-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 11 Dec 2024 15:33:53 -0500 Source: chromium Binary: chromium chromium-common chromium-common-dbgsym chromium-dbgsym chromium-driver chromium-sandbox chromium-sandbox-dbgsym chromium-shell chromium-shell-dbgsym Architecture: i386 Version: 131.0.6778.139-1~deb12u1 Distribution: bookworm-security Urgency: high Maintainer: i386 Build Daemon (x86-grnet-01) Changed-By: Andres Salomon Description: chromium - web browser chromium-common - web browser - common resources used by the chromium packages chromium-driver - web browser - WebDriver support chromium-sandbox - web browser - setuid security sandbox for chromium chromium-shell - web browser - minimal shell Changes: chromium (131.0.6778.139-1~deb12u1) bookworm-security; urgency=high . [ Andres Salomon ] * New upstream security release. - CVE-2024-12381: Type Confusion in V8. Reported by Seunghyun Lee (@0x10n). - CVE-2024-12382: Use after free in Translate. Reported by lime(@limeSec_) from TIANGONG Team of Legendsec at QI-ANXIN Group. * (Temporarily?) switch from llvm's libc++ to gcc's libstdc++ to simplify the prior clang-16/19 upgrades. * d/patches: - fixes/bindgen.patch: refresh. - upstream/dawn-strlen.patch: add gcc-specific build fix. - upstream/ink-isfinite.patch: add gcc-specific build fix. - upstream/webrtc-optional.patch: add gcc-specific build fix. - upstream/variant.patch: add gcc-specific build fixes. - upstream/array.patch: add gcc-specific build fix. - fixes/absl-optional.patch: re-introduce clang/gcc build workaround. - upstream/mrc-copy-op.patch: add gcc-specific build fix. - fixes/font-gc-asan.patch: add a better workaround for bad font-gc behavior under libstdc++. This is self-contained and small, unlike the prior reverts of the switch to font garbage collection. - bookworm/constexpr.patch: re-enable (and refresh) build fix specifically for gcc 12. - bookworm/constexpr2.patch: re-enable build fix for gcc 12. - bookworm/bubble-contents.patch: re-enable build fix for gcc 12. . [ Nathan Teodosio ] * Simplify fixes/bindgen.patch so it doesn't need frequent rebasing. . [ Daniel Richard G. ] * d/copyright: Expand list of Files-Excluded: entries. * d/rules: Various updates to get-orig-source rule, including use of grep-dctrl(1) and the LASTCHANGE.committime timestamp. * d/scripts/check-upstream: Avoid issues with inaccurate $(pwd) value and spaces in filenames, and print all errors instead of only the first one. Checksums-Sha1: f941fa9210c348e487cf8255b4cf86d8c77bdcf5 5472712 chromium-common-dbgsym_131.0.6778.139-1~deb12u1_i386.deb a4a1e7d40ae6ee6cb2d118abc1c593c24e60bc5b 10313024 chromium-common_131.0.6778.139-1~deb12u1_i386.deb 46dcc59e5506ef8c3bec6f769f96805592dbf773 33988396 chromium-dbgsym_131.0.6778.139-1~deb12u1_i386.deb 4eb6c2e7dd5c5fabd9d9465bdb8c09c1cb5ed694 7522944 chromium-driver_131.0.6778.139-1~deb12u1_i386.deb ccffc6342301b9800863d3158a8763fa20166c65 14132 chromium-sandbox-dbgsym_131.0.6778.139-1~deb12u1_i386.deb b153a8df2bd9a0d0d7bdb30ac076dc201c7bb60c 98028 chromium-sandbox_131.0.6778.139-1~deb12u1_i386.deb d464850dda810156ea13b5108e62d8f325e904ff 29497260 chromium-shell-dbgsym_131.0.6778.139-1~deb12u1_i386.deb 4053b07512e8db5b30232dd07967f821c3c48a42 55375096 chromium-shell_131.0.6778.139-1~deb12u1_i386.deb a511188f7cab1b9ad36280c44e6f8b43ca262a63 24746 chromium_131.0.6778.139-1~deb12u1_i386-buildd.buildinfo 298c7e2449b3b01a5acf57366b560d2bfc23cbb7 79431188 chromium_131.0.6778.139-1~deb12u1_i386.deb Checksums-Sha256: 10f0c59674a35710cb81a65b8e73f37afacf36f21c9ad18c83f329a71adcd737 5472712 chromium-common-dbgsym_131.0.6778.139-1~deb12u1_i386.deb e87a0e3e60004fccf741aee14dcdcf0e2d9db4ff36e92b3c25e97fb0523238b0 10313024 chromium-common_131.0.6778.139-1~deb12u1_i386.deb 71f100d30cd2e3adf872bf7daa9a54366290c7aee2e4d0a94b058c9df692045f 33988396 chromium-dbgsym_131.0.6778.139-1~deb12u1_i386.deb 635ed7b1e18e1338ffdf5516a8997aca277a31b3634bb7915e43a3856003237e 7522944 chromium-driver_131.0.6778.139-1~deb12u1_i386.deb 0fc1ccba298ccbda567d53e3c258ff2a5872a546adb4fb6c708791a2932886c2 14132 chromium-sandbox-dbgsym_131.0.6778.139-1~deb12u1_i386.deb 9c48965a0730edbc71ffce8bb004d004670c792409f678de8174b8083e6ab811 98028 chromium-sandbox_131.0.6778.139-1~deb12u1_i386.deb d8ee7f5acbe0b645cac824ffbcbc629e4a59fa29a99cf100894f564910a0dbc7 29497260 chromium-shell-dbgsym_131.0.6778.139-1~deb12u1_i386.deb 248257788436ce7a73d0a275775945a392a7ec71122fa8691f298ca0c6cd5974 55375096 chromium-shell_131.0.6778.139-1~deb12u1_i386.deb 824b8980d53dccabae2b32e035706b784fcf603e5552c933949fdf1beff066f6 24746 chromium_131.0.6778.139-1~deb12u1_i386-buildd.buildinfo 03938339bb699dcb398dfa5651daad772ad4fbaf1c519045ca935318a9f6b3c4 79431188 chromium_131.0.6778.139-1~deb12u1_i386.deb Files: 09f83738367094a4415c7704791764ff 5472712 debug optional chromium-common-dbgsym_131.0.6778.139-1~deb12u1_i386.deb cac416568e1ed3dce822a74f45435404 10313024 web optional chromium-common_131.0.6778.139-1~deb12u1_i386.deb 9e3b01993c34ddcbb4780cb39786a4e7 33988396 debug optional chromium-dbgsym_131.0.6778.139-1~deb12u1_i386.deb f775e8924ade9ff4a4958555bef96f41 7522944 web optional chromium-driver_131.0.6778.139-1~deb12u1_i386.deb 9a164f3bae652e1cb671481915555372 14132 debug optional chromium-sandbox-dbgsym_131.0.6778.139-1~deb12u1_i386.deb 005cb0202fa68238555e586d17de666f 98028 web optional chromium-sandbox_131.0.6778.139-1~deb12u1_i386.deb 2aaefdc9e1eb095367303d0d304c1ac4 29497260 debug optional chromium-shell-dbgsym_131.0.6778.139-1~deb12u1_i386.deb 9476c6481551bf65ae1b6ab5745c60ce 55375096 web optional chromium-shell_131.0.6778.139-1~deb12u1_i386.deb 07701b656b0572985a22faa3c99f1bb0 24746 web optional chromium_131.0.6778.139-1~deb12u1_i386-buildd.buildinfo 29405c9c97773a328f5669bd085ea1d5 79431188 web optional chromium_131.0.6778.139-1~deb12u1_i386.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEyTfXx8sBpQ0Lh3cUU9a0/LcaTpMFAmda4ccACgkQU9a0/Lca TpPOhA/+KBkPw3/WqkSC+OwGtRe+8Bzydx3xCTDS77P9rp31AAcR7499V4+t8sKk EiUbk/NZGUSt1QwvFAUh1BSC3HCTK7KyvwaSuQJ3JYqjEvfNQysM/tXrCsrBtDSs aMsacgE2YZaSB7FXIdZqmPb160acYiLi0nzQwZm+35VO0xXt86GaOeiRjefGhsPP P47XcT726bEHgqpoSsvoL3eI1mdG8N0FvMOEUfC1YU0UcDBLUauImjztyaUoBjKs qaaaEUN5UdbqKcwYS3T1Qi8fKG077mV2FOk7BManKijMli4oPsznh3q32jA5w3wS a3eHB/711Z0ZRfOor8NugYfb2exic0fPTNgSizTcfZ0IL8dUJECkW4GDT4QmhAel JaYsiYB1nrDAavYz5zVV+qE1/2AKgetv9zWFXBKt4441FGPt+RT60y/pw6aUYNS6 PzIpnJlEPalKRA9w72ZRUQ6b6lqprdfdePBOCLzOsNfl8qgQvxjxgTF38VW6GCTp kc6/2xYq332BpBJdSQsIb0guQE2rircDUCSXFJMIpBR7no5unySnFUuq8dUuE8aw S05Gs3nrtUFejKwNz2Jqt66U91d9/Q38A6leKa9rZ8igzT4Y88DVgR95vi5lBYyc mC+wr2IQSTyMOhr9BdITrbjeFWhXjmDQJn1y8bXYKhMplCeaods= =tUeT -----END PGP SIGNATURE-----