-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 05 Feb 2025 00:18:56 -0500 Source: chromium Binary: chromium chromium-common chromium-common-dbgsym chromium-dbgsym chromium-driver chromium-sandbox chromium-sandbox-dbgsym chromium-shell chromium-shell-dbgsym Architecture: amd64 Version: 133.0.6943.53-1~deb12u1 Distribution: bookworm-security Urgency: high Maintainer: amd64 / i386 Build Daemon (x86-ubc-01) Changed-By: Andres Salomon Description: chromium - web browser chromium-common - web browser - common resources used by the chromium packages chromium-driver - web browser - WebDriver support chromium-sandbox - web browser - setuid security sandbox for chromium chromium-shell - web browser - minimal shell Changes: chromium (133.0.6943.53-1~deb12u1) bookworm-security; urgency=high . [ Andres Salomon ] * New upstream stable release. - CVE-2025-0444: Use after free in Skia. Reported by Francisco Alonso (@revskills). - CVE-2025-0445: Use after free in V8. Reported by 303f06e3. - CVE-2025-0451: Inappropriate implementation in Extensions API. Reported by Vitor Torres and Alesandro Ortiz. * Stop deleting third_party/highway, drop libhwy-dev build-dep, and build against the bundled libhwy due to new API requirements. * d/patches: - fixes/highway-include-path.patch: drop; switching to bundled hwy. - bookworm/highway-blink.patch: drop; switching to bundled hwy. - upstream/array.patch: drop, merged upstream. - upstream/ink-isfinite.patch: drop, merged upstream. - upstream/ruy-include.patch: drop, merged upstream. - upstream/uint.patch: drop, merged upstream. - upstream/variant.patch: drop, merged upstream. - upstream/webrtc-optional.patch: drop, merged upstream. - fixes/perfetto.patch: drop, merged upstream. - system/event.patch: drop, upstream no longer uses libevent. - ungoogled/disable-privacy-sandbox.patch: refresh from upstream. - fixes/highway-include-path.patch: delete a libhwy build test, add another header build fix. - bookworm/clang19.patch: add patch to disable unsupported build args - fixes/optional.patch: add header build fix. - bookworm/gn-absl.patch: add global visibilty for more symbols. - bookworm/dq-forward-iterator.patch: add workaround for bookworm's libstdc++ 12. - bookworm/constflatset.patch, bookworm/constexpr.patch: add another workaround for bookworm's libstdc++ 12. . [ Timothy Pearson ] * d/patches/ppc64le: - third_party/0001-Add-PPC64-support-for-boringssl.patch: Refresh for upstream changes - third_party/0002-Add-PPC64-generated-files-for-boringssl.patch: Refresh for upstream changes - third_party/0002-third_party-libvpx-Remove-bad-ppc64-config.patch: Refresh for upstream changes - third_party/0001-third-party-hwy-wrong-include.patch: Work around incorrect header include Checksums-Sha1: 51bc84aa093ff203fa42c090c574c52386e86014 4703608 chromium-common-dbgsym_133.0.6943.53-1~deb12u1_amd64.deb f56492edce693a5ce3030de18c2fe5fba955eaf4 10189892 chromium-common_133.0.6943.53-1~deb12u1_amd64.deb 39e7dd272f5c532334d4d0950f08fb2273c88d4f 30557496 chromium-dbgsym_133.0.6943.53-1~deb12u1_amd64.deb 5114a80cd18c96bac901e77c680f025af18dbab4 7502916 chromium-driver_133.0.6943.53-1~deb12u1_amd64.deb d73d275cec88e5db5c0b8bccbbd7cb162eaf9836 14068 chromium-sandbox-dbgsym_133.0.6943.53-1~deb12u1_amd64.deb e9b43f82ac577ce0c35aaf6f9626977dfc58b0af 100004 chromium-sandbox_133.0.6943.53-1~deb12u1_amd64.deb 178c2d8e0ac26baa1b8f0d0a808d3c55be560b4d 25515524 chromium-shell-dbgsym_133.0.6943.53-1~deb12u1_amd64.deb 1483a27c8737bf1b5f3ceefdd9b86254f4f7d470 54039616 chromium-shell_133.0.6943.53-1~deb12u1_amd64.deb 6082ad55afe0f0d22207f94840496632ba22a1f4 29335 chromium_133.0.6943.53-1~deb12u1_amd64-buildd.buildinfo 8436548305ccf6f469a69bf58938dd3b310bcead 88214880 chromium_133.0.6943.53-1~deb12u1_amd64.deb Checksums-Sha256: 40f09e1fc9da81b8328a9775bab1eba45a1f70644ca12a37090182ba24a781ae 4703608 chromium-common-dbgsym_133.0.6943.53-1~deb12u1_amd64.deb 4ef9d1728787d980d19289e2d08fffc933a2010f234aa35249f1fbfa6548190a 10189892 chromium-common_133.0.6943.53-1~deb12u1_amd64.deb 88965823fc9839038ab7f92d51eb588edf28e7b51da55f653c84fbe7526f9ba3 30557496 chromium-dbgsym_133.0.6943.53-1~deb12u1_amd64.deb b217ebefe0f77ee3afbea9c0df8181496bcc0e6828d75a79254809f9bb966521 7502916 chromium-driver_133.0.6943.53-1~deb12u1_amd64.deb 5d7d9a8576ef5839a35607b3cf2df443e67aab080c8ac5250247f04c7b833a33 14068 chromium-sandbox-dbgsym_133.0.6943.53-1~deb12u1_amd64.deb 0d330ec8ddfe20e02f9d0d7d24cf36803892daef7cae98e678788aba3cdb3cc7 100004 chromium-sandbox_133.0.6943.53-1~deb12u1_amd64.deb 52786e9438372ba3e064fd311d45aec75b228294ec2948f0d0d7f3350cc249fc 25515524 chromium-shell-dbgsym_133.0.6943.53-1~deb12u1_amd64.deb 91c2c86864e5c2427e19d685698050d2fa2f03aadca8bf6d5777596d7edef603 54039616 chromium-shell_133.0.6943.53-1~deb12u1_amd64.deb 8d233e09a3b1343a355eda55351ae3ff304690d8f8e12fefed7f2501c82606e7 29335 chromium_133.0.6943.53-1~deb12u1_amd64-buildd.buildinfo b4a1d52e46fb2455d851a8df0fde23e101c169053f0ad0ea81ff3ddb41d63db8 88214880 chromium_133.0.6943.53-1~deb12u1_amd64.deb Files: 863026dd023c4fce8eade3a7be702685 4703608 debug optional chromium-common-dbgsym_133.0.6943.53-1~deb12u1_amd64.deb 2390794376e3282e2ecbbb219f532119 10189892 web optional chromium-common_133.0.6943.53-1~deb12u1_amd64.deb 44048d29fff6461b2ad41e1d1fcfe547 30557496 debug optional chromium-dbgsym_133.0.6943.53-1~deb12u1_amd64.deb f2adbaef02fb4235172989a45b83c488 7502916 web optional chromium-driver_133.0.6943.53-1~deb12u1_amd64.deb 7e404ff99a4a95c7771a961c7c0e72ca 14068 debug optional chromium-sandbox-dbgsym_133.0.6943.53-1~deb12u1_amd64.deb d24ade55177922cd3a0cb1bdd8657b04 100004 web optional chromium-sandbox_133.0.6943.53-1~deb12u1_amd64.deb fd958adfbb818c1b0bc2ef6def86ed7f 25515524 debug optional chromium-shell-dbgsym_133.0.6943.53-1~deb12u1_amd64.deb fbdb26960f0986ecdb9510ed314282fb 54039616 web optional chromium-shell_133.0.6943.53-1~deb12u1_amd64.deb fe00b827b17bb1127152a7592bbc3b8b 29335 web optional chromium_133.0.6943.53-1~deb12u1_amd64-buildd.buildinfo f18abb2fa39fd905b9fa3d6fccd4281c 88214880 web optional chromium_133.0.6943.53-1~deb12u1_amd64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE4Unr4QHS5Yi4rr9Q3KGKEAtjIVgFAmekFvkACgkQ3KGKEAtj IVilaBAAiPNE9ngghMQSfdGbLJfc1UCtul6Ib9ve7kZPo2F3GRrfj61LeN/pVRCo l1oKa/jFZVuzJrg9Wv8PAxztWMHiM1rQjTk4pUuvuazdYm0srWUWNAJxn0fX3kqZ p6aAN38YB7jpVFY7WbjYg41QRp1ZEhN6wYL0IiHaJ8EFZL3xnD1q1NIw/+K9SMoi SwgZ8GQmpYeb2tEFH0IRzHN1WNsbUx3SbkVXlJplebcOZDTqtihHcEmJPu6d0TeW OeHPQwI87tkBWCxoJsK2L9QbGthnEZsmiazupv5XhxH8Cm/CdRsuv0G4v8glUWxJ iQVD4i0UUm0xl74uNn06Vq/d7z2RYvDVKecgwwEy13Swp6yFaee5MjLoFd2CT/jI Bn15SoOL1FdKwY9t6DqK78kIYEPToqMVkjLlQWMs0rWQlaYq5crgVPiYpbSUu90v mWblQYGLMj+VBCH4AWO7APrgvNFMY5bfFbv5LZ8A/uccDPqmy8RGWQIP1EldLK8l I/XMHLZOhhTOrbS9F1dr8FPVaTd//TTFEF8Yy+hpibGoTSbbgf0VARp/B3XCuqGR ufV8QCwslq8pv9r511MQyptESA96Sl+FtSmAGEINSb4YaFgjQZDExnB1knFfipBR CylnOszF2Ffl6DzvSKdlNT0aT+0UuNxQ42D2MK8EJSTUkzJEfp0= =MA6P -----END PGP SIGNATURE-----