-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Thu, 04 Sep 2025 16:47:14 -0400 Source: chromium Binary: chromium chromium-common chromium-common-dbgsym chromium-dbgsym chromium-driver chromium-headless-shell chromium-headless-shell-dbgsym chromium-sandbox chromium-sandbox-dbgsym chromium-shell chromium-shell-dbgsym Architecture: arm64 Version: 140.0.7339.80-1~deb12u1 Distribution: bookworm-security Urgency: medium Maintainer: arm Build Daemon (arm-conova-02) Changed-By: Andres Salomon Description: chromium - web browser chromium-common - web browser - common resources used by the chromium packages chromium-driver - web browser - WebDriver support chromium-headless-shell - web browser - old headless shell chromium-sandbox - web browser - setuid security sandbox for chromium chromium-shell - web browser - minimal shell Changes: chromium (140.0.7339.80-1~deb12u1) bookworm-security; urgency=medium . * New upstream stable release. - CVE-2025-9864: Use after free in V8. Reported by Pavel Kuzmin of Yandex Security Team. - CVE-2025-9865: Inappropriate implementation in Toolbar. Reported by Khalil Zhani. - CVE-2025-9866: Inappropriate implementation in Extensions. Reported by NDevTK. - CVE-2025-9867: Inappropriate implementation in Downloads. Reported by Farras Givari. * d/patches: - fixes/armhf-icf.patch: refresh. - disable/tests.patch: refresh. - disable/catapult.patch: refresh. - disable/widevine-cdm-cu.patch: refresh (and make it shorter). - bookworm/clang19.patch: refresh. - disable/android.patch: delete a new reference to chrome/android/. - disable/buildtools-libc.patch: drop due to upstream cleanups. - trixie/rust-no-alloc-shim.patch: add a build fix for older rustc. - bookworm/rust-visibility.patch: drop, not needed w/ new rust 1.85. - bookworm/crabbyav1f.patch: drop, not needed w/ new rust 1.85. - bookworm/toktrie-utf8chunks.patch: drop, not needed w/ new rust. - bookworm/derivre-create.patch: drop, not needed w/ new rust. - bookworm/rust-split-at-checked.patch: drop, not needed w/ new rust. - bookworm/crabbyav1f-macro-scope.patch: drop, not needed w/ new rust. - bookworm/rust-box-to-vec.patch: drop, not needed w/ new rust. . [ Timothy Pearson ] * d/patches/ppc64le: - third_party/0002-regenerate-xnn-buildgn.patch: Refresh for upstream changes - fixes/fix-study-crash.patch: Refresh for upstream changes - core/add-ppc64-architecture-to-extensions.diff: Refresh for upstream changes - fixes/fix-unknown-warning-option-messages.diff: Refresh for upstream changes - libaom/0001-Add-pregenerated-config-for-libaom-on-ppc64.patch: Regenerate from new upstream version - third_party/0003-third_party-ffmpeg-Add-ppc64-generated-config.patch: Regenerate from new upstream version Checksums-Sha1: c9f31f40338e45aba0958a7e6241bf6198d440a0 6158648 chromium-common-dbgsym_140.0.7339.80-1~deb12u1_arm64.deb 5ee5bc0f2cb8a9160ba5bb4aa340218428120497 27264408 chromium-common_140.0.7339.80-1~deb12u1_arm64.deb 989a6ab7e6fdfee2bf6d0f38f4e281c7b1afd37f 34240564 chromium-dbgsym_140.0.7339.80-1~deb12u1_arm64.deb 38afae211d175901d1e1cb17728c33906f98e4f5 6889524 chromium-driver_140.0.7339.80-1~deb12u1_arm64.deb 53754928bd91e0fa5b26bcc19fd5d57333cfb828 27895868 chromium-headless-shell-dbgsym_140.0.7339.80-1~deb12u1_arm64.deb 7209a58f220e776053f602fcd81877e22d92735d 48171812 chromium-headless-shell_140.0.7339.80-1~deb12u1_arm64.deb 22df0ce6dec1a3071cc748093f70442179f3b450 20652 chromium-sandbox-dbgsym_140.0.7339.80-1~deb12u1_arm64.deb dc88e7e591bde89b802397e4cea61b2a5a4c70db 107228 chromium-sandbox_140.0.7339.80-1~deb12u1_arm64.deb 7e726ccdf114ec937a1844173589c6bf87be7ba6 30049904 chromium-shell-dbgsym_140.0.7339.80-1~deb12u1_arm64.deb f49d5248e178a73e3ee8063224d87d89b4e5551c 52285216 chromium-shell_140.0.7339.80-1~deb12u1_arm64.deb eacaba515289abd68a9f90e94bd4724d146cfcbe 30259 chromium_140.0.7339.80-1~deb12u1_arm64-buildd.buildinfo b324287a26d54bc39b459e34d8672d867c46b7d1 61440100 chromium_140.0.7339.80-1~deb12u1_arm64.deb Checksums-Sha256: 5e205e3917e00292f9836a9197de37b07e027861617f4b9d133633d2b7af72e3 6158648 chromium-common-dbgsym_140.0.7339.80-1~deb12u1_arm64.deb 8a302ba1fc46902cfe7153684151b3b5a5843058b769aa64f31191c43bdd202f 27264408 chromium-common_140.0.7339.80-1~deb12u1_arm64.deb 0327f5ab82a20c640bd50f3a956b97261b55973f1ca29767e8fbdaf2ef2a133b 34240564 chromium-dbgsym_140.0.7339.80-1~deb12u1_arm64.deb 92fa1a3b5babaa0bdfa6b92379bbac2d3a619c23a157a8ee2f9cdfb81dd49ff4 6889524 chromium-driver_140.0.7339.80-1~deb12u1_arm64.deb e433b2efe73fc6d7221d874a2f2e058e2e8a5b194f381c1c5c8a32dcd3dd9adc 27895868 chromium-headless-shell-dbgsym_140.0.7339.80-1~deb12u1_arm64.deb e21927c5b3fc24c05a10a0c162e154001d41d794158fe505334872147102bbbf 48171812 chromium-headless-shell_140.0.7339.80-1~deb12u1_arm64.deb 9ea834dc7453e62945d60d962d2536fbb72485bdd87a6c79689b5384d45b493d 20652 chromium-sandbox-dbgsym_140.0.7339.80-1~deb12u1_arm64.deb cc4b08d8671b1e12bacab0f53e6d44fbc5c4e58770081d9ea1fa68d45b5db008 107228 chromium-sandbox_140.0.7339.80-1~deb12u1_arm64.deb 121aa2319b0e4841e93541cc82310c3a698ca3cb350c06f770590486bfaa0be1 30049904 chromium-shell-dbgsym_140.0.7339.80-1~deb12u1_arm64.deb 21190c74a57091e9c44f22274c02d157d942aefa17341df4320f27db5f1e0baf 52285216 chromium-shell_140.0.7339.80-1~deb12u1_arm64.deb 0103388fed80ca6f92371d43561975f1886c1af23b91e22c70a5bcc4c545008f 30259 chromium_140.0.7339.80-1~deb12u1_arm64-buildd.buildinfo 1144815800135f9281ac8dbabd94245238b5dc4c4038cbac01e8f0a0a73f15a6 61440100 chromium_140.0.7339.80-1~deb12u1_arm64.deb Files: 07795c535faa35811ca139674c96bd37 6158648 debug optional chromium-common-dbgsym_140.0.7339.80-1~deb12u1_arm64.deb 7264e5a9cb2bf5a86efcd53aa9e49184 27264408 web optional chromium-common_140.0.7339.80-1~deb12u1_arm64.deb 5fb0c2be372a7b1bfe519d171b37ea27 34240564 debug optional chromium-dbgsym_140.0.7339.80-1~deb12u1_arm64.deb 8fc1fbf86090bf8223bb80888925dc29 6889524 web optional chromium-driver_140.0.7339.80-1~deb12u1_arm64.deb 069a807f7568fb0fc349b630aa086b44 27895868 debug optional chromium-headless-shell-dbgsym_140.0.7339.80-1~deb12u1_arm64.deb c19438f5b8413512f675bea4c907f11f 48171812 web optional chromium-headless-shell_140.0.7339.80-1~deb12u1_arm64.deb 3d5707e8a189a66330f097d07dd65ce7 20652 debug optional chromium-sandbox-dbgsym_140.0.7339.80-1~deb12u1_arm64.deb 60bc4b6481be291dc661c8cfa193cc6e 107228 web optional chromium-sandbox_140.0.7339.80-1~deb12u1_arm64.deb 20bfd003e52fcc04e678ba7c95613786 30049904 debug optional chromium-shell-dbgsym_140.0.7339.80-1~deb12u1_arm64.deb 863ebdec91f05861446a93209d9ee4a6 52285216 web optional chromium-shell_140.0.7339.80-1~deb12u1_arm64.deb e7a18991fc3e14543e28a2572086fbac 30259 web optional chromium_140.0.7339.80-1~deb12u1_arm64-buildd.buildinfo c80ec972e139e42e8b76489e2e9e3afb 61440100 web optional chromium_140.0.7339.80-1~deb12u1_arm64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEWHj9K9pO9l4btbD1OQKMdMnEH5MFAmi7BnYACgkQOQKMdMnE H5MmnBAAqS1igMu+p5jvR7BlkAzROMvxwiAOqEE76Bd1uAHD0QcUjOAU73WWUQ1h DrtZNfGgcpqXtciEKSYJy9GY16F3K1mUYg2HbcXmVtJ6RtTH5d+0AeQo4+SZ/2OW fAjYawvOEvh+lx5SEmGihTzDkTDwEN224lOMGUJmM4L60RNeFVXVrIZ+1GJRRLtH h/0GySfp8m0IFdqK4bEUDRTpAl7f/pQzfANB5LJ4QeuK4oGtXboapBm3Dhzq1sEr 00/YgtbbFh7DDZ35BGVeKQPkTSIhHy7fj/EU6RqoZIidnfmi+Blooday1SRS7/e0 TPcmekGEt5f369ZIYWtElKvXmTcMe7rcQyPQtg8Pm/sleOyRCve/SMGejOHVybav /e7nb1U/ew/KyblfXzrhhhHpNMfpvXeKhd/FWihynb9Ge4MFhcVNDbL3rh6eCGLg xdH8VJcj0c+s3dlxbagPRtIkWe2vD4g0JMR8774DUxcbMUlhKRB50fGisgSjY3r5 wnuW43ZfnIrNhYiqghkXDJ/6MyOgNBEKCLk72tRJ0ULfGV2Dk4imT/B21bz6pFBL rm1EKAZtePXc0iR6nxqpmjnNiPM/hlDQHM7cyiIlKfUb9JxFiuO8m0Tfm2Of2ud9 KHOiaEBh44SHkzl62X5yEeKu5FvGU+L4HhRRVSWH9FPCj1P1OzU= =+Ga5 -----END PGP SIGNATURE-----