-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 11 Dec 2024 15:33:53 -0500 Source: chromium Binary: chromium chromium-common chromium-common-dbgsym chromium-dbgsym chromium-driver chromium-sandbox chromium-sandbox-dbgsym chromium-shell chromium-shell-dbgsym Architecture: ppc64el Version: 131.0.6778.139-1~deb12u1 Distribution: bookworm-security Urgency: high Maintainer: ppc64el Build Daemon (ppc64el-osuosl-01) Changed-By: Andres Salomon Description: chromium - web browser chromium-common - web browser - common resources used by the chromium packages chromium-driver - web browser - WebDriver support chromium-sandbox - web browser - setuid security sandbox for chromium chromium-shell - web browser - minimal shell Changes: chromium (131.0.6778.139-1~deb12u1) bookworm-security; urgency=high . [ Andres Salomon ] * New upstream security release. - CVE-2024-12381: Type Confusion in V8. Reported by Seunghyun Lee (@0x10n). - CVE-2024-12382: Use after free in Translate. Reported by lime(@limeSec_) from TIANGONG Team of Legendsec at QI-ANXIN Group. * (Temporarily?) switch from llvm's libc++ to gcc's libstdc++ to simplify the prior clang-16/19 upgrades. * d/patches: - fixes/bindgen.patch: refresh. - upstream/dawn-strlen.patch: add gcc-specific build fix. - upstream/ink-isfinite.patch: add gcc-specific build fix. - upstream/webrtc-optional.patch: add gcc-specific build fix. - upstream/variant.patch: add gcc-specific build fixes. - upstream/array.patch: add gcc-specific build fix. - fixes/absl-optional.patch: re-introduce clang/gcc build workaround. - upstream/mrc-copy-op.patch: add gcc-specific build fix. - fixes/font-gc-asan.patch: add a better workaround for bad font-gc behavior under libstdc++. This is self-contained and small, unlike the prior reverts of the switch to font garbage collection. - bookworm/constexpr.patch: re-enable (and refresh) build fix specifically for gcc 12. - bookworm/constexpr2.patch: re-enable build fix for gcc 12. - bookworm/bubble-contents.patch: re-enable build fix for gcc 12. . [ Nathan Teodosio ] * Simplify fixes/bindgen.patch so it doesn't need frequent rebasing. . [ Daniel Richard G. ] * d/copyright: Expand list of Files-Excluded: entries. * d/rules: Various updates to get-orig-source rule, including use of grep-dctrl(1) and the LASTCHANGE.committime timestamp. * d/scripts/check-upstream: Avoid issues with inaccurate $(pwd) value and spaces in filenames, and print all errors instead of only the first one. Checksums-Sha1: 16c98af46b4641eb66d83da81af3744f8e801899 5122788 chromium-common-dbgsym_131.0.6778.139-1~deb12u1_ppc64el.deb 6360fc0ae4fc393694034db64cc90d1114640d16 14467216 chromium-common_131.0.6778.139-1~deb12u1_ppc64el.deb 51c28462e6cd7221b8642e954e361d36a7e21a77 27282580 chromium-dbgsym_131.0.6778.139-1~deb12u1_ppc64el.deb 5dc1944d6605f04954bd562f4668c433b9dc92bd 6995460 chromium-driver_131.0.6778.139-1~deb12u1_ppc64el.deb dd6b021bdac54d78bc4c2db0d08c11692c8026a1 14240 chromium-sandbox-dbgsym_131.0.6778.139-1~deb12u1_ppc64el.deb d4fdc014bfb34dbb66ab17731c9d54b766defcff 98256 chromium-sandbox_131.0.6778.139-1~deb12u1_ppc64el.deb e661b7a5a241255aed5b4850bfe8823f2e4afba9 22358068 chromium-shell-dbgsym_131.0.6778.139-1~deb12u1_ppc64el.deb 967168c6a05934cab6ce38c2f63a12246d8247b0 50987980 chromium-shell_131.0.6778.139-1~deb12u1_ppc64el.deb e63a65bbd07cde181c68d858fc3369c5325e27ea 24666 chromium_131.0.6778.139-1~deb12u1_ppc64el-buildd.buildinfo 899a9047b25867b6dea611d7ba1b6b0ae2de818b 83206168 chromium_131.0.6778.139-1~deb12u1_ppc64el.deb Checksums-Sha256: 94c02457232d4023ca9e5e58e18fe280c79f76d517cda33a6769683aa22124d5 5122788 chromium-common-dbgsym_131.0.6778.139-1~deb12u1_ppc64el.deb 93d9cddb72557cbbad532cf74532a4d20bc82dc57ef194d3a19ebd473ae4d954 14467216 chromium-common_131.0.6778.139-1~deb12u1_ppc64el.deb 7de7fb0d143d6cdd71cd16f38fba2aca50a566324e2c32d34c003e86ed4ec660 27282580 chromium-dbgsym_131.0.6778.139-1~deb12u1_ppc64el.deb a6e24c193d5526005ac7b3dc6e6c09de81a2ad45f5ed09394999dbc2b14f70c0 6995460 chromium-driver_131.0.6778.139-1~deb12u1_ppc64el.deb d0be128828e380d23f8332540e7e993616040dda852ae4a31f3132ebc8328a53 14240 chromium-sandbox-dbgsym_131.0.6778.139-1~deb12u1_ppc64el.deb 5028a4deb88a53045564f391b40ec7effcdc4a22a88d97e2a71b50062fe1fbee 98256 chromium-sandbox_131.0.6778.139-1~deb12u1_ppc64el.deb 4671217ceb8e770555cb6b830fb878ea143b8d8504c0b3d62cb08b27c1d0ba04 22358068 chromium-shell-dbgsym_131.0.6778.139-1~deb12u1_ppc64el.deb f1c4ab03374f0eff1b5123afa07157364e5917d7981e9e3b4ffeddd283e559cf 50987980 chromium-shell_131.0.6778.139-1~deb12u1_ppc64el.deb cccdcf9dfe6fd95fe70ed154baa16c81f65eda9012d9ea175904b0da8b77de3e 24666 chromium_131.0.6778.139-1~deb12u1_ppc64el-buildd.buildinfo ea5ac05a6655c35470765d990aaa6f84553efed0fbca442b027f3cb009889d6a 83206168 chromium_131.0.6778.139-1~deb12u1_ppc64el.deb Files: 5e7f3a1a0cd8d17e167a99ed2852dbb5 5122788 debug optional chromium-common-dbgsym_131.0.6778.139-1~deb12u1_ppc64el.deb ffc9044eff54b96860a37afa3824d616 14467216 web optional chromium-common_131.0.6778.139-1~deb12u1_ppc64el.deb 5f73f1a2c153d03d9bacfb1bcd0dd000 27282580 debug optional chromium-dbgsym_131.0.6778.139-1~deb12u1_ppc64el.deb cb0611d9d748cc19adaadde1d0bf55d5 6995460 web optional chromium-driver_131.0.6778.139-1~deb12u1_ppc64el.deb cfc02d50a7b63428b5bfd2f6e11b8a05 14240 debug optional chromium-sandbox-dbgsym_131.0.6778.139-1~deb12u1_ppc64el.deb e45ce8ebb574dea9e49e36b11298f586 98256 web optional chromium-sandbox_131.0.6778.139-1~deb12u1_ppc64el.deb f6f76779bdb37f6c553818be4624ac93 22358068 debug optional chromium-shell-dbgsym_131.0.6778.139-1~deb12u1_ppc64el.deb aaccd14e2402157652fff1a2233ca60e 50987980 web optional chromium-shell_131.0.6778.139-1~deb12u1_ppc64el.deb 00bd78b19404fe7008d5574c86593490 24666 web optional chromium_131.0.6778.139-1~deb12u1_ppc64el-buildd.buildinfo 81e5fece6abce33d63a714434a30d71c 83206168 web optional chromium_131.0.6778.139-1~deb12u1_ppc64el.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE5v3ycPFoB5xoBEprvMjydu+xvRMFAmda3IoACgkQvMjydu+x vRPN4w//cVsIQfOsppI14bhabARJYj2JQadfKLjRjYiqCOSFbyCMO3/KX0w6eP2M Et8n7W8ueXK0cV7/IT9/skNRt6EWa1/FzGNkePt+eASJh+Ctv9tzoroBAQx4DbCX n5m9zbNxfGILjtxmqL4KHm9LpYgQ2gZhpxabkzJQ1xmZP17Q1LsjyyA6ZHYvzGvK hALovQX8PrsmcZqX4/0FBiU144Ckk+egz1peK56FTtlQYGaUTPiBKUuirVxnDyH7 yD0DOpzVuAv7pHGU2GHnWs8NZo0DNhCepLdn0jSw01Z5dgu1mHjDJFgs+y4ekY4A L6hc3Cc5+A/l6eG/bSlJSc3RG8OIuKLU4wgkwEPK6SWd1Zexf+6H+PeLX9MEqscV 9l5vgBHyFRL9P1tIOik18Iw9I9fbFIdNNPSUYZWZVDrTrMoPf/RuUhOk7Ie1fKN+ CfgoYXFAAiDJrbtUkDMQ7+kn9sWBtAkB3QSP9FOvSTks4cbpj2UeQxpo7/YdIZ1j Y3HQCyXuWEfLGPLaSqMDi+EYgnMEV1bGuQaGRBy/V32IPsLXycOzEUylidef3YXc q0qbiRjENtNXZsKjPdTKNqyoJx5mfim5IJFDHpvbMO9vIEvIt4E+ZjfxpOoXfpAU griMTi3S0l+dNmxG+sTtXMnCBL1b5m9uX6BS79Tk28lEjDZw6lQ= =Wyq0 -----END PGP SIGNATURE-----