-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Thu, 21 Nov 2024 16:12:03 -0500 Source: chromium Binary: chromium chromium-common chromium-common-dbgsym chromium-dbgsym chromium-driver chromium-sandbox chromium-sandbox-dbgsym chromium-shell chromium-shell-dbgsym Architecture: armhf Version: 131.0.6778.85-1~deb12u1 Distribution: bookworm-security Urgency: high Maintainer: arm Build Daemon (arm-conova-01) Changed-By: Andres Salomon Description: chromium - web browser chromium-common - web browser - common resources used by the chromium packages chromium-driver - web browser - WebDriver support chromium-sandbox - web browser - setuid security sandbox for chromium chromium-shell - web browser - minimal shell Changes: chromium (131.0.6778.85-1~deb12u1) bookworm-security; urgency=high . [ Andres Salomon ] * New upstream stable release. - CVE-2024-11110: Inappropriate implementation in Blink. Reported by Vsevolod Kokorin (Slonser) of Solidlab. - CVE-2024-11111: Inappropriate implementation in Autofill. Reported by Narendra Bhati, Suma Soft Pvt. Ltd - Pune (India). - CVE-2024-11112: Use after free in Media. Reported by Nan Wang(@eternalsakura13) and Zhenghang Xiao(@Kipreyyy) of 360 Vulnerability Research Institute. - CVE-2024-11113: Use after free in Accessibility. Reported by Weipeng Jiang (@Krace) of VRI. - CVE-2024-11114: Inappropriate implementation in Views. Reported by Micky. - CVE-2024-11115: Insufficient policy enforcement in Navigation. Reported by mastersplinter. - CVE-2024-11116: Inappropriate implementation in Paint. Reported by Thomas Orlita. - CVE-2024-11117: Inappropriate implementation in FileSystem. Reported by Ameen Basha M K. - CVE-2024-11395: Type Confusion in V8. Reported by Anonymous. * d/patches: - upstream/wayland-gbm-pixmap.patch: drop, merged upstream. - disable/catapult.patch: refresh. - fixes/bindgen.patch: refresh. - fixes/freetype.patch: add new patch to fix missing enable_freetype arg declaration. - fixes/updater-test.patch: add simple build fix for deleted third_party/updater/. - upstream/stack-header.patch: drop, merged upstream. - bookworm/clang16.patch: refresh. - bookworm/bubble-contents.patch: refresh. - bookworm/constexpr.patch: refresh. - bookworm/gn-absl.patch: add a few more places where libs needed to be made visible. - bookworm/gn-funcs.patch: add another deletion of newer gn features. - bookworm/constexpr-assert.patch: add patch to work around more clang-16 constexpr bugs; this time a fun one with branching optimizations. Whee! . [ Timothy Pearson ] * d/patches/ppc64le: - workarounds/HACK-debian-clang-disable-pa-musttail.patch: Work around additional upstream musttail definitions - workarounds/HACK-debian-clang-disable-base-musttail.patch: Refresh for upstream changes - third_party/0002-third_party-libvpx-Remove-bad-ppc64-config.patch: Refresh for upstream changes Checksums-Sha1: 9cb1a88667bae0ca89e384bdc316003f06940be2 5861480 chromium-common-dbgsym_131.0.6778.85-1~deb12u1_armhf.deb 9b8a3f12471485ab6b35f8fc4c4be939c3d997b2 9877160 chromium-common_131.0.6778.85-1~deb12u1_armhf.deb 96b316075deb58a9f221e86dac32c6661caaee27 33840700 chromium-dbgsym_131.0.6778.85-1~deb12u1_armhf.deb c3c5d2be9f0f385cbfc4338e241cf5826509215f 6735164 chromium-driver_131.0.6778.85-1~deb12u1_armhf.deb 03c41ea4eabf43273207ccf92af663fe403ed61e 12276 chromium-sandbox-dbgsym_131.0.6778.85-1~deb12u1_armhf.deb c45906e370dd162e3258a44da0c0b45aa68080d6 97164 chromium-sandbox_131.0.6778.85-1~deb12u1_armhf.deb 8c9b32a8c83c6846bdf901ee3de4666251da0786 27949596 chromium-shell-dbgsym_131.0.6778.85-1~deb12u1_armhf.deb 715e1a9ed062091a904d60455e8cf66c9b6077ad 49080740 chromium-shell_131.0.6778.85-1~deb12u1_armhf.deb 8527a869235bd9d2d06ce830f7a1b7d8d8e247b8 24841 chromium_131.0.6778.85-1~deb12u1_armhf-buildd.buildinfo bceaa87f46635c20307c6a766d2045e29084efca 70416076 chromium_131.0.6778.85-1~deb12u1_armhf.deb Checksums-Sha256: 3d25e2b05330749034bb31e2c0c76e8441d39cae83b39de7e8a52bd9a9d96ed4 5861480 chromium-common-dbgsym_131.0.6778.85-1~deb12u1_armhf.deb 0dec616d8d33c4f6f1d49db35ab76c0ce55b28e6081d63e9b25cebe6496f052c 9877160 chromium-common_131.0.6778.85-1~deb12u1_armhf.deb 0f94c7817930aacd3a2b6a4ab4f8b2d9665bf77484a44cf21f5fcdebd39d45e8 33840700 chromium-dbgsym_131.0.6778.85-1~deb12u1_armhf.deb 6021c30e59e988ad6413b67eab86141536b5e9065c1c71aafd1afb4ef7c9fbbb 6735164 chromium-driver_131.0.6778.85-1~deb12u1_armhf.deb 29e65e4718fec7bb5627c010f7e451c9c5ccbb30c1bbfb106199bf8079a2d482 12276 chromium-sandbox-dbgsym_131.0.6778.85-1~deb12u1_armhf.deb f5cb542f51e4fb970f2c4b9189de1c7a0d1dcbfa61ba3f297ea12af6a9806680 97164 chromium-sandbox_131.0.6778.85-1~deb12u1_armhf.deb 03da7555aea65b27f965360bf72164abdf58c36ec59f509d791d999d979e28f9 27949596 chromium-shell-dbgsym_131.0.6778.85-1~deb12u1_armhf.deb 384e7d30b68e1880601885225823191cf2667273e8ff37cc4803a7bfa77c1e98 49080740 chromium-shell_131.0.6778.85-1~deb12u1_armhf.deb 95d8edc6ce25af841eb06e222fc7911c460f221ba93647673e7e29d75b73c8f9 24841 chromium_131.0.6778.85-1~deb12u1_armhf-buildd.buildinfo 09852960d42913964e0df78cb3a5b4486f8a6a00af7f9e0cd448ecb517ff1083 70416076 chromium_131.0.6778.85-1~deb12u1_armhf.deb Files: 7c0d8e6afa0aab7b0cccfb736fd2a99a 5861480 debug optional chromium-common-dbgsym_131.0.6778.85-1~deb12u1_armhf.deb dc4a54a44cf50ed8511a1c6cb2f53b50 9877160 web optional chromium-common_131.0.6778.85-1~deb12u1_armhf.deb f44078140fa8ee4ee2b88e00443f528b 33840700 debug optional chromium-dbgsym_131.0.6778.85-1~deb12u1_armhf.deb 91811cee9fbbcf887033b805dc061176 6735164 web optional chromium-driver_131.0.6778.85-1~deb12u1_armhf.deb 229b886ef9de3322d402e23fa2ad6cb2 12276 debug optional chromium-sandbox-dbgsym_131.0.6778.85-1~deb12u1_armhf.deb 172cac7ced768c4b2df408d0f70d2513 97164 web optional chromium-sandbox_131.0.6778.85-1~deb12u1_armhf.deb bb8d73cb1653641608ef61137097cd60 27949596 debug optional chromium-shell-dbgsym_131.0.6778.85-1~deb12u1_armhf.deb dc06a5dcc13b4ae2a62479ddae04497e 49080740 web optional chromium-shell_131.0.6778.85-1~deb12u1_armhf.deb 825e92b2739a194757953f138bb19706 24841 web optional chromium_131.0.6778.85-1~deb12u1_armhf-buildd.buildinfo dd3734efae2c3a801b3dc30a47b82f67 70416076 web optional chromium_131.0.6778.85-1~deb12u1_armhf.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEegRwmIwj8f99iF4m4CwlMGxHD8UFAmdBpU4ACgkQ4CwlMGxH D8XaoQ//ciycaUSVAX62At4fPp8qQ0XTYC/6IiYcyClNPPRuz4qbIegMhqVpy9l+ JXB0JHj155ybxncvHASixV3XqWY+3O1X8RrX9vF2b/nUkd6oXR65AZAa+Z4fiyJ1 SysUv6bANpiYceplPtgsTjXHryPySQvJuQSicR0EAzTaXsXDms5C9j/C7h/654Jk SDX0hFcLDhfQsWCc1hVGptgQApd+ZepqYUsVlp8Iq/93FWkICbZC54/sqK+N61IG 6iAwpdN0wZHwHFsFSiha0kWojq1SYiJt+SqHrKAPrIuMXsDDL1B/LL1uRicfnatz 3YKrjmLqXesQ+mW8Ou2eIkxe10eD9NeHJuqx6OgrNbSUZdWPhqYF/VqJt1pb0lAb tnDXbQmBahMMrgHIDnyPpZ1RDH8lW4xmPqe9/1YiwjEQt/5TzPNjtuceSqrVvcv5 tmfydeaiMV+XlI9TeYzyIyIxnGT81ac5Pdw1pBykH4Dmfpc1Dfr5WD5GAPSS54xA CzXIldrrMCwfdMDHyhzRVhzp2ImYFdQVECeq1xaQB4Znh2S5HbWJBSGTP2v+/GaR X2W5i6l/dDXArUXlnzaVH6DTRVc4PwiNLUZF0jFg1drtDDoD+Wx7eEDHUePfhVUD iPmZWifW53gGwTwShh/N60jo34pc8Hs8HJ9TUzl6R8lk8vIzvv0= =q5iX -----END PGP SIGNATURE-----