-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 11 Dec 2024 15:33:53 -0500 Source: chromium Binary: chromium chromium-common chromium-common-dbgsym chromium-dbgsym chromium-driver chromium-sandbox chromium-sandbox-dbgsym chromium-shell chromium-shell-dbgsym Architecture: amd64 Version: 131.0.6778.139-1~deb12u1 Distribution: bookworm-security Urgency: high Maintainer: amd64 / i386 Build Daemon (x86-csail-01) Changed-By: Andres Salomon Description: chromium - web browser chromium-common - web browser - common resources used by the chromium packages chromium-driver - web browser - WebDriver support chromium-sandbox - web browser - setuid security sandbox for chromium chromium-shell - web browser - minimal shell Changes: chromium (131.0.6778.139-1~deb12u1) bookworm-security; urgency=high . [ Andres Salomon ] * New upstream security release. - CVE-2024-12381: Type Confusion in V8. Reported by Seunghyun Lee (@0x10n). - CVE-2024-12382: Use after free in Translate. Reported by lime(@limeSec_) from TIANGONG Team of Legendsec at QI-ANXIN Group. * (Temporarily?) switch from llvm's libc++ to gcc's libstdc++ to simplify the prior clang-16/19 upgrades. * d/patches: - fixes/bindgen.patch: refresh. - upstream/dawn-strlen.patch: add gcc-specific build fix. - upstream/ink-isfinite.patch: add gcc-specific build fix. - upstream/webrtc-optional.patch: add gcc-specific build fix. - upstream/variant.patch: add gcc-specific build fixes. - upstream/array.patch: add gcc-specific build fix. - fixes/absl-optional.patch: re-introduce clang/gcc build workaround. - upstream/mrc-copy-op.patch: add gcc-specific build fix. - fixes/font-gc-asan.patch: add a better workaround for bad font-gc behavior under libstdc++. This is self-contained and small, unlike the prior reverts of the switch to font garbage collection. - bookworm/constexpr.patch: re-enable (and refresh) build fix specifically for gcc 12. - bookworm/constexpr2.patch: re-enable build fix for gcc 12. - bookworm/bubble-contents.patch: re-enable build fix for gcc 12. . [ Nathan Teodosio ] * Simplify fixes/bindgen.patch so it doesn't need frequent rebasing. . [ Daniel Richard G. ] * d/copyright: Expand list of Files-Excluded: entries. * d/rules: Various updates to get-orig-source rule, including use of grep-dctrl(1) and the LASTCHANGE.committime timestamp. * d/scripts/check-upstream: Avoid issues with inaccurate $(pwd) value and spaces in filenames, and print all errors instead of only the first one. Checksums-Sha1: 44eb12bc0add18f7acd0b93cca117bcacc5df6ed 4748928 chromium-common-dbgsym_131.0.6778.139-1~deb12u1_amd64.deb 5dc803b6f057d58561eac400ac66a0e2ad4ddb9d 10145588 chromium-common_131.0.6778.139-1~deb12u1_amd64.deb 7dfffd55caac4e29e6f564217f6de9c48c360a8f 32217484 chromium-dbgsym_131.0.6778.139-1~deb12u1_amd64.deb 9c1a84804397cd18c7817efddb2222001df6fd5d 7113880 chromium-driver_131.0.6778.139-1~deb12u1_amd64.deb 8c23b1401461087c3581893310ac747c7ea6b018 14076 chromium-sandbox-dbgsym_131.0.6778.139-1~deb12u1_amd64.deb 3e32b2de6f89f12d68b8f26f7ea24407894f15c2 98176 chromium-sandbox_131.0.6778.139-1~deb12u1_amd64.deb 855e0997033a6ce61f70756208feaed078e422ff 26862988 chromium-shell-dbgsym_131.0.6778.139-1~deb12u1_amd64.deb 05d5843baf9ca638c29bc235ffcff82757591952 53196204 chromium-shell_131.0.6778.139-1~deb12u1_amd64.deb 12117e688db28c5846a1b631b52ab2d2e452db08 24734 chromium_131.0.6778.139-1~deb12u1_amd64-buildd.buildinfo 2e780355c52ff64df12406422ff8a17f7fb685b7 87068100 chromium_131.0.6778.139-1~deb12u1_amd64.deb Checksums-Sha256: 5c8e1c221c029c4c4b3f8714affccbf39416adf36ed7bb270e3df5f4141f013f 4748928 chromium-common-dbgsym_131.0.6778.139-1~deb12u1_amd64.deb 0a9ebc4eab5f4ad0c0a77784d988bc09573feac79b30096f232a2fc6131f46e6 10145588 chromium-common_131.0.6778.139-1~deb12u1_amd64.deb 196c5d655dbf253a874515ea4163e1af261e0e996f6bb7a8e7a32a6e6a750f02 32217484 chromium-dbgsym_131.0.6778.139-1~deb12u1_amd64.deb acca73478684a3a96c2ae41e3709585721864bbe2ebb0c77c6076514f7ee3565 7113880 chromium-driver_131.0.6778.139-1~deb12u1_amd64.deb 5fb32c5a99bcaea6283304a368408bb19047c8cfec0baf4c81a046bb544c97b4 14076 chromium-sandbox-dbgsym_131.0.6778.139-1~deb12u1_amd64.deb 0a9efc16c64d8f2a07ec3255fcc09c5319e2cd61aceceb8531c051d86a9e1143 98176 chromium-sandbox_131.0.6778.139-1~deb12u1_amd64.deb 2d4f6bd5ecaedf48b0079da5e8b5509345ac89b4a217e3c635785969d838ffba 26862988 chromium-shell-dbgsym_131.0.6778.139-1~deb12u1_amd64.deb 861a3a6abbacf0723b0e0b77f5ea92796666f48db8c97b988b38246d2f85fd4f 53196204 chromium-shell_131.0.6778.139-1~deb12u1_amd64.deb a1c013307552d87ccd2fe8e3053cf09cbd5c9943374c02bce74a0aaecedb2d60 24734 chromium_131.0.6778.139-1~deb12u1_amd64-buildd.buildinfo 635930d1c1ffb3119472465377c4013e4218089508c29190c9362f8fc55fa4e1 87068100 chromium_131.0.6778.139-1~deb12u1_amd64.deb Files: d09a660f8aee2bb0bd4a929114f80de4 4748928 debug optional chromium-common-dbgsym_131.0.6778.139-1~deb12u1_amd64.deb 2ca6e4b514142c622f6a3fcee584035f 10145588 web optional chromium-common_131.0.6778.139-1~deb12u1_amd64.deb e97129c411515a90841e1b4245ffab74 32217484 debug optional chromium-dbgsym_131.0.6778.139-1~deb12u1_amd64.deb cefb760a042c70db3e189387745b2fed 7113880 web optional chromium-driver_131.0.6778.139-1~deb12u1_amd64.deb 386d69669d7e4454d55bcefb27c92c67 14076 debug optional chromium-sandbox-dbgsym_131.0.6778.139-1~deb12u1_amd64.deb a5c37eb295387f98d65dc9c1d69d885b 98176 web optional chromium-sandbox_131.0.6778.139-1~deb12u1_amd64.deb 76f0a80950b32b4525a265c72fe5253c 26862988 debug optional chromium-shell-dbgsym_131.0.6778.139-1~deb12u1_amd64.deb 5c0a9cdb04caff7445f3291fdc00f2c2 53196204 web optional chromium-shell_131.0.6778.139-1~deb12u1_amd64.deb b6749d98df233650f383be0f9a6a880b 24734 web optional chromium_131.0.6778.139-1~deb12u1_amd64-buildd.buildinfo 2f2843606d3f1459cd78f8ac75ba4b22 87068100 web optional chromium_131.0.6778.139-1~deb12u1_amd64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEvy6d65NNYPbL6IQIEQ1nooK/IAQFAmda07AACgkQEQ1nooK/ IASynA/+JrdsUS5vXY/tnLjAGxWu6GRZwX5KV3Z/P79eM7QFCqnuaWKUY2yIJ/Ld wkCkRvEc5vtJeFwmeOfsSliVksMgpKdavhGqGOlwJOnvUm+nzuBG1XdRlskGUEKy O8xUd4w3ujNp6eUBtjJEbS4jNLIzftOk6zheN539ck6rB88Y97Gp1t3c5Rru7S/C rI0F8lYEap7FOH84g6Knch+WXdaMjluNTKy6xq2XWa2qP+YLc+LbxlXRfpA5XP2/ 9crP2cbfKXT7v7mMkXqFwktb2fv5SrgIdQXIdXOsTjw1HFzX3IJZ3ZUpk1g79jau E4G0c4Xft34NYnrJy6GrQN3mjN0F3ZZZoLx5RapZQ+mc9y8ltBbA/PYoaJ22UBOr hyS3y5Qn27vyKJiENiXVsisGfmO0/Xqhke7rWG6bkxKXFPIUDr1MdHoZ/ZSsSBC2 VVsMRQ/BhPCwMZPR7tu+DL8DMBZwfBph+JAlmCdYODcfniE2nJUCGsiYdBcFGZKJ hz/feEKEm3FtpFM6jcU7jUtbYpdhMCv/rKVfx9AqsjiFEpy3lPYeLG7ozNm6LbtM Jb4XA8Ylb9SJ5yz+TY+4IMmrRvY/kyHJ5l6ppdjtkpsMo9GnpSFgZuahprTiaqlG Q2U6YL8+PCw+3DxoO0KlnFI4/QUO7UTtbeHlrU767dYvnhx0yFA= =ibhY -----END PGP SIGNATURE-----