-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Thu, 21 Nov 2024 16:12:03 -0500 Source: chromium Binary: chromium chromium-common chromium-common-dbgsym chromium-dbgsym chromium-driver chromium-sandbox chromium-sandbox-dbgsym chromium-shell chromium-shell-dbgsym Architecture: arm64 Version: 131.0.6778.85-1~deb12u1 Distribution: bookworm-security Urgency: high Maintainer: arm Build Daemon (arm-conova-03) Changed-By: Andres Salomon Description: chromium - web browser chromium-common - web browser - common resources used by the chromium packages chromium-driver - web browser - WebDriver support chromium-sandbox - web browser - setuid security sandbox for chromium chromium-shell - web browser - minimal shell Changes: chromium (131.0.6778.85-1~deb12u1) bookworm-security; urgency=high . [ Andres Salomon ] * New upstream stable release. - CVE-2024-11110: Inappropriate implementation in Blink. Reported by Vsevolod Kokorin (Slonser) of Solidlab. - CVE-2024-11111: Inappropriate implementation in Autofill. Reported by Narendra Bhati, Suma Soft Pvt. Ltd - Pune (India). - CVE-2024-11112: Use after free in Media. Reported by Nan Wang(@eternalsakura13) and Zhenghang Xiao(@Kipreyyy) of 360 Vulnerability Research Institute. - CVE-2024-11113: Use after free in Accessibility. Reported by Weipeng Jiang (@Krace) of VRI. - CVE-2024-11114: Inappropriate implementation in Views. Reported by Micky. - CVE-2024-11115: Insufficient policy enforcement in Navigation. Reported by mastersplinter. - CVE-2024-11116: Inappropriate implementation in Paint. Reported by Thomas Orlita. - CVE-2024-11117: Inappropriate implementation in FileSystem. Reported by Ameen Basha M K. - CVE-2024-11395: Type Confusion in V8. Reported by Anonymous. * d/patches: - upstream/wayland-gbm-pixmap.patch: drop, merged upstream. - disable/catapult.patch: refresh. - fixes/bindgen.patch: refresh. - fixes/freetype.patch: add new patch to fix missing enable_freetype arg declaration. - fixes/updater-test.patch: add simple build fix for deleted third_party/updater/. - upstream/stack-header.patch: drop, merged upstream. - bookworm/clang16.patch: refresh. - bookworm/bubble-contents.patch: refresh. - bookworm/constexpr.patch: refresh. - bookworm/gn-absl.patch: add a few more places where libs needed to be made visible. - bookworm/gn-funcs.patch: add another deletion of newer gn features. - bookworm/constexpr-assert.patch: add patch to work around more clang-16 constexpr bugs; this time a fun one with branching optimizations. Whee! . [ Timothy Pearson ] * d/patches/ppc64le: - workarounds/HACK-debian-clang-disable-pa-musttail.patch: Work around additional upstream musttail definitions - workarounds/HACK-debian-clang-disable-base-musttail.patch: Refresh for upstream changes - third_party/0002-third_party-libvpx-Remove-bad-ppc64-config.patch: Refresh for upstream changes Checksums-Sha1: 8694bf2389861fe91948ab5c4106a4456f9b49da 5506332 chromium-common-dbgsym_131.0.6778.85-1~deb12u1_arm64.deb 678e7abd4ccf53e339e6033fac40575b071ae79d 13508972 chromium-common_131.0.6778.85-1~deb12u1_arm64.deb 6333a3fd79f108fef0361ed992085d096811afb6 33352980 chromium-dbgsym_131.0.6778.85-1~deb12u1_arm64.deb 7c172f2a8cc72aac1ac2c49fb8c60be1e81aca88 6356912 chromium-driver_131.0.6778.85-1~deb12u1_arm64.deb ce4081e874a1361aa9cbf417757bf1d6e79741a3 14112 chromium-sandbox-dbgsym_131.0.6778.85-1~deb12u1_arm64.deb 087b12b300e5572dbde449605f2562ec774f9d1a 97432 chromium-sandbox_131.0.6778.85-1~deb12u1_arm64.deb 3c58b809a0e032f3aed96f21ba80db028e9ecf64 27859260 chromium-shell-dbgsym_131.0.6778.85-1~deb12u1_arm64.deb 172dd46070d734e3bdb5468db1572666e91769de 46770060 chromium-shell_131.0.6778.85-1~deb12u1_arm64.deb 733bdaa65bd72f74c68dff1bbac776cd85ba2a45 24902 chromium_131.0.6778.85-1~deb12u1_arm64-buildd.buildinfo 970b662f136381ea3b944a9222cdca9688cdc298 75904364 chromium_131.0.6778.85-1~deb12u1_arm64.deb Checksums-Sha256: f1ad9e1c6dcd20218848ee9e35aea872829855df2db205f4167bb137be5ca224 5506332 chromium-common-dbgsym_131.0.6778.85-1~deb12u1_arm64.deb 2c0822f1664de1940ff4c0bd6a0f6225fdeac422753ac57943a68711d783cca6 13508972 chromium-common_131.0.6778.85-1~deb12u1_arm64.deb 934e5295e565005271ee36e38d4a4edc73b6e44f3286b41d025932f8dd59f620 33352980 chromium-dbgsym_131.0.6778.85-1~deb12u1_arm64.deb 3fee92c9f08b1ee50dad1702e280faf577cbc3ffd4135fa3e7c715c12b42ff0f 6356912 chromium-driver_131.0.6778.85-1~deb12u1_arm64.deb b76d19cb462b53eb5003c6e2e9d62607a4d1f74df2fde5f7d10f8fa28954ce46 14112 chromium-sandbox-dbgsym_131.0.6778.85-1~deb12u1_arm64.deb aff7e10f04018cf6672009822f876431d616285363df23043fbe9fdd4481774a 97432 chromium-sandbox_131.0.6778.85-1~deb12u1_arm64.deb 86e269a63bd726a3d35e9aafd7dd37e6bcf2e32df8426090c9eb83d4b94013e5 27859260 chromium-shell-dbgsym_131.0.6778.85-1~deb12u1_arm64.deb d3c8107536efc70d3931f68814eeaa5bbd2888c5c5acfbe795491e54383ac294 46770060 chromium-shell_131.0.6778.85-1~deb12u1_arm64.deb fd718c6dbab6e51859ad6118c82e4dceee4960b8fc6439650abf0fa61044c727 24902 chromium_131.0.6778.85-1~deb12u1_arm64-buildd.buildinfo 8f5fc4830b7030b706ccc868e712451330e5eaa4076264f95da3c6ec80007112 75904364 chromium_131.0.6778.85-1~deb12u1_arm64.deb Files: f4f39bf35999a599dc375a45efd7206c 5506332 debug optional chromium-common-dbgsym_131.0.6778.85-1~deb12u1_arm64.deb 5bf3a65fb331dfad766caf57771f3287 13508972 web optional chromium-common_131.0.6778.85-1~deb12u1_arm64.deb 268c064d9044e9af92c471d6c9e8dd1c 33352980 debug optional chromium-dbgsym_131.0.6778.85-1~deb12u1_arm64.deb cf5a77e2989ab7378cbf4b70970261a3 6356912 web optional chromium-driver_131.0.6778.85-1~deb12u1_arm64.deb d1605a8a8ee5c329109ad3961e722cb3 14112 debug optional chromium-sandbox-dbgsym_131.0.6778.85-1~deb12u1_arm64.deb d8af868e1026afe1913f760c5db2b97a 97432 web optional chromium-sandbox_131.0.6778.85-1~deb12u1_arm64.deb 6a2b257e3b93ba1d257342b210d7f863 27859260 debug optional chromium-shell-dbgsym_131.0.6778.85-1~deb12u1_arm64.deb 7ce91e7a4a225484caa34d95d03955ad 46770060 web optional chromium-shell_131.0.6778.85-1~deb12u1_arm64.deb ed5f644a752ea40a050b793c82424ab7 24902 web optional chromium_131.0.6778.85-1~deb12u1_arm64-buildd.buildinfo 59694fafe77ba454a5aeb8882fab9cf7 75904364 web optional chromium_131.0.6778.85-1~deb12u1_arm64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEU81tY/BC8e+eAeWhLffeOnPnbLUFAmdBob8ACgkQLffeOnPn bLXp/A/+Pn6HgZKyTH1WTxpMa4lMpKmI1AMdwRhQJvbDl5k2hfLt4od65JgzqC8x x8N6pzllPSWBvvcmBCQwUTjaVyPsj/ulsqxOv5Uh9jS4AgSjFOOH/nJLUj4kcvfw 4hLAEWNW5nVH8MzEHAM++n9ry2yqHIGh3bMlUjjN11V2jgqgqKM+AxBxLa6/sgkV XtD+IAQhcOTMNH1291FnmEvZPIaolBUHeAfCbt9z7bvsP8v73pwf52PTX2aT09dP M/okJ+kGl3R8g+ao5MAKinz8lttd1FNdpw33zAwffUA3FcXqxGqwtTX2xeDKhngH Gztomfo/EVW8RmqPYoyXLwUEWkF0o9sNutgLUr4LKWF3qJDiODe/3eCL0vKGscF6 1lf7+s28WuVdlAMsldPrpdM2udd9f6bipwkvcNanfW/n3HBcnZIWC5X7/rk7SLc4 8pPE9aTZWrsqhnjGizsAuGNXM9p6jEtZQbMCOzYdMycC+TIHXqnObVQAI6WXszFu FnqhAiZ5yv+h5rUwYRPvzWi+H4YihYMoECIxAy+R1QILZI9wU7UL3cBI3SLQBG1J YULh+ih6w74kwU2vowMrXbIMfoqUmk4xw483heyStmHCjbMYrrDHKjsqyCu3afxj v4OF/gDYd9HPI/nr6LWFwkQTDjb0BEatCqaeZb1hzfcoc4mCPB8= =CDiT -----END PGP SIGNATURE-----