-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 10 Jun 2025 15:08:42 -0400 Source: chromium Binary: chromium chromium-common chromium-common-dbgsym chromium-dbgsym chromium-driver chromium-headless-shell chromium-headless-shell-dbgsym chromium-sandbox chromium-sandbox-dbgsym chromium-shell chromium-shell-dbgsym Architecture: i386 Version: 137.0.7151.103-1~deb12u1 Distribution: bookworm-security Urgency: high Maintainer: all / amd64 / i386 Build Daemon (x86-grnet-03) Changed-By: Andres Salomon Description: chromium - web browser chromium-common - web browser - common resources used by the chromium packages chromium-driver - web browser - WebDriver support chromium-headless-shell - web browser - old headless shell chromium-sandbox - web browser - setuid security sandbox for chromium chromium-shell - web browser - minimal shell Changes: chromium (137.0.7151.103-1~deb12u1) bookworm-security; urgency=high . * New upstream security release. - CVE-2025-5958: Use after free in Media. Reported by Huang Xilin of Ant Group Light-Year Security Lab. - CVE-2025-5959: Type Confusion in V8. Reported by Seunghyun Lee as part of TyphoonPWN 2025. * Add build-dep on libc++-19-dev and switch to building statically against clang's libc++ (instead of gcc's libstdc++). * d/patches: - fixes/absl-optional.patch: drop, only needed for libstdc++. - fixes/font-gc-asan.patch: drop, only needed for libstdc++. - fixes/stdatomic.patch: drop, only needed for libstdc++. - fixes/make-pair.patch: drop, only needed for libstdc++. - bookworm/constflatset.patch: drop, only needed for libstdc++. - bookworm/constexpr2.patch: drop, only needed for libstdc++. - bookworm/constexpr3.patch: drop, only needed for libstdc++. - bookworm/foreach.patch: add patch from bookworm branch to fix clang-19 build failure. Checksums-Sha1: 8e7692f1c06a31a07dfef1ad205954436f927e7f 5048684 chromium-common-dbgsym_137.0.7151.103-1~deb12u1_i386.deb 3daf42a302fabaf4cd18aa7e5f18f1c6690f2f3e 22330224 chromium-common_137.0.7151.103-1~deb12u1_i386.deb b53f5043264d1f15304f7cf0e10382fb74313bf5 33195048 chromium-dbgsym_137.0.7151.103-1~deb12u1_i386.deb c45210c71f94626a552411da3078926734e71afe 8137020 chromium-driver_137.0.7151.103-1~deb12u1_i386.deb a10d982a466de09ba89408f19be0927e0d8c2f66 27694784 chromium-headless-shell-dbgsym_137.0.7151.103-1~deb12u1_i386.deb dca790f39d3c006f1fbd3fa02e89d5976041d90f 55062896 chromium-headless-shell_137.0.7151.103-1~deb12u1_i386.deb 60d5e8311b167c37540591181224e140d2042d40 18084 chromium-sandbox-dbgsym_137.0.7151.103-1~deb12u1_i386.deb 1e554b0757006f5f69d2ec2b9b1eae35e12b28a3 104376 chromium-sandbox_137.0.7151.103-1~deb12u1_i386.deb 01d58ae0c69df67f0339c17c9e1fe0bd0d6b90a5 28052192 chromium-shell-dbgsym_137.0.7151.103-1~deb12u1_i386.deb 04ff7dc8a19c6fffd7ffa24905154ed24b2cdb90 56898304 chromium-shell_137.0.7151.103-1~deb12u1_i386.deb a19f7c622bbe40752f1c8dd5448890adf48fa6e7 30233 chromium_137.0.7151.103-1~deb12u1_i386-buildd.buildinfo e5d414ea7d568cdeee646895a90b87725f59c82e 70843104 chromium_137.0.7151.103-1~deb12u1_i386.deb Checksums-Sha256: 69a35479a2bb25cd0c384a49f4654b10c78bc8b157feb7330206c013ee1f0ac7 5048684 chromium-common-dbgsym_137.0.7151.103-1~deb12u1_i386.deb ab1c9613e9c9d1dcc5f0bb631e2535db55233813c75d61ee536de74b059bd889 22330224 chromium-common_137.0.7151.103-1~deb12u1_i386.deb d64d03c33253c162b41389ba72949f19c804dd31230699f859070b09c8dc5ef8 33195048 chromium-dbgsym_137.0.7151.103-1~deb12u1_i386.deb b5c04c13f3963476e4a643f588a6c6afc634db6128cca3f20ce7d6b2361d8732 8137020 chromium-driver_137.0.7151.103-1~deb12u1_i386.deb 5bad9deb3de35079f5fc5e1622fea3ad0624302724d54a394f3e8a49bb5edb5a 27694784 chromium-headless-shell-dbgsym_137.0.7151.103-1~deb12u1_i386.deb 926bdae46609765cd3285d8b2299617b84309d68ceb0d6ab19f47e1b922dc150 55062896 chromium-headless-shell_137.0.7151.103-1~deb12u1_i386.deb beb7b0959825b11ab0c151cd03e79c870a459f023224be9601a22a1be12178a3 18084 chromium-sandbox-dbgsym_137.0.7151.103-1~deb12u1_i386.deb be0f43c0d23594654ab234295c0132d77cdc75283c6918d91a84659fc6fee9cd 104376 chromium-sandbox_137.0.7151.103-1~deb12u1_i386.deb ec2f1bcb81a0402e934bc50c9dba40ce3c2d6869e133fb8d5191a749d73cc5c5 28052192 chromium-shell-dbgsym_137.0.7151.103-1~deb12u1_i386.deb 444ba70f472bc7c755e5264fabd239b85485bfbd7326f2caa38cd0450cafca86 56898304 chromium-shell_137.0.7151.103-1~deb12u1_i386.deb d02cd3362d9d2e28bf1b8ab0f0b4b293fc99837ce66810637cdab9061ab1ef09 30233 chromium_137.0.7151.103-1~deb12u1_i386-buildd.buildinfo 9db20ebe02a12c0eb15297c087c0c77ebd5421aa2982c2848ddea76d24d971ef 70843104 chromium_137.0.7151.103-1~deb12u1_i386.deb Files: 48598b7b8373012469ac062f331db190 5048684 debug optional chromium-common-dbgsym_137.0.7151.103-1~deb12u1_i386.deb 805a88a3ecd22150fd257a11d2401f61 22330224 web optional chromium-common_137.0.7151.103-1~deb12u1_i386.deb 6782f7a2d52ae635bef053b373455372 33195048 debug optional chromium-dbgsym_137.0.7151.103-1~deb12u1_i386.deb e8372e68b4888fa961071cc4a3b98d3b 8137020 web optional chromium-driver_137.0.7151.103-1~deb12u1_i386.deb 605bad6dc62b8cedf0ed5b728fa4fecb 27694784 debug optional chromium-headless-shell-dbgsym_137.0.7151.103-1~deb12u1_i386.deb af0b7c3e7c9411fe79a461b1d3eaedad 55062896 web optional chromium-headless-shell_137.0.7151.103-1~deb12u1_i386.deb 0adb4fb5cd8dfd6909747c9d5626e6b8 18084 debug optional chromium-sandbox-dbgsym_137.0.7151.103-1~deb12u1_i386.deb af205f787a3511b2bd27646b94447c2a 104376 web optional chromium-sandbox_137.0.7151.103-1~deb12u1_i386.deb 5ad998ff8ac9244174377465172f6a87 28052192 debug optional chromium-shell-dbgsym_137.0.7151.103-1~deb12u1_i386.deb 3c3bc5b1f95c56c6c4c272ccfe9071cf 56898304 web optional chromium-shell_137.0.7151.103-1~deb12u1_i386.deb c837f04fe6f6a6fba1d25b7f58ccbcb2 30233 web optional chromium_137.0.7151.103-1~deb12u1_i386-buildd.buildinfo ec7b6ed8fbc672dce890d20c7bbd9565 70843104 web optional chromium_137.0.7151.103-1~deb12u1_i386.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEHqtYLkdKRyCY94K8fUw6/tXbAmMFAmhKaggACgkQfUw6/tXb AmM5xA/9EvSsDuaSzjfbXDz04oXgFr8vw8yFcVW1Ezmq6voM0NFeEa3wovyqKQma gFb3EUDLJhE7a33y10moBW2YpHHfnYgoTH4p44okl9TjuNmSgGtRAXgtTmmdlt3v CM/OU1qUUoIrGQA4SCzlqk4JP5cUXVEOcHy2ikx4Eiy5/y739KvJNrAt8QXdJYKo Onx2Cbl206X5docwlC7DeE/C9WqbfV2RAl7PlOVCVQuNo8wdoOkJs6W2L14G3jm4 dL4itbeCkMa/hEg7K6F7Oy0doJv1f1MTSxmYD1vb0d6/GBx1HBxJLA++terSDt0h XWWSyF1R+Y5aiAYjtQWZO3ZyB96pW9pPr33/e+vLR3HkCZyYyed5QRisDHj0YjKs wY5axLBv1shUpI8WB5KpZ9Z/Jkl8h6gxQBjg3OQwZeht5ZwgU3sevsMUlhsjkdAk 26cfcyiPVFbhIjTVCJsdHyvjYOr9SniEFGSZNPHES9h6NvK/idFDd4zhVwPJaFJR E6+mFYwHkwlRsp/JLJYR6RL+wVDlBMOWJc/1fSLDTOgZovdJ+TV5FnovESPQh1Mj Mow4BQ4qZ7I9bhVd2ZwTW1C9YknFQHNQhfAqa9GLKO9iUXK+VMD85m2jd0zLn8jH 97+pimsG8Srj+z3KqNkqOmdySNFbuJ/AArhGF4z0NwKXkLE6O4s= =5Xmh -----END PGP SIGNATURE-----