-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 10 Jun 2025 15:08:42 -0400 Source: chromium Binary: chromium chromium-common chromium-common-dbgsym chromium-dbgsym chromium-driver chromium-headless-shell chromium-headless-shell-dbgsym chromium-sandbox chromium-sandbox-dbgsym chromium-shell chromium-shell-dbgsym Architecture: amd64 Version: 137.0.7151.103-1~deb12u1 Distribution: bookworm-security Urgency: high Maintainer: amd64 / i386 Build Daemon (x86-ubc-01) Changed-By: Andres Salomon Description: chromium - web browser chromium-common - web browser - common resources used by the chromium packages chromium-driver - web browser - WebDriver support chromium-headless-shell - web browser - old headless shell chromium-sandbox - web browser - setuid security sandbox for chromium chromium-shell - web browser - minimal shell Changes: chromium (137.0.7151.103-1~deb12u1) bookworm-security; urgency=high . * New upstream security release. - CVE-2025-5958: Use after free in Media. Reported by Huang Xilin of Ant Group Light-Year Security Lab. - CVE-2025-5959: Type Confusion in V8. Reported by Seunghyun Lee as part of TyphoonPWN 2025. * Add build-dep on libc++-19-dev and switch to building statically against clang's libc++ (instead of gcc's libstdc++). * d/patches: - fixes/absl-optional.patch: drop, only needed for libstdc++. - fixes/font-gc-asan.patch: drop, only needed for libstdc++. - fixes/stdatomic.patch: drop, only needed for libstdc++. - fixes/make-pair.patch: drop, only needed for libstdc++. - bookworm/constflatset.patch: drop, only needed for libstdc++. - bookworm/constexpr2.patch: drop, only needed for libstdc++. - bookworm/constexpr3.patch: drop, only needed for libstdc++. - bookworm/foreach.patch: add patch from bookworm branch to fix clang-19 build failure. Checksums-Sha1: 0487595998acee34127c48d8c4a809063e1e5e30 4985632 chromium-common-dbgsym_137.0.7151.103-1~deb12u1_amd64.deb f8cc70b99ae784f5a09e1147f40fb19529eb3ca5 22258108 chromium-common_137.0.7151.103-1~deb12u1_amd64.deb 5c8bba385f9998ddfb640af2cff42df514e526a5 30669044 chromium-dbgsym_137.0.7151.103-1~deb12u1_amd64.deb af50baac5ed99142cd6946ded91358dca0c7f7d9 7784876 chromium-driver_137.0.7151.103-1~deb12u1_amd64.deb d7917f7e92b21bf092a5c817310485fcecfed8c6 26247568 chromium-headless-shell-dbgsym_137.0.7151.103-1~deb12u1_amd64.deb 98cb1dea6a2086cebb652bfcfdd9cb650ff74934 59265196 chromium-headless-shell_137.0.7151.103-1~deb12u1_amd64.deb da38d8b62ecca406a54d1f17cd2c341caf64d76e 18744 chromium-sandbox-dbgsym_137.0.7151.103-1~deb12u1_amd64.deb 3d2de7405a0daf1c1c46fc8afe42626f0a8e07af 104488 chromium-sandbox_137.0.7151.103-1~deb12u1_amd64.deb 729551c00ae13587a1760ef55dcc70eb06c6b364 25576288 chromium-shell-dbgsym_137.0.7151.103-1~deb12u1_amd64.deb ca980585d54d9d635b3525e3148f8bef0e8d2108 55086736 chromium-shell_137.0.7151.103-1~deb12u1_amd64.deb d60ea3e20e6a942d5f622c30ce2acfd59bcb85a6 30251 chromium_137.0.7151.103-1~deb12u1_amd64-buildd.buildinfo d2688e96b8fbe0c430c95a7c0e31efb72fb7df33 78600444 chromium_137.0.7151.103-1~deb12u1_amd64.deb Checksums-Sha256: ab0a20c0131a48f7f288ed7f66d808fe94ffac39f95c3c3f3644715cee0e5dc0 4985632 chromium-common-dbgsym_137.0.7151.103-1~deb12u1_amd64.deb 00553c70a0441a66a126f18a48cfd3b4efffeb6dedc94cdc0617a43a7fdf8b92 22258108 chromium-common_137.0.7151.103-1~deb12u1_amd64.deb 7bfefdf0b199e63ed3c12283edda69947a212118847f15c5833ad9eb16e00353 30669044 chromium-dbgsym_137.0.7151.103-1~deb12u1_amd64.deb ce19a9931b490c97fcf7296c2168660d2cbc4779e57340d4e5da4a894c00bc76 7784876 chromium-driver_137.0.7151.103-1~deb12u1_amd64.deb 5f86af9217269738cc45ba4e54e23f8c247789975a8eb14a9396e4f79f414285 26247568 chromium-headless-shell-dbgsym_137.0.7151.103-1~deb12u1_amd64.deb 6da2bc20d4ddbc56c527e3911be35a726d13abbe502c5516dd728435e59839e7 59265196 chromium-headless-shell_137.0.7151.103-1~deb12u1_amd64.deb 5cb3b24077ad37decf9823b2fec5b7c4cc29447413cec743433f7ca555dbb1a4 18744 chromium-sandbox-dbgsym_137.0.7151.103-1~deb12u1_amd64.deb 49bc2c3501c8f26cde10bb197e9d7f154405bcffc37f174dc31b5f13464affbb 104488 chromium-sandbox_137.0.7151.103-1~deb12u1_amd64.deb 737876f7e6a205224d37b5dde8a18ed0c201cfd2709954569c0b454f1c034b5f 25576288 chromium-shell-dbgsym_137.0.7151.103-1~deb12u1_amd64.deb 5949eb6157e0e07f24811246accc9e8f97aaa54a78e7d9edf70282bfedcac2b2 55086736 chromium-shell_137.0.7151.103-1~deb12u1_amd64.deb cf97aa0d04f22f1a4b182636fe4252ab652233f5b7d95bbeefdd3181d2550d69 30251 chromium_137.0.7151.103-1~deb12u1_amd64-buildd.buildinfo 2a1781972d9b42a7450350588510c7354d0cec156324556187e4cb90a96a9998 78600444 chromium_137.0.7151.103-1~deb12u1_amd64.deb Files: 4cdcf9de06a2fb3e65dc1141561c0bea 4985632 debug optional chromium-common-dbgsym_137.0.7151.103-1~deb12u1_amd64.deb f246b2ff3783e072bd62edf94755568a 22258108 web optional chromium-common_137.0.7151.103-1~deb12u1_amd64.deb 3d8caa310b027a1003aa022c340c4743 30669044 debug optional chromium-dbgsym_137.0.7151.103-1~deb12u1_amd64.deb 6c4f20d4dfe5f21dd23caef483c06cec 7784876 web optional chromium-driver_137.0.7151.103-1~deb12u1_amd64.deb d5803c7f88cbc6897d07d0ff34ed8bd8 26247568 debug optional chromium-headless-shell-dbgsym_137.0.7151.103-1~deb12u1_amd64.deb 77759551952327715d5194e73072c258 59265196 web optional chromium-headless-shell_137.0.7151.103-1~deb12u1_amd64.deb 28e17655e70db21edf5362b36b23a186 18744 debug optional chromium-sandbox-dbgsym_137.0.7151.103-1~deb12u1_amd64.deb bb2114522c2fea398427f3a34410eeb1 104488 web optional chromium-sandbox_137.0.7151.103-1~deb12u1_amd64.deb 81d724be382eabecb7752fd0cf603112 25576288 debug optional chromium-shell-dbgsym_137.0.7151.103-1~deb12u1_amd64.deb 3ec5fca7ebc5f05fbc603ab93ed1d260 55086736 web optional chromium-shell_137.0.7151.103-1~deb12u1_amd64.deb a1c9beccc59f4fb483db55ac160888f5 30251 web optional chromium_137.0.7151.103-1~deb12u1_amd64-buildd.buildinfo 79c84952ec1518ebc56fe45b2fd55806 78600444 web optional chromium_137.0.7151.103-1~deb12u1_amd64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEnw0rdzqckKx6dwRTEbCLukZn24oFAmhKIBgACgkQEbCLukZn 24p7DA/+Jb0bPk58xKFrXOE/+7KFcai3G8Yq+L+jnvjeHSNbj71FK0XPg5EE0Y4H xGF0HqUyhtQ8YYHHiiHOlHnm/Ssm0TtY6Vr6gQ4ebVhWdCp2e+Y+IEta7qbS38TK 7xK/NhMwq41NH+vpZLYPNTGD+glpB9wW2NEfgFhCYCgO9uBCE0dTCDM9j/0xiMRJ iym59XzB66OHM0PPiTEujCHyRlaTLMTb0FjjOu2ZH48iLrpK2UJMqUfPVnpyYW0A +lwHcibx2OeUFlpGbrH5ab7c2zw+af7ulq57F7mc4l4an2LPCNKHtsglUjbJOBjK u2db6ng4OrFl/YNgLbk96uLSxi3n6wZSqjEroUXKhXK/mOAMl7pbd5WC8h2vCIuK M6zOO5/2Wpun5xrBwTm2sP/M/jwL2+lCxBpRxbOcogttkaqH5ALcS9VTQnu5Cm42 EmYNZwkyAgZsdnRpBc+lWaWx/ZgObvoEMZSvkg9k8k1OitwI8mroSHApLRz6C14Q SrKp9h6PosWQ+vtPiP0Q8gv3w53wIHkLruQqU9T5RWrVUbnTbbelsgOBgOn4Vm8k l2uV/jGPejO8XPyLdIg7gYYFZWnRb9Oal/EjVvSbW7zpx+YgGXgEiHdqXHGgNZTl mOXAxYnl8E03U4DX5cxEH1M1jDk5xkdwgjYdY27MSDG4fRpEd+o= =wEb6 -----END PGP SIGNATURE-----