-06-06

Conversation

@VerteDinde
Copy link
Copy Markdown
Member

Backports the following changes:

Covers the security fixes from the Chrome 148.0.7778.178 stable release that were missing from the 40-x-y tree (Chromium 144.0.7559.236) — none of the fixes from this release were present, including the M144-LTS merges Chrome made after the current pin.

For CVE-2026-9114 (QUIC use-after-free), the cherry-pick is the same hardening mitigation Chrome shipped on stable (ADVANCED_MEMORY_SAFETY_CHECKS() on the vulnerable class); the actual fix (7900197) landed on Chromium main on 2026-06-04 and has not shipped in any Chrome stable channel yet.

Intentionally not backported: 7765503 (CVE-2026-9123) touches only chromecast/media/, which Electron does not compile.

Notes: Security: backported fixes for CVE-2026-9110, CVE-2026-9111, CVE-2026-9112, CVE-2026-9113, CVE-2026-9114, CVE-2026-9115, CVE-2026-9116, CVE-2026-9117, CVE-2026-9118, CVE-2026-9119, CVE-2026-9120, CVE-2026-9121, CVE-2026-9122, CVE-2026-9124, CVE-2026-9126.

@VerteDinde VerteDinde requested a review from a team as a code owner June 6, 2026 06:45
@VerteDinde VerteDinde added security 🔒 semver/patch backwards-compatible bug fixes backport-check-skip Skip trop's backport validity checking 40-x-y labels Jun 6, 2026
@VerteDinde VerteDinde merged commit efa20f4 into 40-x-y Jun 7, 2026
127 of 129 checks passed
@release-clerk
Copy link
Copy Markdown

release-clerk Bot commented Jun 7, 2026

Release Notes Persisted

Security: backported fixes for CVE-2026-9110, CVE-2026-9111, CVE-2026-9112, CVE-2026-9113, CVE-2026-9114, CVE-2026-9115, CVE-2026-9116, CVE-2026-9117, CVE-2026-9118, CVE-2026-9119, CVE-2026-9120, CVE-2026-9121, CVE-2026-9122, CVE-2026-9124, CVE-2026-9126.

@VerteDinde VerteDinde deleted the security-backport/40-x-y/2026-06-06 branch June 7, 2026 04:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

40-x-y backport-check-skip Skip trop's backport validity checking security 🔒 semver/patch backwards-compatible bug fixes

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants