-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 03 Dec 2025 01:54:50 -0500 Source: chromium Binary: chromium chromium-common chromium-common-dbgsym chromium-dbgsym chromium-driver chromium-headless-shell chromium-headless-shell-dbgsym chromium-sandbox chromium-sandbox-dbgsym chromium-shell chromium-shell-dbgsym Architecture: ppc64el Version: 143.0.7499.40-1~deb12u1 Distribution: bookworm-security Urgency: high Maintainer: ppc64el Build Daemon (ppc64el-conova-02) Changed-By: Andres Salomon Description: chromium - web browser chromium-common - web browser - common resources used by the chromium packages chromium-driver - web browser - WebDriver support chromium-headless-shell - web browser - old headless shell chromium-sandbox - web browser - setuid security sandbox for chromium chromium-shell - web browser - minimal shell Changes: chromium (143.0.7499.40-1~deb12u1) bookworm-security; urgency=high . * New upstream stable release. - CVE-2025-13630: Type Confusion in V8. Reported by Shreyas Penkar (@streypaws). - CVE-2025-13631: Inappropriate implementation in Google Updater. Reported by Jota Domingos. - CVE-2025-13632: Inappropriate implementation in DevTools. Reported by Leandro Teles. - CVE-2025-13633: Use after free in Digital Credentials. Reported by Chrome. - CVE-2025-13634: Inappropriate implementation in Downloads. Reported by Eric Lawrence of Microsoft. - CVE-2025-13720: Bad cast in Loader. Reported by Chrome. - CVE-2025-13721: Race in v8. Reported by Chrome. - CVE-2025-13635: Inappropriate implementation in Downloads. Reported by Hafiizh. - CVE-2025-13636: Inappropriate implementation in Split View. Reported by Khalil Zhani. - CVE-2025-13637: Inappropriate implementation in Downloads. Reported by Hafiizh. - CVE-2025-13638: Use after free in Media Stream. Reported by sherkito. - CVE-2025-13639: Inappropriate implementation in WebRTC. Reported by Philipp Hancke. - CVE-2025-13640: Inappropriate implementation in Passwords. Reported by Anonymous. * d/patches: - fixes/headless-gn.patch: refresh. - fixes/chromium-142-iwyu-field-form-data.patch: drop, merged upstream. - disable/tests.patch: refresh. - ungoogled/disable-privacy-sandbox.patch: sync from upstream. - fixes/libpng-testonly.patch: add a workaround for a missing build target that upstream forgot to include. - trixie/rust-no-alloc-shim.patch: mark nightly feature 'no_mangle' as unsafe to make rustc happy. - trixie/cookie-string-view.patch: add a workaround for missing clang-19 feature. . [ Daniel Richard G. ] * d/patches: - debianization/cross-build.patch: Avoid "Assignment had no effect" error from GN when running outside of d/rules. - debianization/rustc-bootstrap.patch: Move RUSTC_BOOTSTRAP=1 here. - disable/license-headless-shell.patch: Don't generate the (unused) LICENSE.headless_shell file, as the rule tends to break easily. - fixes/headless-gn.patch: No longer needed, thanks to previous patch. - trixie/rust-is-multiple-of.patch: add more workarounds for missing rustc features. - bookworm/constexpr.patch: Refresh (source file moved). - bookworm/gn-absl.patch: Refresh. - bookworm/gn-path-exists2.patch: Refresh. - bookworm/rust-unsafe-extern.patch: add workaround for older rust code convention generated by bookworm's version of rust-bindgen. - bookworm/node-esm-dirname.patch: add workaround for older node 18. * d/rules: Move RUSTC_BOOTSTRAP=1 environment setting into patch. . [ Timothy Pearson ] * d/patches/ppc64le: - ppc64le/third_party/0002-regenerate-xnn-buildgn.patch: Regenerate from upstream sources - ppc64le/fixes/fix-clang-selection.patch: Refresh for upstream changes Checksums-Sha1: dac088bc17c1bc58d0c01de63e15f026329a623a 5902432 chromium-common-dbgsym_143.0.7499.40-1~deb12u1_ppc64el.deb 1fe0d2f5253b4b2d22e5eb593cbf297d9b9f977e 29791960 chromium-common_143.0.7499.40-1~deb12u1_ppc64el.deb 5d8b1f5e9fe9f9643fbacfcb1fdfbf86a2c8b566 30403232 chromium-dbgsym_143.0.7499.40-1~deb12u1_ppc64el.deb 1faeaf765288e9abfd161d528bc88baa2ef62833 7469212 chromium-driver_143.0.7499.40-1~deb12u1_ppc64el.deb b68b071403f259dde2028d598c183b213c4bff89 24236612 chromium-headless-shell-dbgsym_143.0.7499.40-1~deb12u1_ppc64el.deb c6e1624fa01923f29505f4684bc645f9e91cee5a 53538628 chromium-headless-shell_143.0.7499.40-1~deb12u1_ppc64el.deb cf34634bdb324e5ca760b809aabb38bf105fc6f6 19252 chromium-sandbox-dbgsym_143.0.7499.40-1~deb12u1_ppc64el.deb 4af8f4ad0e445afd0f4ffca9590a85a38821716f 108820 chromium-sandbox_143.0.7499.40-1~deb12u1_ppc64el.deb d7ae83bf86ee2e217878ed26497bd94f2b5bceba 26319832 chromium-shell-dbgsym_143.0.7499.40-1~deb12u1_ppc64el.deb 0e22229da89510f4225b52bec2a9eab7a0164857 58406236 chromium-shell_143.0.7499.40-1~deb12u1_ppc64el.deb 18da1d9996bd70a7affc85de9679306cbd549cdf 30243 chromium_143.0.7499.40-1~deb12u1_ppc64el-buildd.buildinfo 784419aed7a64dba3fe3c9a5f386ee149992cab1 70249016 chromium_143.0.7499.40-1~deb12u1_ppc64el.deb Checksums-Sha256: 59ce0f227c310de1ba612c69a46be210fd9f61169743f5dd6d68704f7e32ef87 5902432 chromium-common-dbgsym_143.0.7499.40-1~deb12u1_ppc64el.deb 2de859c4b6774a405f1b59dd00ae689d5b279e5f5c8d3062a16aed78ec16c9aa 29791960 chromium-common_143.0.7499.40-1~deb12u1_ppc64el.deb 0289e5730577d704ff6a6059b8a4dc1ab5915de6bb7bbbf77dbaee95d8283f85 30403232 chromium-dbgsym_143.0.7499.40-1~deb12u1_ppc64el.deb bedc378b0a2aa4d13169bf884f8f7421151a006a91df588b9ca84afc6fc157bd 7469212 chromium-driver_143.0.7499.40-1~deb12u1_ppc64el.deb 5e4af6bf2103f7645563047f3c665c59fdf088917c56f061ee618c3cfd16e6cc 24236612 chromium-headless-shell-dbgsym_143.0.7499.40-1~deb12u1_ppc64el.deb c1839a29f98060d573d677d6dd596ec5eccf48b8063bce7f17bdb0829a994530 53538628 chromium-headless-shell_143.0.7499.40-1~deb12u1_ppc64el.deb 30838ed60adf8a383b1d9f94e88d5df31ff1fe54557742c2103012314bd66b09 19252 chromium-sandbox-dbgsym_143.0.7499.40-1~deb12u1_ppc64el.deb da9244ce3101fade3eb41288e1a9948d4a0cc357540001b89febd8ac8422412c 108820 chromium-sandbox_143.0.7499.40-1~deb12u1_ppc64el.deb 79f6ce2704e4a14bef1a92fd6ead0d15a56148242e9a58c2d50ae37d117077b3 26319832 chromium-shell-dbgsym_143.0.7499.40-1~deb12u1_ppc64el.deb c52fa4262c49c07a69a191a7f016d44330ddd1c1b8a5071ded75dd54628c2d1a 58406236 chromium-shell_143.0.7499.40-1~deb12u1_ppc64el.deb 12033272153659814fe6447d0242b0237e17c1745360d84fd6fdb47161fad505 30243 chromium_143.0.7499.40-1~deb12u1_ppc64el-buildd.buildinfo 3757321c6400e99bedd650ea05dbbd7db383141d1d56301c28ad24599247cbad 70249016 chromium_143.0.7499.40-1~deb12u1_ppc64el.deb Files: 473879c4e1e01e18e94f5cc05ca21401 5902432 debug optional chromium-common-dbgsym_143.0.7499.40-1~deb12u1_ppc64el.deb 37f3abdf891b5a51b678e8fcbc963bdf 29791960 web optional chromium-common_143.0.7499.40-1~deb12u1_ppc64el.deb bf94372bd0a984a6ccee07bf40d809d4 30403232 debug optional chromium-dbgsym_143.0.7499.40-1~deb12u1_ppc64el.deb 44c2ee1815b1a02e1ae418746626b248 7469212 web optional chromium-driver_143.0.7499.40-1~deb12u1_ppc64el.deb e3d28bdf512f7488d38b6d1282fea3ff 24236612 debug optional chromium-headless-shell-dbgsym_143.0.7499.40-1~deb12u1_ppc64el.deb 3277cc2fc61636b49a720617febb5b5e 53538628 web optional chromium-headless-shell_143.0.7499.40-1~deb12u1_ppc64el.deb e067e75e8d7241342fc4bfe5a0805e9d 19252 debug optional chromium-sandbox-dbgsym_143.0.7499.40-1~deb12u1_ppc64el.deb d711ede98240caa72edf31dd9e1ee263 108820 web optional chromium-sandbox_143.0.7499.40-1~deb12u1_ppc64el.deb 81e8f4d197b7780dbc058dae72319fcb 26319832 debug optional chromium-shell-dbgsym_143.0.7499.40-1~deb12u1_ppc64el.deb fbd301f463695a51f657552208b4fba9 58406236 web optional chromium-shell_143.0.7499.40-1~deb12u1_ppc64el.deb 71085e19aeadf7fe464a35a3ee076937 30243 web optional chromium_143.0.7499.40-1~deb12u1_ppc64el-buildd.buildinfo adf9bcc58c3f772c9f83584d9adb5a99 70249016 web optional chromium_143.0.7499.40-1~deb12u1_ppc64el.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEZAv/jpGRqS40qyb11oy1TpxF0ZAFAmkxjAIACgkQ1oy1TpxF 0ZAufQ//bC8R1z8B/qpy3YKvy3jOJryJpZUhqEPiycLl1h3quCfkkmhQIHT8BeTi /5lMrYAL0vVtvLrOSuep2eFA59Y4khNzHFFCmkCJ6D1yMQfd9Psr9LhQsTIcHacd PA+a7dVX0hlsx2IVc/3vPdM73E2rDjOUdCok3gRgI4CnzAPSyaKy7OcfKuA8ik4o 7IlL0C/6I3WV72XCvTeRJsoxUGfjWrHs80Ga/Q/lxoKd3eJt/A1iWOTHjKtrA/g/ vyMXdjQlnsX1y3ie2NLVkODgDAqJHSj5Dl6rCsjBrXtKCznHwqoyUf0UXrUOIDmp U3enPu34BnDYqqXFKU3XW1cwo1DBe8KD8ElM2fs5EfI7hMF0jXCCXkK7F4dV2+ZO y+dur4OKemMVtp7vKYH+n/C4Q5ODiG9V28zbbFRFAqaVEx4o/i9NRuNIO2kQuJNy jJcnQQf6J3GoAl/jMUG+BT4CH0JWnvfhz03ziuT1zrEt78stbtj5Q/ryjR5MU2F9 mkIOZFxTSSRNS41ApBUFWrJvQS/OWqXuqjk1/pTDo+mi04pJL0kmoqequlXNkqwB q7wlIrKPXLwhRqW6z2GBO2/yl/Aek2tHgIQkDeWSInglHBdnlmk7aGhpEaCiVCJQ cuXrBlF6yqG6kUNf7XRpIquhQKnS6FFFvKuJEi2yRDNcSfL1QaU= =RPEo -----END PGP SIGNATURE-----