-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 06 May 2025 14:13:50 -0400 Source: chromium Binary: chromium chromium-common chromium-common-dbgsym chromium-dbgsym chromium-driver chromium-headless-shell chromium-headless-shell-dbgsym chromium-sandbox chromium-sandbox-dbgsym chromium-shell chromium-shell-dbgsym Architecture: amd64 Version: 136.0.7103.92-1~deb12u1 Distribution: bookworm-security Urgency: high Maintainer: amd64 / i386 Build Daemon (x86-ubc-01) Changed-By: Andres Salomon Description: chromium - web browser chromium-common - web browser - common resources used by the chromium packages chromium-driver - web browser - WebDriver support chromium-headless-shell - web browser - old headless shell chromium-sandbox - web browser - setuid security sandbox for chromium chromium-shell - web browser - minimal shell Changes: chromium (136.0.7103.92-1~deb12u1) bookworm-security; urgency=high . [ Andres Salomon ] * New upstream security release. - CVE-2025-4372: Use after free in WebAudio. Reported by Huang Xilin of Ant Group Light-Year Security Lab. . [ Daniel Richard G. ] * d/patches/fixes/armhf-no-thumb.patch: Fix armhf FTBFS due to use of a Rust target (thumbv7neon) that Debian does not ship. Checksums-Sha1: fb7babb54c7cc590cec27997fc215f8d5b4ba990 4760928 chromium-common-dbgsym_136.0.7103.92-1~deb12u1_amd64.deb 51cd621a1fc53133c8504b204cab6c2266525fe4 21145728 chromium-common_136.0.7103.92-1~deb12u1_amd64.deb e0da2588a50a896f3fb3e16b67adf8737031ddad 30327356 chromium-dbgsym_136.0.7103.92-1~deb12u1_amd64.deb 3ba9bb0c358af4a1a3a8905e1197184cbd558b17 7528500 chromium-driver_136.0.7103.92-1~deb12u1_amd64.deb df04e4cfa9e78a0bdcb7eb66666fb681c32108f9 25978056 chromium-headless-shell-dbgsym_136.0.7103.92-1~deb12u1_amd64.deb 3c026cc7b247fc8efd00841ab13a14f8ef5b474d 58581812 chromium-headless-shell_136.0.7103.92-1~deb12u1_amd64.deb 5b0929e10f433261d2f262683687f0f74dd67c9b 14076 chromium-sandbox-dbgsym_136.0.7103.92-1~deb12u1_amd64.deb c7748ed6cfd93400586e6b1364d52faaec5dd18b 103008 chromium-sandbox_136.0.7103.92-1~deb12u1_amd64.deb be825b1514d4bf75877c4dc625c6b19b87537d69 25254424 chromium-shell-dbgsym_136.0.7103.92-1~deb12u1_amd64.deb d368602e56d8a4fadeed72c352593250478d0a23 54049264 chromium-shell_136.0.7103.92-1~deb12u1_amd64.deb 7c5c9945c52fdc34077219cf11482c0375740f0c 30089 chromium_136.0.7103.92-1~deb12u1_amd64-buildd.buildinfo ab0ca35503613a625467ea8b0fba428c952aa416 78615960 chromium_136.0.7103.92-1~deb12u1_amd64.deb Checksums-Sha256: f948ac5aad74d56918eef624c5a7507de2a659bf50614ede88e1b574ff7df87b 4760928 chromium-common-dbgsym_136.0.7103.92-1~deb12u1_amd64.deb b5ec66fc8b98bd868e187b9041e63cb2bcda5d48032681630fab985be93ea0cb 21145728 chromium-common_136.0.7103.92-1~deb12u1_amd64.deb f5109948fd3730c2ceb0179a5fd4e52458b9686b6177ba710de1ef8e1d90b4a4 30327356 chromium-dbgsym_136.0.7103.92-1~deb12u1_amd64.deb ccb2d91972c68bae19ddedd0f596b13cb29ef7c9abc52867ed987782b8624490 7528500 chromium-driver_136.0.7103.92-1~deb12u1_amd64.deb 78fe92a31f126753649b66f1dd8f3e680cf66fc34db78a261cb7cc8eae62494f 25978056 chromium-headless-shell-dbgsym_136.0.7103.92-1~deb12u1_amd64.deb df549bdf827660d356f820001f7de38913faea0a46a39a698f069b7e79376543 58581812 chromium-headless-shell_136.0.7103.92-1~deb12u1_amd64.deb 51fac1e0f87bd223aaea5a1a4342bea66b684faeddba7558a79fb195e4673c9f 14076 chromium-sandbox-dbgsym_136.0.7103.92-1~deb12u1_amd64.deb 7bf75331e3de33f7f691547efd8cf8d26153fa62daa1259cb90750cd0dac8a35 103008 chromium-sandbox_136.0.7103.92-1~deb12u1_amd64.deb 21e7dd7250705ed43449615a745f3a6acb86be76cc3fbbb5762667ccc6f8c56b 25254424 chromium-shell-dbgsym_136.0.7103.92-1~deb12u1_amd64.deb 2dfe37cef6c9b6c1cd3ef2f7f8ed825a405019085c6ce256deb360dcebe130ee 54049264 chromium-shell_136.0.7103.92-1~deb12u1_amd64.deb 1639f253586094a94fbc53bdb86fd504f7ae9aaab537836807887749906b9dac 30089 chromium_136.0.7103.92-1~deb12u1_amd64-buildd.buildinfo 1ebd0eadc0df0d1826549e9ba6c542fd01e321a3223adece0bdddb598a271614 78615960 chromium_136.0.7103.92-1~deb12u1_amd64.deb Files: b6fab060b54cf3645cbcb05d80854c28 4760928 debug optional chromium-common-dbgsym_136.0.7103.92-1~deb12u1_amd64.deb 687d83869e6bf21dcea65a1bd2c4b139 21145728 web optional chromium-common_136.0.7103.92-1~deb12u1_amd64.deb 45e7e1e941981920f6d35ee2e49da2a5 30327356 debug optional chromium-dbgsym_136.0.7103.92-1~deb12u1_amd64.deb 70df31bfc2f9e44e164613fee3db3d15 7528500 web optional chromium-driver_136.0.7103.92-1~deb12u1_amd64.deb c580c938cd994aed78c5955ea8fc4145 25978056 debug optional chromium-headless-shell-dbgsym_136.0.7103.92-1~deb12u1_amd64.deb db33c4eb215a9d4861e6602198899350 58581812 web optional chromium-headless-shell_136.0.7103.92-1~deb12u1_amd64.deb f5edecd5dc4402bb6333a920bce3f4fa 14076 debug optional chromium-sandbox-dbgsym_136.0.7103.92-1~deb12u1_amd64.deb 634e87dde31787a9f6b299383f08d929 103008 web optional chromium-sandbox_136.0.7103.92-1~deb12u1_amd64.deb ebf0998bedec17c5fa471c262f78809b 25254424 debug optional chromium-shell-dbgsym_136.0.7103.92-1~deb12u1_amd64.deb 5c2f480ad8274a12b312e96bbce9451e 54049264 web optional chromium-shell_136.0.7103.92-1~deb12u1_amd64.deb 8a28d1ebe515257283960ffa2a8f89a7 30089 web optional chromium_136.0.7103.92-1~deb12u1_amd64-buildd.buildinfo 536949a67234aea9a26839a5d7a5d099 78615960 web optional chromium_136.0.7103.92-1~deb12u1_amd64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEnw0rdzqckKx6dwRTEbCLukZn24oFAmgbW7oACgkQEbCLukZn 24p7Ow/7BEWbxCwFlwDQIpCS/LnSJWFvPgAEZiypKHDKxcX2ozqnFae0Vzoix6Dw 193LeWZiGPM5ALdMPb5WM3MKpMEzJwVtfQ2KObuYTcvlcjIXPUG7pWkHEJbpCwsp Ms9EwbaofhKOCuNnAOqDhmIAXS3wHaHnJpitgcYgl9g2GDg+TFrMxgH+SE1q0Vla p5t7GGSjNltTY2lelJfI2r8fvv+7krOLEBzjUuTUxwtjtF1huKG/VTfZEbjARgKr SbUkoJyiVcOmtT/Fmo0je7wqPnBBtbOIPBozIwhRTv5cePtI21f/WYk5/7TReKFC VsuEyQpdpI4HHxfiIRWkqANs+i28gfRtaVTPMNWpFbEpkUT74F8K6d3FmbTcVSj0 o601oxrZDEDVziJr6tNy+TgERd9KiuoWGIDyfgkxu17QBeHeBHVIe84XBBvTfgLm NYTJo77h6SqNTXx4+4+Rv4tkPv0JLmswL6xxpj80uSp7Re+cQ4xV9VpMnuD5mtcO gmA7ny3avIylHU91wD6kLC0MSVQHMQ1xOERiWzFhsqpp1cvvQkZvcGYnY9vpVZr7 w4T1l7/KRck95iCqxogHD9GbyZygnLP8mtc4/B2I5ncl4ePkFThZ3wzWd/OPKaiZ 2KTusTCHQDcF3p+mxPqGvfcVKE8kCRj2naQxS4hUyJGpmEQk9zw= =cNzr -----END PGP SIGNATURE-----