-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 11 Dec 2024 15:33:53 -0500 Source: chromium Binary: chromium chromium-common chromium-common-dbgsym chromium-dbgsym chromium-driver chromium-sandbox chromium-sandbox-dbgsym chromium-shell chromium-shell-dbgsym Architecture: arm64 Version: 131.0.6778.139-1~deb12u1 Distribution: bookworm-security Urgency: high Maintainer: arm Build Daemon (arm-conova-03) Changed-By: Andres Salomon Description: chromium - web browser chromium-common - web browser - common resources used by the chromium packages chromium-driver - web browser - WebDriver support chromium-sandbox - web browser - setuid security sandbox for chromium chromium-shell - web browser - minimal shell Changes: chromium (131.0.6778.139-1~deb12u1) bookworm-security; urgency=high . [ Andres Salomon ] * New upstream security release. - CVE-2024-12381: Type Confusion in V8. Reported by Seunghyun Lee (@0x10n). - CVE-2024-12382: Use after free in Translate. Reported by lime(@limeSec_) from TIANGONG Team of Legendsec at QI-ANXIN Group. * (Temporarily?) switch from llvm's libc++ to gcc's libstdc++ to simplify the prior clang-16/19 upgrades. * d/patches: - fixes/bindgen.patch: refresh. - upstream/dawn-strlen.patch: add gcc-specific build fix. - upstream/ink-isfinite.patch: add gcc-specific build fix. - upstream/webrtc-optional.patch: add gcc-specific build fix. - upstream/variant.patch: add gcc-specific build fixes. - upstream/array.patch: add gcc-specific build fix. - fixes/absl-optional.patch: re-introduce clang/gcc build workaround. - upstream/mrc-copy-op.patch: add gcc-specific build fix. - fixes/font-gc-asan.patch: add a better workaround for bad font-gc behavior under libstdc++. This is self-contained and small, unlike the prior reverts of the switch to font garbage collection. - bookworm/constexpr.patch: re-enable (and refresh) build fix specifically for gcc 12. - bookworm/constexpr2.patch: re-enable build fix for gcc 12. - bookworm/bubble-contents.patch: re-enable build fix for gcc 12. . [ Nathan Teodosio ] * Simplify fixes/bindgen.patch so it doesn't need frequent rebasing. . [ Daniel Richard G. ] * d/copyright: Expand list of Files-Excluded: entries. * d/rules: Various updates to get-orig-source rule, including use of grep-dctrl(1) and the LASTCHANGE.committime timestamp. * d/scripts/check-upstream: Avoid issues with inaccurate $(pwd) value and spaces in filenames, and print all errors instead of only the first one. Checksums-Sha1: 0ce35d589546adf5965e5884180bb997bd7b784f 5340008 chromium-common-dbgsym_131.0.6778.139-1~deb12u1_arm64.deb 11293dfd223f13042d8c7d56b8cb3c3b4687e2fa 13536116 chromium-common_131.0.6778.139-1~deb12u1_arm64.deb d406da7e2b28ba37537279ff5d02038514ca4bb8 32549140 chromium-dbgsym_131.0.6778.139-1~deb12u1_arm64.deb 446918ed3fabf941cfcba3b31675e81707f03bfa 6412784 chromium-driver_131.0.6778.139-1~deb12u1_arm64.deb ac55a6e8ca84badf076b415fa5a4c159479c2bab 14340 chromium-sandbox-dbgsym_131.0.6778.139-1~deb12u1_arm64.deb 109b89962b8439028c7d9ede8c0f8ed98e643ca4 98036 chromium-sandbox_131.0.6778.139-1~deb12u1_arm64.deb 605f37ff62f5696e027674a57e255f79eca264f9 27233376 chromium-shell-dbgsym_131.0.6778.139-1~deb12u1_arm64.deb a489c4015e47288e71a385a602eb4c10e9546e94 47218676 chromium-shell_131.0.6778.139-1~deb12u1_arm64.deb a77bcd267ee3673a96a47492d7f65f4ee3878385 24716 chromium_131.0.6778.139-1~deb12u1_arm64-buildd.buildinfo 57aea47c343db078155ad7da41349f564594b233 76629488 chromium_131.0.6778.139-1~deb12u1_arm64.deb Checksums-Sha256: aaaee4731fcd3defb08b78aee8c5144b84e74c6ba4df58cbe269223c9bc66243 5340008 chromium-common-dbgsym_131.0.6778.139-1~deb12u1_arm64.deb c2a26d58c826b3f73f4cb93854661605d0965a50c3df58dcb41168d276399a9c 13536116 chromium-common_131.0.6778.139-1~deb12u1_arm64.deb 1d5035cd68beffedbc341ffa0b31edb3fcc135557fdc49d4a305e33639532523 32549140 chromium-dbgsym_131.0.6778.139-1~deb12u1_arm64.deb 020bb2d800c4adeb8922f1c6370757672847e1bdcb16b0f83d1bbbc5e76f390f 6412784 chromium-driver_131.0.6778.139-1~deb12u1_arm64.deb eb6bff7eb8f2a7682c9383159b61e17f8cae1dbc34669b0d82b44d6599fa2a63 14340 chromium-sandbox-dbgsym_131.0.6778.139-1~deb12u1_arm64.deb 03815e6abea95ac1e3274c3121f42ec7b5f4c921aa3bac126945a01056d01c0a 98036 chromium-sandbox_131.0.6778.139-1~deb12u1_arm64.deb 715dcf6db8fb5aafba78e0bdb2105bc876692393d5cd1bc69129b54c570ccf9a 27233376 chromium-shell-dbgsym_131.0.6778.139-1~deb12u1_arm64.deb 5af5f87c51914412a4486e63e64b659ebcb0f48bfbb7f31fa8ce78135e08bd08 47218676 chromium-shell_131.0.6778.139-1~deb12u1_arm64.deb 3e3eae46d6339e0226dc9dfe172a80cd9788e26db346c26bd0bf85493ad283e8 24716 chromium_131.0.6778.139-1~deb12u1_arm64-buildd.buildinfo 58c1e86754ce71726ba84ca885547929279f5701fde544e7f99d4d999232ee76 76629488 chromium_131.0.6778.139-1~deb12u1_arm64.deb Files: d7e144905642c8f72dc3594c81b0127c 5340008 debug optional chromium-common-dbgsym_131.0.6778.139-1~deb12u1_arm64.deb ee5379efc402c40312d2abac0c71d99a 13536116 web optional chromium-common_131.0.6778.139-1~deb12u1_arm64.deb af1e0cdad281ffdea2a8f3977eb52041 32549140 debug optional chromium-dbgsym_131.0.6778.139-1~deb12u1_arm64.deb f814a0630089ca4486beacd315b70fda 6412784 web optional chromium-driver_131.0.6778.139-1~deb12u1_arm64.deb 72093b4472130e8d3b67ed6abe91235b 14340 debug optional chromium-sandbox-dbgsym_131.0.6778.139-1~deb12u1_arm64.deb a5cd311f3baff92632b02735edf24103 98036 web optional chromium-sandbox_131.0.6778.139-1~deb12u1_arm64.deb ad11e534446d7b061a861a60552a4f8e 27233376 debug optional chromium-shell-dbgsym_131.0.6778.139-1~deb12u1_arm64.deb bce1822e9055b8895befcc63c2511297 47218676 web optional chromium-shell_131.0.6778.139-1~deb12u1_arm64.deb ba8854bc85396bc71e42bcd84372b706 24716 web optional chromium_131.0.6778.139-1~deb12u1_arm64-buildd.buildinfo 79f117bf668dda25c91b054968ed8e50 76629488 web optional chromium_131.0.6778.139-1~deb12u1_arm64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEVM4SKBZumztS8zr3lST9Us03ywsFAmda0d0ACgkQlST9Us03 ywtEKw//SmwIqKv+AF4riGEmTW+aln0tNQQMQj6iDcVnOfeT26YsDJRjKND0uty3 zC42j39YdbkBKCTwbGj5p3sdlG4GzrB6yyXkIXjH8sXIc5ZB84aGUXy+zn9kUg2i aY5qM4PzrNcjcXkOQsQXqsOHqJheNJQB3akHoccz3NE9k4ufehBDuwjy4HJcrAWB 5jGayA6YEIdwK6SGf8xztllSSm6AhXrm72A1WwHdFsWVLTDchgv86nJ0kTBNkP+v jkh2q/7N/+brZrp+O+6A00CFiIN13mb5cW/QgHeeD6lyIYSDoFC9jkKEeZncdtsi uO2nh4tqCrTnGp6GVE17gpamD/25neV4ucHKm0MF9eq19kWrO1jjcYAv6Hr8rz3C nSXiaWcWHQF2q0bw6Vd99+mTMvAOfysLBUQcaOk+O4EODZB9SquDIt5FTdgvr3ir c+kSF1bclYQVZgcG6J+XOmO9mqxGH9mEXlQygxEkB8z5TP+WWOKKFI2V5THPuR7X w3ZCaPFzk+u2E2db461bPHEBirT7+eN+fa8mAG+YQB9d+BTZ/up9A1uVGo7L8dnJ 6K+gqX5Zy8xylH7J4ftnyJPM7hIw52pwXQWnxSMuWDSrLE30C9JJRkRtVj4aqz9J GI6lZBM42VUpc0Uj6ITZ7r09RkYAPIzuOOjnkcTtgS/1YXp4AUo= =d4eR -----END PGP SIGNATURE-----