-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 05 Feb 2025 00:18:56 -0500 Source: chromium Binary: chromium chromium-common chromium-common-dbgsym chromium-dbgsym chromium-driver chromium-sandbox chromium-sandbox-dbgsym chromium-shell chromium-shell-dbgsym Architecture: armhf Version: 133.0.6943.53-1~deb12u1 Distribution: bookworm-security Urgency: high Maintainer: arm Build Daemon (arm-conova-01) Changed-By: Andres Salomon Description: chromium - web browser chromium-common - web browser - common resources used by the chromium packages chromium-driver - web browser - WebDriver support chromium-sandbox - web browser - setuid security sandbox for chromium chromium-shell - web browser - minimal shell Changes: chromium (133.0.6943.53-1~deb12u1) bookworm-security; urgency=high . [ Andres Salomon ] * New upstream stable release. - CVE-2025-0444: Use after free in Skia. Reported by Francisco Alonso (@revskills). - CVE-2025-0445: Use after free in V8. Reported by 303f06e3. - CVE-2025-0451: Inappropriate implementation in Extensions API. Reported by Vitor Torres and Alesandro Ortiz. * Stop deleting third_party/highway, drop libhwy-dev build-dep, and build against the bundled libhwy due to new API requirements. * d/patches: - fixes/highway-include-path.patch: drop; switching to bundled hwy. - bookworm/highway-blink.patch: drop; switching to bundled hwy. - upstream/array.patch: drop, merged upstream. - upstream/ink-isfinite.patch: drop, merged upstream. - upstream/ruy-include.patch: drop, merged upstream. - upstream/uint.patch: drop, merged upstream. - upstream/variant.patch: drop, merged upstream. - upstream/webrtc-optional.patch: drop, merged upstream. - fixes/perfetto.patch: drop, merged upstream. - system/event.patch: drop, upstream no longer uses libevent. - ungoogled/disable-privacy-sandbox.patch: refresh from upstream. - fixes/highway-include-path.patch: delete a libhwy build test, add another header build fix. - bookworm/clang19.patch: add patch to disable unsupported build args - fixes/optional.patch: add header build fix. - bookworm/gn-absl.patch: add global visibilty for more symbols. - bookworm/dq-forward-iterator.patch: add workaround for bookworm's libstdc++ 12. - bookworm/constflatset.patch, bookworm/constexpr.patch: add another workaround for bookworm's libstdc++ 12. . [ Timothy Pearson ] * d/patches/ppc64le: - third_party/0001-Add-PPC64-support-for-boringssl.patch: Refresh for upstream changes - third_party/0002-Add-PPC64-generated-files-for-boringssl.patch: Refresh for upstream changes - third_party/0002-third_party-libvpx-Remove-bad-ppc64-config.patch: Refresh for upstream changes - third_party/0001-third-party-hwy-wrong-include.patch: Work around incorrect header include Checksums-Sha1: 42f3e9f96f2430d912fe9c44d8efb45032a6e571 5044448 chromium-common-dbgsym_133.0.6943.53-1~deb12u1_armhf.deb f8285c283cad42f855e9ac0448ddace180bcfc37 10094100 chromium-common_133.0.6943.53-1~deb12u1_armhf.deb ef3f3a712d4ea92ad4217ad2deb78dab6ee94165 32355664 chromium-dbgsym_133.0.6943.53-1~deb12u1_armhf.deb ced97603c6a686293ef4ec6f04f54b70c81f1a3b 7264256 chromium-driver_133.0.6943.53-1~deb12u1_armhf.deb a3e99024d04e3b6a901bf7f244a674b014af8933 12684 chromium-sandbox-dbgsym_133.0.6943.53-1~deb12u1_armhf.deb 5c075c73dd62ca236ddec630159c26342c6c12ff 99544 chromium-sandbox_133.0.6943.53-1~deb12u1_armhf.deb 828dd12b4dffc9011cc67e2e0727c3839c3d20f6 26317376 chromium-shell-dbgsym_133.0.6943.53-1~deb12u1_armhf.deb dadba0e8b59e29330de9b101e11db342c525eb7f 50858372 chromium-shell_133.0.6943.53-1~deb12u1_armhf.deb 174f031a01a14b773ac457641a820d54b1f7961a 29256 chromium_133.0.6943.53-1~deb12u1_armhf-buildd.buildinfo 93a2973d00d338a451d0147c461924a6d7fa6d6a 73005880 chromium_133.0.6943.53-1~deb12u1_armhf.deb Checksums-Sha256: db44920e9a1fb95593f9b8197b522776d5501aac13629c9ea4ed92f4c8699135 5044448 chromium-common-dbgsym_133.0.6943.53-1~deb12u1_armhf.deb 8993046aa4b298d55c9e700dbf0eedc432b6bfba0a6c6769ac5e485944ec623e 10094100 chromium-common_133.0.6943.53-1~deb12u1_armhf.deb cb175ddec792522df4fd8f89a5c36deb36889e4fd47f13f7fbd73ff22d9fd90d 32355664 chromium-dbgsym_133.0.6943.53-1~deb12u1_armhf.deb 21d52e8eb33361744ea6cbe51f32b04ef442709fee5c1ca42de226e2e909c47c 7264256 chromium-driver_133.0.6943.53-1~deb12u1_armhf.deb 18943d98109abcbfef4b24c86c17589381d449b4ca4dbb0c2d3174a846d6c60c 12684 chromium-sandbox-dbgsym_133.0.6943.53-1~deb12u1_armhf.deb 5cae7ea741f95af311ec6de6988938045de72a526abce30d3b179cc370f3b00a 99544 chromium-sandbox_133.0.6943.53-1~deb12u1_armhf.deb 46a29f8a6023c710167eb49879d108cb46f445ffe844e671d72326007d81bbd4 26317376 chromium-shell-dbgsym_133.0.6943.53-1~deb12u1_armhf.deb ffa416ac739c2db9f56e03cd12357efd448fe3b2a1dbdc1afbe32ef7b92ed97b 50858372 chromium-shell_133.0.6943.53-1~deb12u1_armhf.deb 2bd1c4f656e958c23851d6eee6b348f99af490f10d2c36377ec4e5ff4b89b822 29256 chromium_133.0.6943.53-1~deb12u1_armhf-buildd.buildinfo a3e8c40adaade1234a2d76cde1ab42000b831cb1347d7b5fb3118050d392e807 73005880 chromium_133.0.6943.53-1~deb12u1_armhf.deb Files: e60975b4d665421f7c3d30fafe903fc4 5044448 debug optional chromium-common-dbgsym_133.0.6943.53-1~deb12u1_armhf.deb 32d37c72b62f8df0c18450060ea1347d 10094100 web optional chromium-common_133.0.6943.53-1~deb12u1_armhf.deb eca068dbaf6d128740633e4e261c9718 32355664 debug optional chromium-dbgsym_133.0.6943.53-1~deb12u1_armhf.deb fb40db6bd00b4f79a56897e6ef383fc3 7264256 web optional chromium-driver_133.0.6943.53-1~deb12u1_armhf.deb 3e3dae885ead8a52803611c1ed21d59e 12684 debug optional chromium-sandbox-dbgsym_133.0.6943.53-1~deb12u1_armhf.deb 57aed2a20bcba68ff837dcf27765728a 99544 web optional chromium-sandbox_133.0.6943.53-1~deb12u1_armhf.deb f7d54f1f036aa188adb81133ab536cff 26317376 debug optional chromium-shell-dbgsym_133.0.6943.53-1~deb12u1_armhf.deb 9eca611d1babcbfbd857e6929c620092 50858372 web optional chromium-shell_133.0.6943.53-1~deb12u1_armhf.deb ced89e49eee37ee49177943133666f90 29256 web optional chromium_133.0.6943.53-1~deb12u1_armhf-buildd.buildinfo 02c696602327ad8ec5fcc5d79dbaeefb 73005880 web optional chromium_133.0.6943.53-1~deb12u1_armhf.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEegRwmIwj8f99iF4m4CwlMGxHD8UFAmekWqEACgkQ4CwlMGxH D8Vlpw//f6QwOEa/HSk++BBxQnjoZctesersiWJoqLqekV7b7WglqvfZUQelILcB ibbp8c1I9TVmlkaXQHTNKFQPtawuUh/XU+Cr2LFUhDg4pZbuDrLYj9OTZIsxqLJy uvwN9tqAJP6qUVnEZ6Ghl/1KZDYOiOLvKP9anSZVVDk6KAiJMYzrU74Th+dDT8HV 6xYzih290bTnFq3lExFaYAOPrka3PCht0ZNVztff3yAq6Coqpl30ihvNQhiv+hYe gg1gwRLjGyXTezmdp7yKlc1ptkrUt8hzD8hq1cdq4WnVLvhKNjKgXCX+aj0W3Guw 72dbjhO6Uly4vjWg0Ps5h8/fY/oamLvIVIn3z447j4iB5vMii4kgxHZvG1C1C8pq 896w47OY3a7Ko2WxtLB0fzxAtFUwL1lJNbwsofmZ79ozoFgX9yWFwsY82i5ythwJ 06ca5QgqgPRdcse0ZupNMU2KYCy4066A3pyF1B+moOEELrYVlE9NtLCidC9AkJBB 5V6B03jvGjRebYzzWRpa7tyKHn1foBgWIDexn+WFMYjJHSLRnqpkd2l0pXjkyz6a DNjGzH9swwPL+zrsNSXnuz9R6hfTRpw4+7WQUkAJaQvoMRPbX1IjZ2x4E/f45yAU zhUCrq3CHY8srU6tXZLZBmHasDyfulsww6T0aoO8e1BWNdMe2QU= =JNQ8 -----END PGP SIGNATURE-----