-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Thu, 21 Nov 2024 16:12:03 -0500 Source: chromium Binary: chromium chromium-common chromium-common-dbgsym chromium-dbgsym chromium-driver chromium-sandbox chromium-sandbox-dbgsym chromium-shell chromium-shell-dbgsym Architecture: i386 Version: 131.0.6778.85-1~deb12u1 Distribution: bookworm-security Urgency: high Maintainer: amd64 / i386 Build Daemon (x86-ubc-02) Changed-By: Andres Salomon Description: chromium - web browser chromium-common - web browser - common resources used by the chromium packages chromium-driver - web browser - WebDriver support chromium-sandbox - web browser - setuid security sandbox for chromium chromium-shell - web browser - minimal shell Changes: chromium (131.0.6778.85-1~deb12u1) bookworm-security; urgency=high . [ Andres Salomon ] * New upstream stable release. - CVE-2024-11110: Inappropriate implementation in Blink. Reported by Vsevolod Kokorin (Slonser) of Solidlab. - CVE-2024-11111: Inappropriate implementation in Autofill. Reported by Narendra Bhati, Suma Soft Pvt. Ltd - Pune (India). - CVE-2024-11112: Use after free in Media. Reported by Nan Wang(@eternalsakura13) and Zhenghang Xiao(@Kipreyyy) of 360 Vulnerability Research Institute. - CVE-2024-11113: Use after free in Accessibility. Reported by Weipeng Jiang (@Krace) of VRI. - CVE-2024-11114: Inappropriate implementation in Views. Reported by Micky. - CVE-2024-11115: Insufficient policy enforcement in Navigation. Reported by mastersplinter. - CVE-2024-11116: Inappropriate implementation in Paint. Reported by Thomas Orlita. - CVE-2024-11117: Inappropriate implementation in FileSystem. Reported by Ameen Basha M K. - CVE-2024-11395: Type Confusion in V8. Reported by Anonymous. * d/patches: - upstream/wayland-gbm-pixmap.patch: drop, merged upstream. - disable/catapult.patch: refresh. - fixes/bindgen.patch: refresh. - fixes/freetype.patch: add new patch to fix missing enable_freetype arg declaration. - fixes/updater-test.patch: add simple build fix for deleted third_party/updater/. - upstream/stack-header.patch: drop, merged upstream. - bookworm/clang16.patch: refresh. - bookworm/bubble-contents.patch: refresh. - bookworm/constexpr.patch: refresh. - bookworm/gn-absl.patch: add a few more places where libs needed to be made visible. - bookworm/gn-funcs.patch: add another deletion of newer gn features. - bookworm/constexpr-assert.patch: add patch to work around more clang-16 constexpr bugs; this time a fun one with branching optimizations. Whee! . [ Timothy Pearson ] * d/patches/ppc64le: - workarounds/HACK-debian-clang-disable-pa-musttail.patch: Work around additional upstream musttail definitions - workarounds/HACK-debian-clang-disable-base-musttail.patch: Refresh for upstream changes - third_party/0002-third_party-libvpx-Remove-bad-ppc64-config.patch: Refresh for upstream changes Checksums-Sha1: 24d3cc02ba9fdd6aeb294b9e9d9d073709b2593b 5465692 chromium-common-dbgsym_131.0.6778.85-1~deb12u1_i386.deb 5ea356aaa9a91f0b16b1dcefd2f0cc3203f553a1 10329416 chromium-common_131.0.6778.85-1~deb12u1_i386.deb 25a88b6eae05ec0f287e1ea9fc36648f53659fe6 33729964 chromium-dbgsym_131.0.6778.85-1~deb12u1_i386.deb 8161192268e6f63dc16975d95ae1a84da1900244 7405076 chromium-driver_131.0.6778.85-1~deb12u1_i386.deb 8446dccf65866a1e95df893c20e5e5b5115fb3da 14004 chromium-sandbox-dbgsym_131.0.6778.85-1~deb12u1_i386.deb 1a901ebd8ab3905daf5d835b7dda32f105294b82 97424 chromium-sandbox_131.0.6778.85-1~deb12u1_i386.deb ee92ee13db8d790c9783b9d7ac2f128366cd3112 29241416 chromium-shell-dbgsym_131.0.6778.85-1~deb12u1_i386.deb 3ec5ed305dec5fd46529a116e84f95e4bea9b8d8 54895824 chromium-shell_131.0.6778.85-1~deb12u1_i386.deb 65897f146a4804b34a9550013027d1b41976d88b 24916 chromium_131.0.6778.85-1~deb12u1_i386-buildd.buildinfo 393da8dfdb861bd2576d9db125a394305dcc635a 78505256 chromium_131.0.6778.85-1~deb12u1_i386.deb Checksums-Sha256: 5755614b930ad39fe5989d82b00df8bf57db01747f8fcca82e338f9352ceec02 5465692 chromium-common-dbgsym_131.0.6778.85-1~deb12u1_i386.deb 6470f7cfd13992c19c9ae547bcf9d3c56e158745453c3531f2fe3c3326a789b8 10329416 chromium-common_131.0.6778.85-1~deb12u1_i386.deb 94c6f4908d8104ee094b129ac10ff0faaef5e3c3df6aa6740cac14b8b592b6d7 33729964 chromium-dbgsym_131.0.6778.85-1~deb12u1_i386.deb 02bcb9de4e22bb5952b4a26a11bfae783a4b87948068e3ccf95bbd7051733ab8 7405076 chromium-driver_131.0.6778.85-1~deb12u1_i386.deb 0107a09ff426796311a18ace21d291203f2b1cfdccf99cd879177b7dc519f0af 14004 chromium-sandbox-dbgsym_131.0.6778.85-1~deb12u1_i386.deb 7d969157b75b199b198931986c4ecc94efb93c14bffaf3f21168e45149716f90 97424 chromium-sandbox_131.0.6778.85-1~deb12u1_i386.deb 84979e3a2eb2caf3af529cfa25b5f88689ccd8cb352d51a2d848616adc82fee6 29241416 chromium-shell-dbgsym_131.0.6778.85-1~deb12u1_i386.deb c22268b4a80710d12c7ab4b03654a16610b53ef486a9f52e0e6cf124961f84dc 54895824 chromium-shell_131.0.6778.85-1~deb12u1_i386.deb 521d9530751791243add1a2a345ae613d32d142d1fa128799bd1f3ae7aa59f1f 24916 chromium_131.0.6778.85-1~deb12u1_i386-buildd.buildinfo 7c56522840f5a673d971145d5c674b9a4645c2b6598f5034fac9e5c85facae3f 78505256 chromium_131.0.6778.85-1~deb12u1_i386.deb Files: f57ee2c6ab4fc6f88fdbc7f75b3b161e 5465692 debug optional chromium-common-dbgsym_131.0.6778.85-1~deb12u1_i386.deb 92e5f3895a785795ce37b4d96bc8e328 10329416 web optional chromium-common_131.0.6778.85-1~deb12u1_i386.deb 8047c62fc4c6383057d1d36586a9fb57 33729964 debug optional chromium-dbgsym_131.0.6778.85-1~deb12u1_i386.deb 9886259ce44b27394b0ad2174d77eb0d 7405076 web optional chromium-driver_131.0.6778.85-1~deb12u1_i386.deb b125b537015cfed779e23350b780771a 14004 debug optional chromium-sandbox-dbgsym_131.0.6778.85-1~deb12u1_i386.deb a6442163b96b97a12fc509d6c94a3156 97424 web optional chromium-sandbox_131.0.6778.85-1~deb12u1_i386.deb 7fe2cb81bc30bb07b6f9356f258941a7 29241416 debug optional chromium-shell-dbgsym_131.0.6778.85-1~deb12u1_i386.deb fde59f7909bac20171ae0a6c1c666cb7 54895824 web optional chromium-shell_131.0.6778.85-1~deb12u1_i386.deb f6af484014920f4c493bdc3c35432f9c 24916 web optional chromium_131.0.6778.85-1~deb12u1_i386-buildd.buildinfo 1a3184a32be6165bc3e0c57cc02f7fbd 78505256 web optional chromium_131.0.6778.85-1~deb12u1_i386.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEGBeuno8wiDXCewDuqqLQG5ksqMMFAmdBdzwACgkQqqLQG5ks qMMm0g/9Em3enIwOUysewSuZJqwuAhVAGzAN4fxSjBL0g+1KocaAsb9xVcwI5oyV y3H0qa4C7fBUwhdPooDaBGVWARn3ocfZhMD4OTttO/njFLXQkbk8QOUO88YukU5z kr17+TIATU+rORTY4mVq9Pnn+BvDythn3T1dr/TCf0ISFdM5iBpa8zYe9jqdOw8r muwFggT6/ezqyoUU7/iz9kfe1E053839U6aDB6b13rM3wVeG9GmZFbEEhxTJO/bx SIv217cJdl4UBUk4xfevoIi7YLbUPusOdW3lRXzV8qDae+wCQQgg5d6fpVQgwgGO 1QqvnsSkvs5/Pi5aQZJn6HblniID6U3wIVBAHa4I4miHoOD1meY/Tu/AFtz4Hwr/ nlnMq3nHome43fo1oLmnhA6ILG+1vzsFdOG3FWiFXBzXNiSdbh/U7c46x/BIWihr ShWUeWbNgZuYmehaSvrae5Am5wYr1fikbf7AYmUDNjq1o6NfV9pR7K3n2n4CB0WO e33C3sog3IcBUva3QQ7qG6ZS7YsTogXbOsN4PYb5H3Gn6mIHiutSI7g5Mt2fKZzj Gy26gW9s2xKIFFoyNgHbKUj+zMAM7WgqTnK9mcCrYdc4HoJfKR32f2NH2TE19XSZ a66ep3gwNeKY3h/Olj6I4kC8i2FpWi69DjmVbaC0qN3zX6n41KU= =1nsN -----END PGP SIGNATURE-----