-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Thu, 04 Sep 2025 16:47:14 -0400 Source: chromium Binary: chromium chromium-common chromium-common-dbgsym chromium-dbgsym chromium-driver chromium-headless-shell chromium-headless-shell-dbgsym chromium-sandbox chromium-sandbox-dbgsym chromium-shell chromium-shell-dbgsym Architecture: i386 Version: 140.0.7339.80-1~deb12u1 Distribution: bookworm-security Urgency: medium Maintainer: i386 Build Daemon (x86-grnet-01) Changed-By: Andres Salomon Description: chromium - web browser chromium-common - web browser - common resources used by the chromium packages chromium-driver - web browser - WebDriver support chromium-headless-shell - web browser - old headless shell chromium-sandbox - web browser - setuid security sandbox for chromium chromium-shell - web browser - minimal shell Changes: chromium (140.0.7339.80-1~deb12u1) bookworm-security; urgency=medium . * New upstream stable release. - CVE-2025-9864: Use after free in V8. Reported by Pavel Kuzmin of Yandex Security Team. - CVE-2025-9865: Inappropriate implementation in Toolbar. Reported by Khalil Zhani. - CVE-2025-9866: Inappropriate implementation in Extensions. Reported by NDevTK. - CVE-2025-9867: Inappropriate implementation in Downloads. Reported by Farras Givari. * d/patches: - fixes/armhf-icf.patch: refresh. - disable/tests.patch: refresh. - disable/catapult.patch: refresh. - disable/widevine-cdm-cu.patch: refresh (and make it shorter). - bookworm/clang19.patch: refresh. - disable/android.patch: delete a new reference to chrome/android/. - disable/buildtools-libc.patch: drop due to upstream cleanups. - trixie/rust-no-alloc-shim.patch: add a build fix for older rustc. - bookworm/rust-visibility.patch: drop, not needed w/ new rust 1.85. - bookworm/crabbyav1f.patch: drop, not needed w/ new rust 1.85. - bookworm/toktrie-utf8chunks.patch: drop, not needed w/ new rust. - bookworm/derivre-create.patch: drop, not needed w/ new rust. - bookworm/rust-split-at-checked.patch: drop, not needed w/ new rust. - bookworm/crabbyav1f-macro-scope.patch: drop, not needed w/ new rust. - bookworm/rust-box-to-vec.patch: drop, not needed w/ new rust. . [ Timothy Pearson ] * d/patches/ppc64le: - third_party/0002-regenerate-xnn-buildgn.patch: Refresh for upstream changes - fixes/fix-study-crash.patch: Refresh for upstream changes - core/add-ppc64-architecture-to-extensions.diff: Refresh for upstream changes - fixes/fix-unknown-warning-option-messages.diff: Refresh for upstream changes - libaom/0001-Add-pregenerated-config-for-libaom-on-ppc64.patch: Regenerate from new upstream version - third_party/0003-third_party-ffmpeg-Add-ppc64-generated-config.patch: Regenerate from new upstream version Checksums-Sha1: 1ad1ba57a82c1606a3ca80044e32e425b39d7784 5084624 chromium-common-dbgsym_140.0.7339.80-1~deb12u1_i386.deb 8798be5f4cd2c7c9866d3020f97c295b141f8a29 22375396 chromium-common_140.0.7339.80-1~deb12u1_i386.deb 34e5c651b7f7c039fb4d0bbaad0c42b73b0311d5 33737040 chromium-dbgsym_140.0.7339.80-1~deb12u1_i386.deb 6a136d569ddd9fc78b8abb57e14222090c496681 7932972 chromium-driver_140.0.7339.80-1~deb12u1_i386.deb 9d57fdc7e0c5fe6cc1f371a3da00216ada630955 28043156 chromium-headless-shell-dbgsym_140.0.7339.80-1~deb12u1_i386.deb 93869f1bf71cbf45c9a66a3997b1008b780f1f07 55546532 chromium-headless-shell_140.0.7339.80-1~deb12u1_i386.deb 7b53c49239772db29c70c6c329966b4196335fec 18088 chromium-sandbox-dbgsym_140.0.7339.80-1~deb12u1_i386.deb c5b864019640bb0a6a9a347a1213c9fd4b0f741b 106412 chromium-sandbox_140.0.7339.80-1~deb12u1_i386.deb eceddffe45ef851d21d715aa40a4781445fcda0b 30119504 chromium-shell-dbgsym_140.0.7339.80-1~deb12u1_i386.deb 56eebfe2ede52121e61faba6fc57f0cddefad989 60223840 chromium-shell_140.0.7339.80-1~deb12u1_i386.deb d98897e9a6ff7cd53e84172e3df0550979f717ce 30292 chromium_140.0.7339.80-1~deb12u1_i386-buildd.buildinfo 1e67a5515864502885ecb94392b0fb393a3ddcad 72092000 chromium_140.0.7339.80-1~deb12u1_i386.deb Checksums-Sha256: 9f0e28be88138cca68a8690e4312de4dcd9c0fbfd145dcc3940a983faa717724 5084624 chromium-common-dbgsym_140.0.7339.80-1~deb12u1_i386.deb 24853561f6481011d4b2dd1cea3b5bf515114d85c80e2c158b2370ed5bcc92c0 22375396 chromium-common_140.0.7339.80-1~deb12u1_i386.deb 86a78929cf37a43c040652498fb8a979fd9fac2cdad21929c0ab2e8b79de490d 33737040 chromium-dbgsym_140.0.7339.80-1~deb12u1_i386.deb 80b5e549e7bec212dac7de9687bfc733fe3aa7fdd3fa93d41319720af1e888de 7932972 chromium-driver_140.0.7339.80-1~deb12u1_i386.deb 7d98f380f435cada40115e857c6fd1d6dda1ae9733cce5d2bba859a8d0ac370d 28043156 chromium-headless-shell-dbgsym_140.0.7339.80-1~deb12u1_i386.deb 8c5b0ac40807be32aa41058657fc2f3b93ad09a2440f222e3a0d0b34f70a15db 55546532 chromium-headless-shell_140.0.7339.80-1~deb12u1_i386.deb f50db40f09653977719d5e97f9d7275e075c169c9ef0b8fe233750264a23f1ed 18088 chromium-sandbox-dbgsym_140.0.7339.80-1~deb12u1_i386.deb 3f50115d7e316ac483340c8da07ca69cffdcb77349d67da638e517c13e12b093 106412 chromium-sandbox_140.0.7339.80-1~deb12u1_i386.deb 937e206cc326e1e0d747120aad690abcb823ba6c179813862fff89c33880f026 30119504 chromium-shell-dbgsym_140.0.7339.80-1~deb12u1_i386.deb 5a0c62ab0ffc98e90359f2bfe038ea25e0359ff56964700b302a913b79aa15f4 60223840 chromium-shell_140.0.7339.80-1~deb12u1_i386.deb 400d2605d83b152fd108d64808fa88e957584255bb0e96506b17ace06c10d1b6 30292 chromium_140.0.7339.80-1~deb12u1_i386-buildd.buildinfo 97e60ab8eacc1cb654e36a9cd2db452fc49962bb87532400c12242201cc6d326 72092000 chromium_140.0.7339.80-1~deb12u1_i386.deb Files: 7dfd6e745deb1fc6b52e2fe4951922df 5084624 debug optional chromium-common-dbgsym_140.0.7339.80-1~deb12u1_i386.deb 567158b3753ad453e5d0344e06fcaf4f 22375396 web optional chromium-common_140.0.7339.80-1~deb12u1_i386.deb ff89ee14e8548f7eef19b646d1fad11a 33737040 debug optional chromium-dbgsym_140.0.7339.80-1~deb12u1_i386.deb 56b42a7623aac76b388a948cf6a3ff77 7932972 web optional chromium-driver_140.0.7339.80-1~deb12u1_i386.deb a73fa35541cf2b2d8ef0d63ade7f44d7 28043156 debug optional chromium-headless-shell-dbgsym_140.0.7339.80-1~deb12u1_i386.deb 993036f9d4cf221671df3e72eb059d2d 55546532 web optional chromium-headless-shell_140.0.7339.80-1~deb12u1_i386.deb 9fabc83a399a440548bf15ba711cfcb7 18088 debug optional chromium-sandbox-dbgsym_140.0.7339.80-1~deb12u1_i386.deb e9c20835c34fc41185f8613b3661bd8a 106412 web optional chromium-sandbox_140.0.7339.80-1~deb12u1_i386.deb a5ebea2c93d94f74f512ca3312edbea9 30119504 debug optional chromium-shell-dbgsym_140.0.7339.80-1~deb12u1_i386.deb d352d16b26627535b7eeda61566f217f 60223840 web optional chromium-shell_140.0.7339.80-1~deb12u1_i386.deb cfcd9844a043ac6ab4f756e33d9b6cee 30292 web optional chromium_140.0.7339.80-1~deb12u1_i386-buildd.buildinfo 5881959a91c7b2bf78c442ace6802b20 72092000 web optional chromium_140.0.7339.80-1~deb12u1_i386.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEv2qEY4xQXyY/2dWIvGw9w6VrLCcFAmi7Eu4ACgkQvGw9w6Vr LCfRGA/+K86B7pg3ekxxmsOBNneP1+dvDfPvNuJOR1mtw08Gp+gUgXYmIalYwEnD UmsqD721i6xh18QTL95HZ1jQsMKGV4X1aX6oIWKOO8oPQ395h0rfuAm5d3V53ltg 5gKK/oD1zO7EnWY1VU8v5Kidu5vGmC4Q+0HwmuaAyZJdQyNMsRyl20Z5MLTKB7NS KLw51TlmnbdCYG1YbwVPHrLP0BE2d3LewTeTLmfHiqLwZiMMNzUoeeqvu31ES59G kRF//1NFjvswhuytsTTIuJBzbIl5ttZHaveb2jPp1/v1Duyx6Q/iXuS0Ag2Fm8wG 9zOu4LsIphaZOKb+Qg0Y3D46jbG+ZfgAnPzVA3gLV9/4oHAoMOtGlsnR3+LUNzNK C1S1bO6l1QC+uu5tyeWfA0lkiiNP/sFCURTRxCAO5ZUSvqox5BQv9wKN0HuD9Ud9 sLckXxm4st83ny3dvMK5VNEsA6MKu/NDCP/bTbHFNaHEyk9lrWQr0ha9Tv9EHEHs RkYBB3jJaNlmbASJwnFxMG9m3vIA6jdyvvd7UAKenF/y0apzwx8HYP9sUOFZxGFf kCR85OLCS4KnZfIVawup1iixMEUm8Z/nKchagidYslmDQqm7jEF/BSWnYEymqqqY ACuJHgxIY5X6Q/CgfOHuCXEelCTg+C7UxkuRGemnGs8jlbRFlJ4= =Dq4K -----END PGP SIGNATURE-----