Google ChromeOS/ChromeOS Flex (122.0.6045.214) Security Update Advisory

Overview

 

Google has made available an update that addresses a vulnerability in ChromeOS/ChromeOS Flex products. users of affected versions are advised to update to the latest version.

 

Affected Products

 

google ChromeOS/ChromeOS Flex prior to 122.0.6045.214 (platform version 15753.38.0)
google ChromeOS LTS Channel versions prior to 114.0.5735.355 (platform version: 15437.95.0)

 

Resolved Vulnerabilities

 

vulnerability that could allow an unauthorized user to create an administrator in the management portal via authentication bypass (CVE-2024-0204)

Local privilege escalation vulnerability due to exploitation of a use-after-free vulnerability in the netfilter: nf_tables component of the Linux kernel (CVE-2024-1086)

A use-after-free vulnerability in the GPU architecture kernel driver allows an unprivileged local user to access already freed memory by performing improper GPU processing operations (CVE-2023-5427)

Use-after-free vulnerability in the JavaScript engine in Foxit Software’s PDF Reader (CVE-2023-28746)

use-after-free vulnerability in the WebGPU of Google Chrome prior to 120.0.6099.199 that allows heap corruption exploitation via a crafted HTML page (CVE-2024-0225)

stack corruption exploitable via a crafted HTML page when using use after free in Peer Connection in Google Chrome prior to 121.0.6167.139 (CVE-2024-1059)

out-of-bounds memory write vulnerability in the Linux kernel’s transport layer security features due to the way function splice is called using a ktls socket as the target (CVE-2024-0646)

 

Vulnerability Patches

 

vulnerability patches were made available in the March 5, 2024 update. Please follow the instructions on the Referenced Sites to update to the latest Vulnerability Patches version.

google ChromeOS/ChromeOS Flex 122.0.6045.214 (platform version 15753.38.0)
google ChromeOS LTS Channel 114.0.5735.355 (platform version: 15437.95.0)

 

Referenced Sites

 

[1] Stable Channel Update for ChromeOS / ChromeOS Flex
https://chromereleases.googleblog.com/2024/03/stable-channel-update-for-chromeos.html
[2] CVE-2024-0204 Detail
https://nvd.nist.gov/vuln/detail/cve-2024-0204
[3] CVE-2024-1086 Detail
https://nvd.nist.gov/vuln/detail/CVE-2024-1086
[4] CVE-2023-5427 Detail
https://nvd.nist.gov/vuln/detail/CVE-2023-5427
[5] CVE-2023-28744 Detail
https://nvd.nist.gov/vuln/detail/CVE-2023-28744
[6] Long Term Support Channel Update for ChromeOS
https://chromereleases.googleblog.com/2024/03/long-term-support-channel-update-for.html
[7] CVE-2024-0225 Detail
long Term Support Channel Update for ChromeOS https://nvd.nist.gov/vuln/detail/CVE-2024-0225
[8] CVE-2024-1059 Detail
https://nvd.nist.gov/vuln/detail/CVE-2024-1059
[9] CVE-2024-0646 Detail
https://nvd.nist.gov/vuln/detail/CVE-2024-0646