-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 30 Apr 2024 17:53:52 -0400 Source: chromium Binary: chromium chromium-common chromium-common-dbgsym chromium-dbgsym chromium-driver chromium-sandbox chromium-sandbox-dbgsym chromium-shell chromium-shell-dbgsym Architecture: armhf Version: 124.0.6367.118-1~deb12u1 Distribution: bookworm-security Urgency: high Maintainer: arm Build Daemon (arm-conova-03) Changed-By: Andres Salomon Description: chromium - web browser chromium-common - web browser - common resources used by the chromium packages chromium-driver - web browser - WebDriver support chromium-sandbox - web browser - setuid security sandbox for chromium chromium-shell - web browser - minimal shell Changes: chromium (124.0.6367.118-1~deb12u1) bookworm-security; urgency=high . * New upstream security release. - CVE-2024-4331: Use after free in Picture In Picture. Reported by Zhenghang Xiao (@Kipreyyy). - CVE-2024-4368: Use after free in Dawn. Reported by wgslfuzz. * Build-dep on libhwy-dev and delete the bundled third_party/highway. * Build-dep on libharfbuzz-dev and delete the bundled harfbuzz-ng. * Build-dep on libdav1d-dev and delete the bundled third_party/dav1d. * d/patches: - ppc64le/third_party/0001-Add-PPC64-support-for-libdav1d.patch, ppc64le/third_party/0001-Fix-libdav1d-compilation-on-clang-ppc.patch, ppc64le/third_party/0003-thirdparty-fix-dav1d-gn.patch, fixes/arm64-ftbfs.patch: drop these 4 patches that are only needed for bundled libdav1d. - ppc64le/third_party/0001-Fix-highway-ppc-hwcap.patch, ppc64le/third_party/0002-Highway-disable-128-bit-vsx.patch: drop these two patches that were needed for bundled highway. - upstream/ozone1.patch: drop, merged upstream. - upstream/ozone2.patch: drop, merged upstream. - fixes/bad-font-gc2.patch: refresh. . [ Timothy Pearson ] * d/patches/ppc64le: - third_party/0001-Add-PPC64-support-for-boringssl.patch: Fix inadvertent breakage of i386 build Checksums-Sha1: 82cf7d73ff1192ac04ec86cbf5ac0046072426e0 1306752 chromium-common-dbgsym_124.0.6367.118-1~deb12u1_armhf.deb 581bdee4934d26fe0797d530ce706421db946dbc 4949028 chromium-common_124.0.6367.118-1~deb12u1_armhf.deb 426834d5333d31b6381661c8d0ce38ad4c880030 34288848 chromium-dbgsym_124.0.6367.118-1~deb12u1_armhf.deb d2d05cc1be78f5306fe247d20d00c7d7e2c73c85 5867376 chromium-driver_124.0.6367.118-1~deb12u1_armhf.deb b591045d8c38c0e39ccb57dde34acb0f6cbb8871 12220 chromium-sandbox-dbgsym_124.0.6367.118-1~deb12u1_armhf.deb ba77cbdbcf9efb6c5f1761b71aabf4f81e8dfdf4 88964 chromium-sandbox_124.0.6367.118-1~deb12u1_armhf.deb 6ae6fb4ffb2373ad7c02c7c5713c538a198c1f94 28313728 chromium-shell-dbgsym_124.0.6367.118-1~deb12u1_armhf.deb da3f78e5c6ae7015bee8f7bf43a089419582bd93 47884548 chromium-shell_124.0.6367.118-1~deb12u1_armhf.deb c8688043588207f82729e9ee10869bd35881d667 24632 chromium_124.0.6367.118-1~deb12u1_armhf-buildd.buildinfo 813b9e17f506901d7a32ca87ee291511f9badcd5 68696356 chromium_124.0.6367.118-1~deb12u1_armhf.deb Checksums-Sha256: ead9c6ec116be00abb3cacfedd535252b5f933445d74a843d8e148469f0ae984 1306752 chromium-common-dbgsym_124.0.6367.118-1~deb12u1_armhf.deb a087806f3cd93b614d59a177410d655e0b6fd1fd206683816b36e4b90e7645fa 4949028 chromium-common_124.0.6367.118-1~deb12u1_armhf.deb 6fa9bb4cdd8a6a9a3e1808f54ac4ea84ac2d8cf39b3015cb24d5e879ba293c2a 34288848 chromium-dbgsym_124.0.6367.118-1~deb12u1_armhf.deb 8a22f44a10b2edeed1b3206c0b329ee154163c002f0f5c85e28acf505c7955af 5867376 chromium-driver_124.0.6367.118-1~deb12u1_armhf.deb e0d2bf8bfdac57ce7af3465840b11e48fd603a071ae7268065cf728c62b639b1 12220 chromium-sandbox-dbgsym_124.0.6367.118-1~deb12u1_armhf.deb bc4f027cf37b1724bc1cea1c21cf07fe6e2ebe3d92980b976ce2c3c6147d9530 88964 chromium-sandbox_124.0.6367.118-1~deb12u1_armhf.deb 0e80ea9cc2bc344e66f101d9bd9b0af9bdbb24ffce6effeca86130b605135b16 28313728 chromium-shell-dbgsym_124.0.6367.118-1~deb12u1_armhf.deb 7bdaba4723df961ef956e647d0035a1548cbaf35a2b50df3315deee4e670fa68 47884548 chromium-shell_124.0.6367.118-1~deb12u1_armhf.deb ec50c7f10625af3ce171280a42e73a051646c13e57dd0e33b7bd465096c3bccc 24632 chromium_124.0.6367.118-1~deb12u1_armhf-buildd.buildinfo 3bec2fd6c9f5b13ea276849a0baa4f20c87c074b1a6d9a4cd254b9d92af7b0b5 68696356 chromium_124.0.6367.118-1~deb12u1_armhf.deb Files: f4d4c2515ef66eaa809268c6712b72bc 1306752 debug optional chromium-common-dbgsym_124.0.6367.118-1~deb12u1_armhf.deb 9eb1f5d1102f91399da0a3bec1765035 4949028 web optional chromium-common_124.0.6367.118-1~deb12u1_armhf.deb b29d8310e6bccbb2b266183e35305ec9 34288848 debug optional chromium-dbgsym_124.0.6367.118-1~deb12u1_armhf.deb 69626a760247e109704d42cb2b19b5d4 5867376 web optional chromium-driver_124.0.6367.118-1~deb12u1_armhf.deb a42506ca6d8d84ed790c76e73a8340c6 12220 debug optional chromium-sandbox-dbgsym_124.0.6367.118-1~deb12u1_armhf.deb 26c09a4ce516e9af233e72c5889bbea2 88964 web optional chromium-sandbox_124.0.6367.118-1~deb12u1_armhf.deb b1c48a2bf7d1927c9bfefc30037142f9 28313728 debug optional chromium-shell-dbgsym_124.0.6367.118-1~deb12u1_armhf.deb 52eef22711452ce0a2d5fc18c8613c20 47884548 web optional chromium-shell_124.0.6367.118-1~deb12u1_armhf.deb 78dd2469d73f103fe887de969e4db9fe 24632 web optional chromium_124.0.6367.118-1~deb12u1_armhf-buildd.buildinfo 14b9a5ccf10c81c3c272501417f93e3d 68696356 web optional chromium_124.0.6367.118-1~deb12u1_armhf.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEU81tY/BC8e+eAeWhLffeOnPnbLUFAmYy8IsACgkQLffeOnPn bLWXAw//WLgAoPz9bd3BHcgC/GEuGiVtkmqj+OIDiQCiTzwvq451KOo0tPp6u05c mdIEaw7WdL9Q7zIQ+iHihxaU6Nt0qdUu514GjBmkXAdoY9XJCR7OjnMUSOxqAfe9 +13l75MNUjSRtM69EoUDlqjdXkfemcmcr3UdCeIBKvUeRG8UmXAA1Qm25FwL5Pqu 3JVZWugIePAXNLEyyLGG+rQpRx2uu7+VFOy4tQPOnKucwgKxiPtmAKRx2Sle69Bp F6WN+WQ9wVlN/F8b6pgxfi1IlNmeMfCKepRUBgPDa//OAG0OPp022ZnfndLD/Sep Giu2s4nOUzV2ykZvf50lFSzA6TMXi0eCzFrH2zUCggPEwbn+iD0eLX1beAjJwBP8 9z0srSaTDA7zDf2HHCVN3dVzRFIaHNur1EqLYwIREQGtenRxYBs62qTivEUgro9m PvENm+/n0xMixe+X//7JU7rWcx0lohtT1MUA0cDAz3xXlOKBaTMfrUfQ41ia4iL+ HOlsh2QeEHjJSFf9qczfnXTaDpSd/nuGC6AbN+gI6EeE4PCYjdCoj+00EB6XozB0 Jk1bRbyrMD8QU5XcT9DjIcf8udGvsvfaK5mm1/OwgJSI7R3XTS7UZgMpJwG0z3Yl tsIbMy7MbIlrsJUbCeSfmf+iyl9W0D7yWyf9SLlgZIUJRg+PJtw= =+LYc -----END PGP SIGNATURE-----