-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 10 Jun 2025 15:08:42 -0400 Source: chromium Binary: chromium chromium-common chromium-common-dbgsym chromium-dbgsym chromium-driver chromium-headless-shell chromium-headless-shell-dbgsym chromium-sandbox chromium-sandbox-dbgsym chromium-shell chromium-shell-dbgsym Architecture: arm64 Version: 137.0.7151.103-1~deb12u1 Distribution: bookworm-security Urgency: high Maintainer: arm Build Daemon (arm-ubc-04) Changed-By: Andres Salomon Description: chromium - web browser chromium-common - web browser - common resources used by the chromium packages chromium-driver - web browser - WebDriver support chromium-headless-shell - web browser - old headless shell chromium-sandbox - web browser - setuid security sandbox for chromium chromium-shell - web browser - minimal shell Changes: chromium (137.0.7151.103-1~deb12u1) bookworm-security; urgency=high . * New upstream security release. - CVE-2025-5958: Use after free in Media. Reported by Huang Xilin of Ant Group Light-Year Security Lab. - CVE-2025-5959: Type Confusion in V8. Reported by Seunghyun Lee as part of TyphoonPWN 2025. * Add build-dep on libc++-19-dev and switch to building statically against clang's libc++ (instead of gcc's libstdc++). * d/patches: - fixes/absl-optional.patch: drop, only needed for libstdc++. - fixes/font-gc-asan.patch: drop, only needed for libstdc++. - fixes/stdatomic.patch: drop, only needed for libstdc++. - fixes/make-pair.patch: drop, only needed for libstdc++. - bookworm/constflatset.patch: drop, only needed for libstdc++. - bookworm/constexpr2.patch: drop, only needed for libstdc++. - bookworm/constexpr3.patch: drop, only needed for libstdc++. - bookworm/foreach.patch: add patch from bookworm branch to fix clang-19 build failure. Checksums-Sha1: 385a38b354317061a57bbd06100f80ded2de7190 5886808 chromium-common-dbgsym_137.0.7151.103-1~deb12u1_arm64.deb cab6fb9147b50ef7278b857249caff50ce108907 26926252 chromium-common_137.0.7151.103-1~deb12u1_arm64.deb bbee24d15ad78029a3f1dde69d3db9f90b42d273 31312848 chromium-dbgsym_137.0.7151.103-1~deb12u1_arm64.deb 72c58f58bb06adf456d3b003b4a0a0b252ce9665 6999960 chromium-driver_137.0.7151.103-1~deb12u1_arm64.deb 06f7f258ccb06f323b04b16a6c8f77f5b3f99ad2 26355712 chromium-headless-shell-dbgsym_137.0.7151.103-1~deb12u1_arm64.deb bc805bdc0f225ebeaab1e37b8e61b6f0c3f1c265 51680596 chromium-headless-shell_137.0.7151.103-1~deb12u1_arm64.deb 33bf24e6fc2ef47e86c358e4c82d50920393994f 19860 chromium-sandbox-dbgsym_137.0.7151.103-1~deb12u1_arm64.deb fee58f1f05d12632acb51bdfbde482946a24b6d2 105132 chromium-sandbox_137.0.7151.103-1~deb12u1_arm64.deb fcd18448bb72ddbfdbb4c08e9b9553a4cc50cfd4 26148256 chromium-shell-dbgsym_137.0.7151.103-1~deb12u1_arm64.deb dafaff0159cae7a70bfbae3b447c8ab2acd1f3e0 48731324 chromium-shell_137.0.7151.103-1~deb12u1_arm64.deb 7f05771e7dd5d2a4eb2219a2f141a5fe4fc3a6bd 30216 chromium_137.0.7151.103-1~deb12u1_arm64-buildd.buildinfo f9b4a207feb4adcc7cc17a0835c731b08c71262e 67928420 chromium_137.0.7151.103-1~deb12u1_arm64.deb Checksums-Sha256: a5cc6700878b5015d5215e7670f37c18f2f293d79ccb58afe7742f0f18ad318a 5886808 chromium-common-dbgsym_137.0.7151.103-1~deb12u1_arm64.deb 86079e6485c7d0ab8f8fccf6415f097fe352750ac058fd69a10ab9bdb5f17ad2 26926252 chromium-common_137.0.7151.103-1~deb12u1_arm64.deb 6d01a6baf1bcb0ddc3da5d5bdadd0f77b3265fd04ebf736fd37a64b187c0cc5e 31312848 chromium-dbgsym_137.0.7151.103-1~deb12u1_arm64.deb df6faaead8ce14cd8b11d5152a5c1708ece61893ed224e8350817a2f83efbb09 6999960 chromium-driver_137.0.7151.103-1~deb12u1_arm64.deb ce95b19534eb27fc7ee210d9e250a190c791d6b8a5037131de46bcbc78357d37 26355712 chromium-headless-shell-dbgsym_137.0.7151.103-1~deb12u1_arm64.deb b74ede32e04edb7ee12a28fb670481d573964b644123e9cd246c69a212a43d8d 51680596 chromium-headless-shell_137.0.7151.103-1~deb12u1_arm64.deb 343d33f61d07107ca758550aa4e8a364d7de80ce515580c7fa086f1cb1d2aff9 19860 chromium-sandbox-dbgsym_137.0.7151.103-1~deb12u1_arm64.deb 82e5e90007c3ff296d72ae549abd17b89344a9cbce7f01f3092112a80f86145e 105132 chromium-sandbox_137.0.7151.103-1~deb12u1_arm64.deb 7c005658585eddaef00647614529c1ff9a40273022ab01b5303b52a630488d86 26148256 chromium-shell-dbgsym_137.0.7151.103-1~deb12u1_arm64.deb c21a48c5c44fc7c7ac41feb2085a2b98cc1abf0ce633cd385787eb050535ef49 48731324 chromium-shell_137.0.7151.103-1~deb12u1_arm64.deb 0ca48102b8021f27cbe6935e32d505f7ce51be61fd0bfa0a15e8bab387f6be11 30216 chromium_137.0.7151.103-1~deb12u1_arm64-buildd.buildinfo def6073d8789b0c02e75be276a1ab550c8c9830e468b133ac00d0fcbe33f04e2 67928420 chromium_137.0.7151.103-1~deb12u1_arm64.deb Files: 21bcbe6588a1b07f0896982bc1b17137 5886808 debug optional chromium-common-dbgsym_137.0.7151.103-1~deb12u1_arm64.deb 03c6b9b4e19bddc03e151c6252e6899b 26926252 web optional chromium-common_137.0.7151.103-1~deb12u1_arm64.deb c72c33b2559c8c93428ac2f8f75bc5a0 31312848 debug optional chromium-dbgsym_137.0.7151.103-1~deb12u1_arm64.deb aad697ef7aad924d497035437ff673d9 6999960 web optional chromium-driver_137.0.7151.103-1~deb12u1_arm64.deb f8946715b57bb652aa79d30c9cbaf4d1 26355712 debug optional chromium-headless-shell-dbgsym_137.0.7151.103-1~deb12u1_arm64.deb 75051dc4b844f414d29a1dbe1c56102c 51680596 web optional chromium-headless-shell_137.0.7151.103-1~deb12u1_arm64.deb 95ab331334386e39a85fe77e0670f3aa 19860 debug optional chromium-sandbox-dbgsym_137.0.7151.103-1~deb12u1_arm64.deb 9946f84bdffe7267c6a1ca84c2754d70 105132 web optional chromium-sandbox_137.0.7151.103-1~deb12u1_arm64.deb 29dadee3ba6621721684026e7c296e7c 26148256 debug optional chromium-shell-dbgsym_137.0.7151.103-1~deb12u1_arm64.deb 86e580e98c7763d55bfe9e0dec5e0fe6 48731324 web optional chromium-shell_137.0.7151.103-1~deb12u1_arm64.deb 41a91850a511e5ba3dc31a6597c31201 30216 web optional chromium_137.0.7151.103-1~deb12u1_arm64-buildd.buildinfo 1c6fdd27fee540c113ed7d61f1b905ea 67928420 web optional chromium_137.0.7151.103-1~deb12u1_arm64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEUPFH3FhY8nQZGtLwVLd4YzMSDKEFAmhNcBEACgkQVLd4YzMS DKGadQ//cSvQFQayEHVMYFEqiRrrTV1oImU9CF0OpsX7nL3g7VVSmA9MCRdzy977 cpgd3PK1Kz1Wl7dt3FBX0R3TH3i/1F1IcA/BK+aIWALV+1hphbvXB8ZXNAP7wVsx DYNRy+f12bBqzd5XaMErLMMnFnj00JbEHUtYx7F5OF6LQyk0hHVRvslDQl8lEDza lkP+NEZlnYdUhdgVjQI2brHXa/n2xEYTG18D6K0NSQUMPV5427V6C1ddRnfT4tqq bIeJbqKfgevg/k3RsnAjmcPzFYwNywUh66cB9igRrzQthd7e9qIcitGl2/44b5jm 0sNSQy7w40BWbsDOJUYmGU6J2A+fNW2y2KUF4beErVydCtw5nl637u8vP9Cs4HV6 F0E898TjXCStvbOHHuhzdZrbxTS0iBxtEIypKgrJoArVF3Lm97rn0IPDwoBZkubx xWvoH7krJXCfoDgaTl73yLc4L570nvj71CVhLbWJJRxo5LwzQ09caz6u3ONAkayZ BaRSwPYGbOYayI28PYpHfMYVIM4IVlwbwTWA5bOxaeXeqP0sIqRQD07L7J3L6qrB 0KCDMDpq03QgT8Wcy62ZP35gU+OTtTsePdlJ4FiIJGv4ZM98CC7/9dSDFo/rSA73 XHIr44srEMs5XEIn3BrBuZek+/TU13fX97T8ZjIyjAaqTsU1ccw= =qnmd -----END PGP SIGNATURE-----