-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 11 Dec 2024 15:33:53 -0500 Source: chromium Binary: chromium chromium-common chromium-common-dbgsym chromium-dbgsym chromium-driver chromium-sandbox chromium-sandbox-dbgsym chromium-shell chromium-shell-dbgsym Architecture: armhf Version: 131.0.6778.139-1~deb12u1 Distribution: bookworm-security Urgency: high Maintainer: arm Build Daemon (arm-conova-01) Changed-By: Andres Salomon Description: chromium - web browser chromium-common - web browser - common resources used by the chromium packages chromium-driver - web browser - WebDriver support chromium-sandbox - web browser - setuid security sandbox for chromium chromium-shell - web browser - minimal shell Changes: chromium (131.0.6778.139-1~deb12u1) bookworm-security; urgency=high . [ Andres Salomon ] * New upstream security release. - CVE-2024-12381: Type Confusion in V8. Reported by Seunghyun Lee (@0x10n). - CVE-2024-12382: Use after free in Translate. Reported by lime(@limeSec_) from TIANGONG Team of Legendsec at QI-ANXIN Group. * (Temporarily?) switch from llvm's libc++ to gcc's libstdc++ to simplify the prior clang-16/19 upgrades. * d/patches: - fixes/bindgen.patch: refresh. - upstream/dawn-strlen.patch: add gcc-specific build fix. - upstream/ink-isfinite.patch: add gcc-specific build fix. - upstream/webrtc-optional.patch: add gcc-specific build fix. - upstream/variant.patch: add gcc-specific build fixes. - upstream/array.patch: add gcc-specific build fix. - fixes/absl-optional.patch: re-introduce clang/gcc build workaround. - upstream/mrc-copy-op.patch: add gcc-specific build fix. - fixes/font-gc-asan.patch: add a better workaround for bad font-gc behavior under libstdc++. This is self-contained and small, unlike the prior reverts of the switch to font garbage collection. - bookworm/constexpr.patch: re-enable (and refresh) build fix specifically for gcc 12. - bookworm/constexpr2.patch: re-enable build fix for gcc 12. - bookworm/bubble-contents.patch: re-enable build fix for gcc 12. . [ Nathan Teodosio ] * Simplify fixes/bindgen.patch so it doesn't need frequent rebasing. . [ Daniel Richard G. ] * d/copyright: Expand list of Files-Excluded: entries. * d/rules: Various updates to get-orig-source rule, including use of grep-dctrl(1) and the LASTCHANGE.committime timestamp. * d/scripts/check-upstream: Avoid issues with inaccurate $(pwd) value and spaces in filenames, and print all errors instead of only the first one. Checksums-Sha1: 3d62c9dc71b5d9075af232f2e0835119483b6292 5742492 chromium-common-dbgsym_131.0.6778.139-1~deb12u1_armhf.deb 729905aa862b8b0e7a0d0147a8a21e56cf6529dc 10060536 chromium-common_131.0.6778.139-1~deb12u1_armhf.deb e7861f5642d9263ddf6f87210bd76097de1e2ca0 33131308 chromium-dbgsym_131.0.6778.139-1~deb12u1_armhf.deb 0e14eafee60a56b68e9a03658c5382cc661316be 6916244 chromium-driver_131.0.6778.139-1~deb12u1_armhf.deb 712438f66c355bba8767044979c268b243f2dc69 12704 chromium-sandbox-dbgsym_131.0.6778.139-1~deb12u1_armhf.deb 4925938fa4855d64ad27a5471784a256260928ce 97708 chromium-sandbox_131.0.6778.139-1~deb12u1_armhf.deb c3fd12831e3c645b7175d078c41c5a909cb2d9eb 27545760 chromium-shell-dbgsym_131.0.6778.139-1~deb12u1_armhf.deb ca81ba558036bb9ed91e59057b44140af9f64b8b 50193216 chromium-shell_131.0.6778.139-1~deb12u1_armhf.deb 830e8c4fbd2a011617a1b1b1aff09d4c1500a8df 24658 chromium_131.0.6778.139-1~deb12u1_armhf-buildd.buildinfo 886b2cc69890c029b1e8c84a9e074058ab327e09 72217648 chromium_131.0.6778.139-1~deb12u1_armhf.deb Checksums-Sha256: 7c3621c6fddb1a8ef99c5599efdc9b4183953caa77b93f9682790daf5cebe11b 5742492 chromium-common-dbgsym_131.0.6778.139-1~deb12u1_armhf.deb 2cd78690ba50c3b1d6fc1b03ca3a4276b035e270bdb677afdf58db34a1398f88 10060536 chromium-common_131.0.6778.139-1~deb12u1_armhf.deb 156084419149d10a0553792b110742641e44637ca88b97fff7c77c1fca933606 33131308 chromium-dbgsym_131.0.6778.139-1~deb12u1_armhf.deb 56aa3f435b3c85caab9b72018b4d31631b9b932857548c5c41b4fb00e1bf743e 6916244 chromium-driver_131.0.6778.139-1~deb12u1_armhf.deb 6bc7dcf477535effa2ad6c37a091776bb67c2478e8ceed80a17e85fba45b8d33 12704 chromium-sandbox-dbgsym_131.0.6778.139-1~deb12u1_armhf.deb 0a6c0a5eba3bb9439680fffa7b3b43f8b9e58ef2d090f7a924d18b67d051e79d 97708 chromium-sandbox_131.0.6778.139-1~deb12u1_armhf.deb bd326631f522bdd68fdf6f1b3868403dc153c029ad99c13d2554a5681131a496 27545760 chromium-shell-dbgsym_131.0.6778.139-1~deb12u1_armhf.deb 222a17eff926174ca2a971c027f597e1739b9f43500093223822714c3315b2d6 50193216 chromium-shell_131.0.6778.139-1~deb12u1_armhf.deb efc89ce769d08f35224fcc80618904c0256f6726a058910ae417bd6e3b83ffe8 24658 chromium_131.0.6778.139-1~deb12u1_armhf-buildd.buildinfo c3d0aa65e807e1bedc6380ab0bd3bc09f154b7b38f21beb26b9ce9a918e1da04 72217648 chromium_131.0.6778.139-1~deb12u1_armhf.deb Files: 703002b34041c7e531980f439062dbd8 5742492 debug optional chromium-common-dbgsym_131.0.6778.139-1~deb12u1_armhf.deb 8a7d8488f321cee04071bc5e6dd91e04 10060536 web optional chromium-common_131.0.6778.139-1~deb12u1_armhf.deb 6b063b818dde0b9c7f40a82ef741a7ec 33131308 debug optional chromium-dbgsym_131.0.6778.139-1~deb12u1_armhf.deb e957ce28860f208fc02c8fa22d25f0f0 6916244 web optional chromium-driver_131.0.6778.139-1~deb12u1_armhf.deb 841c04aa4e74cca86a7c102c4e18e594 12704 debug optional chromium-sandbox-dbgsym_131.0.6778.139-1~deb12u1_armhf.deb 26fef8ffd268e8f217b785703fb1cc8f 97708 web optional chromium-sandbox_131.0.6778.139-1~deb12u1_armhf.deb a654190ecc02cf9d4e7048996b8c71ce 27545760 debug optional chromium-shell-dbgsym_131.0.6778.139-1~deb12u1_armhf.deb 349e45bf47730a3d11f0648eccbbc4b6 50193216 web optional chromium-shell_131.0.6778.139-1~deb12u1_armhf.deb 89761306adb86aa90d2a0d63e2d22252 24658 web optional chromium_131.0.6778.139-1~deb12u1_armhf-buildd.buildinfo fc74f7782b165962256d61060dcc90c4 72217648 web optional chromium_131.0.6778.139-1~deb12u1_armhf.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEegRwmIwj8f99iF4m4CwlMGxHD8UFAmda2lwACgkQ4CwlMGxH D8W/7xAA1/YUvgw5o1U9ThOthWPb3zdU1qDwvWL/bgHtEsDoQDY7nlWwl8OS8FBM RKJ/22GzBMERn748lzZqdCnzdtN9XHaY1YOtwFAa6uR2WjVl2GdnwkxMktjRPnPi Gl9qly19SybWzC7hOw2ogPFC383NQYEzBcF3bFtkHGk+/DcTXYKt72JAWXpSxI+o 2pM9eH38aJtVfm0GGD0yfbUzQdd93TJaX2mWwFTAwVkXfcxUVk6N6StzMzSwqnLl sdxiHLD63F/C7J4Npy/iSGXV81S/ijDkygqKFVqXRMSvgivKNVzBG7awHawwl36A PBIym4ikixt1cfGkYmAJp9wES3UKq5G0QMf8fmgk0eRAShJwpvdLOHGiw6tzzVDe qVV9+OAQMzW9io7w+wH7fhVoyBzvyQzU0Frm4OYs2bqnJU0K980CIvim1hlJEx3Y BuIUGArJyEt2tNQUD0e/RFheilFxzKsFdtzNGsOO7bZevVrpZdHtk/7cLANay3bJ CpG0PK+1SEzeXZ4WrQq/pjtlJGGj7EJ08HUEHNMwd6aroi+ajl0wrrMjeZ+lAaH0 KvE6nfYoPJ/9WYx2dHGqbJXflE7PrYKqb2obxLnLT2XRxmIWQezJH5uA7ZeL4Nai THvJMYbheQ/1F9Htqs/ZCohb8CbY2JUSjke2e9DoQ3J24FXH4IE= =lJSj -----END PGP SIGNATURE-----