CVE-2024-5834
published 2024-06-11CVE-2024-5834: Inappropriate implementation in Dawn in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to execute arbitrary code via a crafted HTML page…
PriorityP347high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
0.57%
43.1th percentile
Inappropriate implementation in Dawn in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chromium | chromium | >= 0 < 126.0.6478.56-1~deb12u1 | 126.0.6478.56-1~deb12u1 |
| chromium | chromium | >= 0 < 126.0.6478.56-1 | 126.0.6478.56-1 |
| chromium | chromium | >= 0 < 126.0.6478.56-1 | 126.0.6478.56-1 |
| debian | chromium | < chromium 126.0.6478.56-1~deb12u1 (bookworm) | chromium 126.0.6478.56-1~deb12u1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| chrome | < 126.0.6478.54 | 126.0.6478.54 | |
| chrome | >= 126.0.6478.54 < 126.0.6478.54 | 126.0.6478.54 | |
| chrome_chrome | — | — | |
| msrc | microsoft_edge | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_debian8.8HIGH
vendor_msrc8.8HIGH
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: io_uring: check for overflows in io_pin_pages
vendor_redhat·2024-12-27·CVSS 5.5
CVE-2024-53187 [MEDIUM] CWE-190 kernel: io_uring: check for overflows in io_pin_pages
kernel: io_uring: check for overflows in io_pin_pages
In the Linux kernel, the following vulnerability has been resolved:
io_uring: check for overflows in io_pin_pages
WARNING: CPU: 0 PID: 5834 at io_uring/memmap.c:144 io_pin_pages+0x149/0x180 io_uring/memmap.c:144
CPU: 0 UID: 0 PID: 5834 Comm: syz-executor825 Not tainted 6.12.0-next-20241118-syzkaller #0
Call Trace:
__io_uaddr_map+0xfb/0x2d0 io_uring/memmap.c:183
io_rings_map io_uring/io_uring.c:2611 [inline]
io_allocate_scq_urings+0x1c0/0x650 io_uring/io_uring.c:3470
io_uring_create+0x5b5/0xc00 io_uring/io_uring.c:3692
io_uring_setup io_uring/io_uring.c:3781 [inline]
...
io_pin_pages()'s uaddr parameter came directly from the user and can be
garbage. Don't just add size to it as it can overflow.
Package: kernel (Red Hat Enterprise Li
Microsoft
Chromium: CVE-2024-5834 Inappropriate implementation in Dawn
vendor_msrc·2024-06-11·CVSS 8.8
CVE-2024-5834 [HIGH] Chromium: CVE-2024-5834 Inappropriate implementation in Dawn
Chromium: CVE-2024-5834 Inappropriate implementation in Dawn
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the version of the browser?
In your Microsoft Edge browser, click on the 3 dots (...) on the very right-hand side of the window
Click on Help and Feedback
Click on About Microsoft Edge
Chrome
Stable Channel Update for Desktop: CVE-2024-5833
vendor_chrome·2024-06-11·CVSS 8.8
CVE-2024-5833 [HIGH] Stable Channel Update for Desktop: CVE-2024-5833
Stable Channel Update for Desktop
CVE-2024-5833: Type Confusion in V8. Reported by @ginggilBesel on 2024-05-24 [$5000][ 342840932 ] High CVE-2024-5834: Inappropriate implementation in Dawn
Reported by gelatin dessert on 2024-05-26 [$3000][ 341991535 ] High CVE-2024-5835: Heap buffer overflow in Tab Groups
Severity: high
Debian
CVE-2024-5834: chromium - Inappropriate implementation in Dawn in Google Chrome prior to 126.0.6478.54 all...
vendor_debian·2024·CVSS 8.8
CVE-2024-5834 [HIGH] CVE-2024-5834: chromium - Inappropriate implementation in Dawn in Google Chrome prior to 126.0.6478.54 all...
Inappropriate implementation in Dawn in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 126.0.6478.56-1~deb12u1)
bullseye: open
forky: resolved (fixed in 126.0.6478.56-1)
sid: resolved (fixed in 126.0.6478.56-1)
trixie: resolved (fixed in 126.0.6478.56-1)
GHSA
GHSA-664v-jfq4-4mfq: Inappropriate implementation in Dawn in Google Chrome prior to 126
ghsa_unreviewed·2024-06-11
CVE-2024-5834 [HIGH] CWE-94 GHSA-664v-jfq4-4mfq: Inappropriate implementation in Dawn in Google Chrome prior to 126
Inappropriate implementation in Dawn in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
OSV
CVE-2024-5834: Inappropriate implementation in Dawn in Google Chrome prior to 126
osv·2024-06-11·CVSS 8.8
CVE-2024-5834 [HIGH] CVE-2024-5834: Inappropriate implementation in Dawn in Google Chrome prior to 126
Inappropriate implementation in Dawn in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://chromereleases.googleblog.com/2024/06/stable-channel-update-for-desktop.htmlhttps://issues.chromium.org/issues/342840932https://lists.fedoraproject.org/archives/list/[email protected]/message/7VXA32LXMNK3DSK3JBRLTBPFUH7LTODU/https://lists.fedoraproject.org/archives/list/[email protected]/message/MPU7AB53QQVNTBPGRMJRY5SXJNYWW3FX/https://chromereleases.googleblog.com/2024/06/stable-channel-update-for-desktop.htmlhttps://issues.chromium.org/issues/342840932https://lists.fedoraproject.org/archives/list/[email protected]/message/7VXA32LXMNK3DSK3JBRLTBPFUH7LTODU/https://lists.fedoraproject.org/archives/list/[email protected]/message/MPU7AB53QQVNTBPGRMJRY5SXJNYWW3FX/
2024-06-11
Published