-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 05 Feb 2025 00:18:56 -0500 Source: chromium Binary: chromium chromium-common chromium-common-dbgsym chromium-dbgsym chromium-driver chromium-sandbox chromium-sandbox-dbgsym chromium-shell chromium-shell-dbgsym Architecture: i386 Version: 133.0.6943.53-1~deb12u1 Distribution: bookworm-security Urgency: high Maintainer: i386 Build Daemon (x86-grnet-01) Changed-By: Andres Salomon Description: chromium - web browser chromium-common - web browser - common resources used by the chromium packages chromium-driver - web browser - WebDriver support chromium-sandbox - web browser - setuid security sandbox for chromium chromium-shell - web browser - minimal shell Changes: chromium (133.0.6943.53-1~deb12u1) bookworm-security; urgency=high . [ Andres Salomon ] * New upstream stable release. - CVE-2025-0444: Use after free in Skia. Reported by Francisco Alonso (@revskills). - CVE-2025-0445: Use after free in V8. Reported by 303f06e3. - CVE-2025-0451: Inappropriate implementation in Extensions API. Reported by Vitor Torres and Alesandro Ortiz. * Stop deleting third_party/highway, drop libhwy-dev build-dep, and build against the bundled libhwy due to new API requirements. * d/patches: - fixes/highway-include-path.patch: drop; switching to bundled hwy. - bookworm/highway-blink.patch: drop; switching to bundled hwy. - upstream/array.patch: drop, merged upstream. - upstream/ink-isfinite.patch: drop, merged upstream. - upstream/ruy-include.patch: drop, merged upstream. - upstream/uint.patch: drop, merged upstream. - upstream/variant.patch: drop, merged upstream. - upstream/webrtc-optional.patch: drop, merged upstream. - fixes/perfetto.patch: drop, merged upstream. - system/event.patch: drop, upstream no longer uses libevent. - ungoogled/disable-privacy-sandbox.patch: refresh from upstream. - fixes/highway-include-path.patch: delete a libhwy build test, add another header build fix. - bookworm/clang19.patch: add patch to disable unsupported build args - fixes/optional.patch: add header build fix. - bookworm/gn-absl.patch: add global visibilty for more symbols. - bookworm/dq-forward-iterator.patch: add workaround for bookworm's libstdc++ 12. - bookworm/constflatset.patch, bookworm/constexpr.patch: add another workaround for bookworm's libstdc++ 12. . [ Timothy Pearson ] * d/patches/ppc64le: - third_party/0001-Add-PPC64-support-for-boringssl.patch: Refresh for upstream changes - third_party/0002-Add-PPC64-generated-files-for-boringssl.patch: Refresh for upstream changes - third_party/0002-third_party-libvpx-Remove-bad-ppc64-config.patch: Refresh for upstream changes - third_party/0001-third-party-hwy-wrong-include.patch: Work around incorrect header include Checksums-Sha1: 2ae7ff6a7eb23b06d0265903b84c3ff2a556c28a 4775556 chromium-common-dbgsym_133.0.6943.53-1~deb12u1_i386.deb 104174638d4fbe17290ddafe839b319a5749a2aa 10355596 chromium-common_133.0.6943.53-1~deb12u1_i386.deb 3dc3c8bd961ba01087f93646b6568b9fafaf7b8f 32897712 chromium-dbgsym_133.0.6943.53-1~deb12u1_i386.deb 783b91fb760df5730ff4be2603c527939f23a098 7922316 chromium-driver_133.0.6943.53-1~deb12u1_i386.deb 632a11b1d8bbe7918517f738272789fa9b32d659 14116 chromium-sandbox-dbgsym_133.0.6943.53-1~deb12u1_i386.deb 9660c851b97f743efe9962945e5e8d84b6c037b8 99860 chromium-sandbox_133.0.6943.53-1~deb12u1_i386.deb 12b314d22809a2ffc58f4073588fa27cda5397d3 27927372 chromium-shell-dbgsym_133.0.6943.53-1~deb12u1_i386.deb 94f65b487aa348d01be14449d360858b217d7392 56218280 chromium-shell_133.0.6943.53-1~deb12u1_i386.deb dfdfed9c13216dffdb7380c54333df66f72fbaaa 29344 chromium_133.0.6943.53-1~deb12u1_i386-buildd.buildinfo 464b606cf1e6269f8e3e507091328d2c47a31ee4 80453848 chromium_133.0.6943.53-1~deb12u1_i386.deb Checksums-Sha256: 09ea264c8d11e6bed3d081750676c785fe38877a29ace68fccbb58ace13bc658 4775556 chromium-common-dbgsym_133.0.6943.53-1~deb12u1_i386.deb a81e6a7280a06c87295634fe0a52881cb077e07b6327a55bf3c1b3facc330bd0 10355596 chromium-common_133.0.6943.53-1~deb12u1_i386.deb 9dab88fce12ce3f21810b691ec5a454a184a47852583fb8d8c04ce9da3396f9d 32897712 chromium-dbgsym_133.0.6943.53-1~deb12u1_i386.deb 50f789c67b43a2f02cca3a75ebd1ef3d4cb1b744610618ffa2bd673d7b7c056d 7922316 chromium-driver_133.0.6943.53-1~deb12u1_i386.deb cfca5264f9a8a8708a2910ded397e86de05835fe7c59fcbdb1362384d3e12107 14116 chromium-sandbox-dbgsym_133.0.6943.53-1~deb12u1_i386.deb 75af33ad67bd253b81ffc831d25d23a1688b3f311645cd30b5222497c5153f33 99860 chromium-sandbox_133.0.6943.53-1~deb12u1_i386.deb dbd7e8d3bbcd38c03cfd085b382c8a846f6edf589b6fa722cf18e1b7e1f920fc 27927372 chromium-shell-dbgsym_133.0.6943.53-1~deb12u1_i386.deb 3a369ccffe1ec302251af1f57139044528e95fe00eeeffe462ac8f31ee4546f8 56218280 chromium-shell_133.0.6943.53-1~deb12u1_i386.deb 1e2260b8dda5925cdbe726474a53219ff2bd13cbb826e2a958f641bcb66aac21 29344 chromium_133.0.6943.53-1~deb12u1_i386-buildd.buildinfo b26d0e19e03a39eca982fe2afcc844d1ea546a0d92564ce98367d8dddf396626 80453848 chromium_133.0.6943.53-1~deb12u1_i386.deb Files: 579ed8cf5194dc32320c61de6cbe8bf3 4775556 debug optional chromium-common-dbgsym_133.0.6943.53-1~deb12u1_i386.deb 41f662838d62054bd3d74b014f8329d1 10355596 web optional chromium-common_133.0.6943.53-1~deb12u1_i386.deb 84733261a8fe62ee2194d9a17323a4d5 32897712 debug optional chromium-dbgsym_133.0.6943.53-1~deb12u1_i386.deb d3f8dd3609f3e745bc59175364517398 7922316 web optional chromium-driver_133.0.6943.53-1~deb12u1_i386.deb 6e009a0d18a4f335803cb5dc0a7668c3 14116 debug optional chromium-sandbox-dbgsym_133.0.6943.53-1~deb12u1_i386.deb e6d425b1af35e8bda0d93133a0e1cbf1 99860 web optional chromium-sandbox_133.0.6943.53-1~deb12u1_i386.deb ba36235a6726c74a24c49d70efa4608c 27927372 debug optional chromium-shell-dbgsym_133.0.6943.53-1~deb12u1_i386.deb 30e0eb7db06ade69b31dc79806de6d9f 56218280 web optional chromium-shell_133.0.6943.53-1~deb12u1_i386.deb 704e38b61d351a52bb49e117351f0fcb 29344 web optional chromium_133.0.6943.53-1~deb12u1_i386-buildd.buildinfo a229339b6ba186c2b277638bc306f0fc 80453848 web optional chromium_133.0.6943.53-1~deb12u1_i386.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEyTfXx8sBpQ0Lh3cUU9a0/LcaTpMFAmekZnoACgkQU9a0/Lca TpOwvQ/+I6+yiCEFm0GDdn1jg5jvi0l76IzmIua+WXPtXl50r/ahqneJtpfmbNJT hQCyxG87l0IwYVeBykftVKvkMaOoAQ7fNQBHU0/BqNt62jOD+ZpuT09OwT1WwE5H l4CPuE6MxaqcGR0/MFRlnYb2VjGik4nRStI/YpkuKam99Ge7NZRYCISkdQntz5J+ b/hkGBjJemhahjdOENhmyRmFghq3sD7dY/vxtS5oXsexytQNZjhB0vbOgfuGDn/g EuIVUi4L+/rjN2pCti7+MQ8A1yGSwfim90QlT2SAHs6ki5NXWL4E5EvSX7nLmCIa GB6knelDkmFsA3hfg4rYqsjsy1O7vkGLBqwz+VAJ+aVH0LdQMRHcUP2jzix954tR GO0brnHwFzvVjv9PoHu4SnQFE9slpUjWJTM4WR1FRCs+S1wAvWNV0wRbS/JfvrLc caouFzNIr8FBm4InYNUQud2UAagQk4giMt2wsY2RyLp5t+MqO3k4+cji9VPKilvt mKTcTMzqjLFm1J7vlX96c1bapeywIOR7+Wb4F4YpkJ2hxvtgE3js1/8mVQHXNY2a 3BPT3z69t0ULQidWeeIeUsj7/ccpVgd2TOjGwOi3XJ/lpHh2Geb6Aj0KU2TCXBOV 3XafOTPv893IHaBMRn6lFk8TMjsOlVej7WzLd8bJr5iR9lm4Doc= =ssGV -----END PGP SIGNATURE-----