-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 15 Apr 2025 22:12:30 -0400 Source: chromium Binary: chromium chromium-common chromium-common-dbgsym chromium-dbgsym chromium-driver chromium-headless-shell chromium-headless-shell-dbgsym chromium-sandbox chromium-sandbox-dbgsym chromium-shell chromium-shell-dbgsym Architecture: ppc64el Version: 135.0.7049.95-1~deb12u1 Distribution: bookworm-security Urgency: high Maintainer: ppc64el Build Daemon (ppc64el-osuosl-02) Changed-By: Andres Salomon Description: chromium - web browser chromium-common - web browser - common resources used by the chromium packages chromium-driver - web browser - WebDriver support chromium-headless-shell - web browser - old headless shell chromium-sandbox - web browser - setuid security sandbox for chromium chromium-shell - web browser - minimal shell Closes: 1103226 Changes: chromium (135.0.7049.95-1~deb12u1) bookworm-security; urgency=high . [ Andres Salomon ] * New upstream security release. - CVE-2025-3619: Heap buffer overflow in Codecs. Reported by Elias Hohl. - CVE-2025-3620: Use after free in USB. Reported by @retsew0x01. . [ Daniel Richard G. ] * d/copyright, d/patches/system/rapidjson.patch: Slightly narrow the scope of the bundled RapidJSON deletion, and rework this patch so that it does not require the deletion in order to apply. This allows applying the debianization directly to the unrepackaged upstream tarball source. * d/patches/system/gperf.patch: Import (self-authored) upstream patch to prevent build breakage due to changes in gperf 3.2 generated code (closes: #1103226). * d/rules: Add new check-version rule to validate the package version. Also squelch error messages due to absent clang and rustc executables. * d/rules: Download Gentoo's upstream source tarball straight from GitHub. Checksums-Sha1: 53ddcc9258a0af804915e87206a5ed053af6eb2a 5322860 chromium-common-dbgsym_135.0.7049.95-1~deb12u1_ppc64el.deb d05fb24c650144442d1c5245623d80112e032e85 26235900 chromium-common_135.0.7049.95-1~deb12u1_ppc64el.deb a76d0cd04394ed8146015540ee18217e6b78180f 25997588 chromium-dbgsym_135.0.7049.95-1~deb12u1_ppc64el.deb f8ea74e3f8760760568db964553b26aa0215d75e 7414320 chromium-driver_135.0.7049.95-1~deb12u1_ppc64el.deb 4e29e29915d8c59f27c88ed49b409b8de41c91e7 21515868 chromium-headless-shell-dbgsym_135.0.7049.95-1~deb12u1_ppc64el.deb 9662aad0aa17f0420c18509708d359902bf51de8 54567652 chromium-headless-shell_135.0.7049.95-1~deb12u1_ppc64el.deb a052653be80774e95ecf20512b9e983fc4001dc7 14256 chromium-sandbox-dbgsym_135.0.7049.95-1~deb12u1_ppc64el.deb 886a6e2fd0d48c92ce5453d49350c510f8ae38b7 102380 chromium-sandbox_135.0.7049.95-1~deb12u1_ppc64el.deb aa04f7961e2be3ae068547a0d3339af65df2199f 21278692 chromium-shell-dbgsym_135.0.7049.95-1~deb12u1_ppc64el.deb ec0ebf5c980dfbf58b08d6a8a3e35743d8eaffe3 51492024 chromium-shell_135.0.7049.95-1~deb12u1_ppc64el.deb 0f42646edb2d9253bc6be8fa337a9095600fef85 30264 chromium_135.0.7049.95-1~deb12u1_ppc64el-buildd.buildinfo f98235e390058cf7bf0d54f38023cfdd620f0ab0 74019236 chromium_135.0.7049.95-1~deb12u1_ppc64el.deb Checksums-Sha256: a0d87f6fbeba29b3aee5aef7c15c34ab185830aa31d0d85bf12766b91c7fad93 5322860 chromium-common-dbgsym_135.0.7049.95-1~deb12u1_ppc64el.deb 018baf0406efd9bda28281ca4506254c37ddbc72db8d094db8f064e7656083e8 26235900 chromium-common_135.0.7049.95-1~deb12u1_ppc64el.deb fc1badec46b8dccf6f66f1a886ca48344194b9baec57056eadffda686ca4894e 25997588 chromium-dbgsym_135.0.7049.95-1~deb12u1_ppc64el.deb f7706878282e416493ccc27607c0f4c55d8cbe03824e1b657b25ffbbcf4f9085 7414320 chromium-driver_135.0.7049.95-1~deb12u1_ppc64el.deb 76c6298b947b23b17d965577d62a60c1ae8c331ac81e38582415336aded069b2 21515868 chromium-headless-shell-dbgsym_135.0.7049.95-1~deb12u1_ppc64el.deb 4e7571d16a9ce8232b8b417dfd6be51d4808ee8b69e20d54226f40152e7c9ae9 54567652 chromium-headless-shell_135.0.7049.95-1~deb12u1_ppc64el.deb f65176d768ca0b05423314ad04f408e538e75935d9771979d4830da4b7570b21 14256 chromium-sandbox-dbgsym_135.0.7049.95-1~deb12u1_ppc64el.deb 7948f0bac5e0cefb8451d5313268722a65d7a5ec1681cb2a294233bb76a997d4 102380 chromium-sandbox_135.0.7049.95-1~deb12u1_ppc64el.deb 6dd80c98e0986b1311870efb8283b1741145c984ef59898e9d9915dbfd738b5e 21278692 chromium-shell-dbgsym_135.0.7049.95-1~deb12u1_ppc64el.deb 9326f888171b67adad5a097b18df306272064c436f458e2cd4b60a8a3112efda 51492024 chromium-shell_135.0.7049.95-1~deb12u1_ppc64el.deb ee7198b5d4088042f261246d036977ceaab77c5efa9fae4c3ee278b00089a00a 30264 chromium_135.0.7049.95-1~deb12u1_ppc64el-buildd.buildinfo 07456bd01b3e9332dd27f1b96b2d24f1b80110aebd4b0a3bb22c21602f30b29b 74019236 chromium_135.0.7049.95-1~deb12u1_ppc64el.deb Files: a958a7a729eedbb12de1dde4edc28797 5322860 debug optional chromium-common-dbgsym_135.0.7049.95-1~deb12u1_ppc64el.deb 54e719b8d8650eb2b6d2599ea4f0b5a6 26235900 web optional chromium-common_135.0.7049.95-1~deb12u1_ppc64el.deb d4d3c45487745baefc1d2773b0be824c 25997588 debug optional chromium-dbgsym_135.0.7049.95-1~deb12u1_ppc64el.deb 5341a71599eb517f3208d5b7091b63a4 7414320 web optional chromium-driver_135.0.7049.95-1~deb12u1_ppc64el.deb 6c28294466c09cd08f4943d1f967971f 21515868 debug optional chromium-headless-shell-dbgsym_135.0.7049.95-1~deb12u1_ppc64el.deb bd514ebbea03d5fecd62589336a6fa71 54567652 web optional chromium-headless-shell_135.0.7049.95-1~deb12u1_ppc64el.deb 43b3b3050cab96bcec68e071510b6529 14256 debug optional chromium-sandbox-dbgsym_135.0.7049.95-1~deb12u1_ppc64el.deb 803e4048d34e3246b53351acb5935d5c 102380 web optional chromium-sandbox_135.0.7049.95-1~deb12u1_ppc64el.deb 967e64869e3671b4f88b4f5760f2ce42 21278692 debug optional chromium-shell-dbgsym_135.0.7049.95-1~deb12u1_ppc64el.deb 9dda8cce275e671379b5271e60f27b76 51492024 web optional chromium-shell_135.0.7049.95-1~deb12u1_ppc64el.deb 2985b1e5f4486e936e21586d0c0b2191 30264 web optional chromium_135.0.7049.95-1~deb12u1_ppc64el-buildd.buildinfo c19aa85be3c13dafb8c27f50a8e25c41 74019236 web optional chromium_135.0.7049.95-1~deb12u1_ppc64el.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE0YcVZfZCWQv84jpRNcqbeolus3sFAmgCn3EACgkQNcqbeolu s3stMhAAqG8tVvvUWnuGZXNFSlo+ZnW1lWv3PRVyapiFxOrpvYuXF8aK+qLYo+ZT 4tD5SXUt6Syx/m+VTnHjQ2oWx40yjFUd+Dd8xpUp69Nklr8SUAePA9tkBrlbc5KE k3acCXyo6pAyX1S02ogAb6vMF4JlYHyJrJjNMhqsYzIQrzqecFw6YW62Pb/wZO24 NmwLTWO8g2qqvPzLu2o9OV8tSAu1Y81pLJ/tE+qQd0YFzYMjTyUdmeRwV+l5f+FD m+dTDpoee+AEH5QI8yaCnGjKrLN/3wttJBKqmx+W1ZGRGN1s4voe14wbrrBkgu+K aOWg+NKQyXgB67eGau/uFG+qxHHC9K2BlNwk4Ooe0IWmdN/MUV4r2rvryLvvDAYU XxBZM9HSrI4IHuCvXcAmQJ2llULgNjICErG6Qr+daoyRR9kV08N//fy3xnKftOa0 Cd/mOS6tXaXCXVPsG2lI/DFnmWNjSL98gEDhc4BPYjWXVMDxm4MzK8LA6251+25U soO3CAT+fp5cumZXKRc432adhwQaL84Mj3h5eU0LEFj2cAnY7FxuGDDWtCm5VQ3f CoX3RLIK2mrQcTRZo+r8Mh1FFviX6qKbNcKmCSsJHmVPh27B6kp4hp5gREak7Z1J aSDrHKxvKQeRblLSDzvpAQYfwvINJYYoR2bHs35moyoqHpIcOTY= =StRs -----END PGP SIGNATURE-----