-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
Format: 1.8
Date: Tue, 10 Jun 2025 15:08:42 -0400
Source: chromium
Architecture: source
Version: 137.0.7151.103-1
Distribution: unstable
Urgency: high
Maintainer: Debian Chromium Team <
chromium@packages.debian.org>
Changed-By: Andres Salomon <
dilinger@debian.org>
Changes:
chromium (137.0.7151.103-1) unstable; urgency=high
.
* New upstream security release.
- CVE-2025-5958: Use after free in Media.
Reported by Huang Xilin of Ant Group Light-Year Security Lab.
- CVE-2025-5959: Type Confusion in V8.
Reported by Seunghyun Lee as part of TyphoonPWN 2025.
* Add build-dep on libc++-19-dev and switch to building statically
against clang's libc++ (instead of gcc's libstdc++).
* d/patches:
- fixes/absl-optional.patch: drop, only needed for libstdc++.
- fixes/font-gc-asan.patch: drop, only needed for libstdc++.
- fixes/stdatomic.patch: drop, only needed for libstdc++.
- fixes/make-pair.patch: drop, only needed for libstdc++.
- bookworm/constflatset.patch: drop, only needed for libstdc++.
- bookworm/constexpr3.patch: drop, only needed for libstdc++.
- bookworm/foreach.patch: add patch from bookworm branch to fix
clang-19 build failure.
Checksums-Sha1:
edfb207c066148c0cf3207091d5f6adcb2f6709e 3951 chromium_137.0.7151.103-1.dsc
be259914ba138809b594f75f6c3c666f9bb8796f 945589756 chromium_137.0.7151.103.orig.tar.xz
9bb396af0327c3c4264d2af95b85ef198ecfe1f9 401448 chromium_137.0.7151.103-1.debian.tar.xz
789b14f5d1f8ae4e8a80780cd50ed6a3d32bbac7 26459 chromium_137.0.7151.103-1_source.buildinfo
Checksums-Sha256:
caeec410034a2fc2677155a951d3ad21c9354cda56c91710e872b255169cedc4 3951 chromium_137.0.7151.103-1.dsc
a2818b540c51258182be5e84b1bf88f518ff69c0339ae14003ec2bebe1c38545 945589756 chromium_137.0.7151.103.orig.tar.xz
1d2ca472e2da410eca04da86126969f300f82c22918d789b6e6b24c55542d45d 401448 chromium_137.0.7151.103-1.debian.tar.xz
a5f1be9c17944ca88297f2374ea24e4421a676ffda2f749f27008183d29ad6c9 26459 chromium_137.0.7151.103-1_source.buildinfo
Files:
e923d798f39d1a2dc432f170b00ce916 3951 web optional chromium_137.0.7151.103-1.dsc
2d993b8f4f4197f2891079fc66228c54 945589756 web optional chromium_137.0.7151.103.orig.tar.xz
51b09020c5c61ff9fc69e48a33bd0d90 401448 web optional chromium_137.0.7151.103-1.debian.tar.xz
9b6a69036b6e41e50cf8a4945913c4a8 26459 web optional chromium_137.0.7151.103-1_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iQJIBAEBCAAyFiEEUAUk+X1YiTIjs19qZF0CR8NudjcFAmhJLHQUHGRpbGluZ2Vy QGRlYmlhbi5vcmcACgkQZF0CR8NudjeDNA/+PNFsBy5n2dJGga54ab7VBWSVN/0a zWLMZwFkI7rKBZ2BTxLWVk7e7UkPcBc76Y0p9itQmN4Dvs0BEEU8VlDFYPe2l4BC 2sLp9NkkmpEmo1xOu6T3XYLMeNFMf3pBgfZTt59RGRCJofW0Flpw+iiCpl3WzYKS HoDC81AIsk9d3VfwgyYVf2+sZigPvyRg/Q7YrOBDiK5TpS4VXXZQIPQbK3iPzMCn 50qRcgk3axjpDfpMwSZFOmwMOsAtkJYiK8OAP9QPYEcKRLBXZ96kKrUd1XyFnYN2 i3wi0uBU82S7kL+7ZgLIK5lLVsUSqThYzcFxhPtItLAzlxW54TMFm5gmu9vktl5L sDFG1GoFJZJape7oapjgOa3bC8vALI7XAX9UVCfG2en0135stseiVa4bkEo7G+/X ivFXUeV4eFFoWeM8uotFz8aQy+bG59a36Z4kwC365bJWeEsQPwIZo82pxlSJiy7O n41AWx05UqK1IGEAtJ1mz98ZS3Hw0FaHL2Fxxtc0RzL7lHKEBN4yk4Z1EFLhvH+b rwKoplaR4opeg8AWySVKIFbovbs59ZmMDSNQmHJBopj5CAifnqh8neauUF/6S/GH lhFq95OPA7eLR8WulNL8LDB/mXrWyGJXa4wTn7g5enCIePQw8OOa9SQkflJ98B6s MjHWc7+yBgMMzPs=
=DhZi
-----END PGP SIGNATURE-----
--==============55232279759147782=Content-Type: application/pgp-signature
-----BEGIN PGP SIGNATURE-----
iHUEABYIAB0WIQTziqJOuF8J+ZI8pJSb9qggYcy5IQUCaEk5IQAKCRCb9qggYcy5 IVu4AP4hiznHFFvCGjGp87qjF37nQDnvICEr8nnGZNgdHu+HFgEA6uL7kuTJhtu6 1T/uVp974sxLzTXX6/maP9wjubDpNAc=VGXg
-----END PGP SIGNATURE-----
--- SoupGate-Win32 v1.05
* Origin: fsxNet Usenet Gateway (21:1/5)