-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 30 Apr 2024 17:53:52 -0400 Source: chromium Binary: chromium chromium-common chromium-common-dbgsym chromium-dbgsym chromium-driver chromium-sandbox chromium-sandbox-dbgsym chromium-shell chromium-shell-dbgsym Architecture: arm64 Version: 124.0.6367.118-1~deb12u1 Distribution: bookworm-security Urgency: high Maintainer: arm Build Daemon (arm-ubc-01) Changed-By: Andres Salomon Description: chromium - web browser chromium-common - web browser - common resources used by the chromium packages chromium-driver - web browser - WebDriver support chromium-sandbox - web browser - setuid security sandbox for chromium chromium-shell - web browser - minimal shell Changes: chromium (124.0.6367.118-1~deb12u1) bookworm-security; urgency=high . * New upstream security release. - CVE-2024-4331: Use after free in Picture In Picture. Reported by Zhenghang Xiao (@Kipreyyy). - CVE-2024-4368: Use after free in Dawn. Reported by wgslfuzz. * Build-dep on libhwy-dev and delete the bundled third_party/highway. * Build-dep on libharfbuzz-dev and delete the bundled harfbuzz-ng. * Build-dep on libdav1d-dev and delete the bundled third_party/dav1d. * d/patches: - ppc64le/third_party/0001-Add-PPC64-support-for-libdav1d.patch, ppc64le/third_party/0001-Fix-libdav1d-compilation-on-clang-ppc.patch, ppc64le/third_party/0003-thirdparty-fix-dav1d-gn.patch, fixes/arm64-ftbfs.patch: drop these 4 patches that are only needed for bundled libdav1d. - ppc64le/third_party/0001-Fix-highway-ppc-hwcap.patch, ppc64le/third_party/0002-Highway-disable-128-bit-vsx.patch: drop these two patches that were needed for bundled highway. - upstream/ozone1.patch: drop, merged upstream. - upstream/ozone2.patch: drop, merged upstream. - fixes/bad-font-gc2.patch: refresh. . [ Timothy Pearson ] * d/patches/ppc64le: - third_party/0001-Add-PPC64-support-for-boringssl.patch: Fix inadvertent breakage of i386 build Checksums-Sha1: 7deb01d046b8d9a17a817c2adee061abddff27ed 1285684 chromium-common-dbgsym_124.0.6367.118-1~deb12u1_arm64.deb 867c735ab7683739dc8bcf6e5b3e060c1a5836ea 4861500 chromium-common_124.0.6367.118-1~deb12u1_arm64.deb 8ebf4fcde8b6067806888dfd703e025cc610ef81 35910472 chromium-dbgsym_124.0.6367.118-1~deb12u1_arm64.deb 60ebda5c14e22cd1e69189c0a8defb692eab7a2b 5567444 chromium-driver_124.0.6367.118-1~deb12u1_arm64.deb 7580bb569c9f5b595b4e0bd75a36df70f25c1d3c 14464 chromium-sandbox-dbgsym_124.0.6367.118-1~deb12u1_arm64.deb bc2b14b7b7f1cff1759dea5be302013d7e9f5b7b 89288 chromium-sandbox_124.0.6367.118-1~deb12u1_arm64.deb 5c87c4de5f95f4bf6c5a0ebbf81c037a8620ad3d 30454768 chromium-shell-dbgsym_124.0.6367.118-1~deb12u1_arm64.deb 35917d8b836cc2511ecef1a61e499b1385d5ff16 46363536 chromium-shell_124.0.6367.118-1~deb12u1_arm64.deb e8f333d75dd53c93d622341fa6fe3b0515cd4533 24690 chromium_124.0.6367.118-1~deb12u1_arm64-buildd.buildinfo fa8d902929c44f39f812c03214799fd46b3fe80a 66216556 chromium_124.0.6367.118-1~deb12u1_arm64.deb Checksums-Sha256: 14664f354a377a4d99ebc8aea09fd19fb6e3787da273152d85cb648b75b1fb4e 1285684 chromium-common-dbgsym_124.0.6367.118-1~deb12u1_arm64.deb 395df4f48f3f7501f3e9c6c35d5affdc7de5320a499f954160ba81b3c6fa2bfb 4861500 chromium-common_124.0.6367.118-1~deb12u1_arm64.deb 018fca5a9134f9707b329eaa6704d732aaaf20557193de35d524fc2e7e406c77 35910472 chromium-dbgsym_124.0.6367.118-1~deb12u1_arm64.deb fb1776a7c57276ccd44afc3af781ce59433cf443931fc33ce965d2f7b4cfeb40 5567444 chromium-driver_124.0.6367.118-1~deb12u1_arm64.deb 65f369c4a6d893a58adda7f733fe269ddd4af19e3e7b393f568cfdd4bd8a188b 14464 chromium-sandbox-dbgsym_124.0.6367.118-1~deb12u1_arm64.deb 9459c8e33052a6e4e46b342608cdb191060aed3d1933db030167afd76821db66 89288 chromium-sandbox_124.0.6367.118-1~deb12u1_arm64.deb 725791d704aa956fc52ee67afbd598f0f36fb06af1457e84fba32089a018ac9d 30454768 chromium-shell-dbgsym_124.0.6367.118-1~deb12u1_arm64.deb e7e209a1aae2a0d59918126b25dd79d1e8b2ea4269f11eb9cdaa18c41f79a186 46363536 chromium-shell_124.0.6367.118-1~deb12u1_arm64.deb dbedc8756b7fb61881bbeed6a6a221f975b97a21b1c8aec157d32d9339c05a2f 24690 chromium_124.0.6367.118-1~deb12u1_arm64-buildd.buildinfo 40299bc2325af7a623748e6dced21f6e614b10369922f5cb6340a65b1810bac2 66216556 chromium_124.0.6367.118-1~deb12u1_arm64.deb Files: 0ac6a9df659c9c923dd31808f82daea5 1285684 debug optional chromium-common-dbgsym_124.0.6367.118-1~deb12u1_arm64.deb 305326ea6973dbf166ada53839fe3dde 4861500 web optional chromium-common_124.0.6367.118-1~deb12u1_arm64.deb 6e7b5bbdc359cadf83437fb3086ea2ab 35910472 debug optional chromium-dbgsym_124.0.6367.118-1~deb12u1_arm64.deb 1efc1c222bf3c5753f39ea78c86fd408 5567444 web optional chromium-driver_124.0.6367.118-1~deb12u1_arm64.deb a07b7feaea08690823b01e4560b11e30 14464 debug optional chromium-sandbox-dbgsym_124.0.6367.118-1~deb12u1_arm64.deb 13a6573aa63c0bab3c5b5d80059bfb0a 89288 web optional chromium-sandbox_124.0.6367.118-1~deb12u1_arm64.deb 05c39c15684968346b7ef6232505d1d8 30454768 debug optional chromium-shell-dbgsym_124.0.6367.118-1~deb12u1_arm64.deb 0016ac52acb00874b38e4d76bf4ebf3d 46363536 web optional chromium-shell_124.0.6367.118-1~deb12u1_arm64.deb 7d38987731bce79119e0dfd271e99078 24690 web optional chromium_124.0.6367.118-1~deb12u1_arm64-buildd.buildinfo 2484b92c33a66d223ca5da1f6c9ed75f 66216556 web optional chromium_124.0.6367.118-1~deb12u1_arm64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEH43oX1cK+BEEs9Pe/9j0ct/+ZwwFAmY1NWkACgkQ/9j0ct/+ ZwzOjQ//U5BLsor3SlPzbYSjfFfn0ObQXfX8FVOejR+GIflA2NIEmbOvNWJx5SOz HBvuhe5406AMCCcxTd85C5uJ0Wv3aMk2JeHQcmzPVpjp6xecwaKwdBR1UdGTHIsQ bgQDJD7fazvbmwhgoGq3oQ+sadaSPzANEgmSjgoCI/1+IdF+JDtCrmMhK/ne6+xp V44KKmpmCw1z/MAbLFhv6f56t4oYWqG9mda6zrIMRpJNsNR9E2ovMnRE+IGxuIT7 dARprQs1XD52dVUUiEsetTuZfQS0Z4lqmu2FuQEAXm22OOE9r6S7A5o+TmHkSROB C4LiGKbAtnsBLU8dTBuf2BCOZCxqqlUAhEiHivtDznydxyVrp+SddcqdJ7z1p+sh wGpIWdj8m/6LwtwLnsHDe18YdD3NiFvB5M6nNiPD7k1yBCZEGRs6bYcgGPMC3cIM zqKLJVJoAod/5TIM3yaYy8w9n0GseX7zkBt78DEEVGw6sTmukgMo9AZMxEcY6AwX d3x2UjPM78RA3nPht4g2pUFVuD7bjZYJ1VhL1Otz4fhgNXixgtJoux/9JzxSOOX7 pkuJ6YUjDOfuhEvzbyrP0nrtgdUOKzXCz4SRjiS6ik6JDSBwufYJAkq5qU3bjXOF MPXELHox6rHRMW3f+tJX9bRi6LPlDn0vHq1MS/OAjWXMD/VUL4I= =vNx5 -----END PGP SIGNATURE-----