-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 01 Apr 2026 12:42:51 -0400 Source: chromium Binary: chromium chromium-common chromium-common-dbgsym chromium-dbgsym chromium-driver chromium-headless-shell chromium-headless-shell-dbgsym chromium-sandbox chromium-sandbox-dbgsym chromium-shell chromium-shell-dbgsym Architecture: ppc64el Version: 146.0.7680.177-1~deb13u1 Distribution: trixie-security Urgency: high Maintainer: ppc64el Build Daemon (ppc64el-conova-01) Changed-By: Andres Salomon Description: chromium - web browser chromium-common - web browser - common resources used by the chromium packages chromium-driver - web browser - WebDriver support chromium-headless-shell - web browser - old headless shell chromium-sandbox - web browser - setuid security sandbox for chromium chromium-shell - web browser - minimal shell Changes: chromium (146.0.7680.177-1~deb13u1) trixie-security; urgency=high . [ Andres Salomon ] * New upstream security release. - CVE-2026-5272: Heap buffer overflow in GPU. Reported by inspector-ambitious. - CVE-2026-5273: Use after free in CSS. Reported by Anonymous. - CVE-2026-5274: Integer overflow in Codecs. Reported by heapracer (@heapracer). - CVE-2026-5275: Heap buffer overflow in ANGLE. Reported by c6eed09fc8b174b0f3eebedcceb1e792. - CVE-2026-5276: Insufficient policy enforcement in WebUSB. Reported by Ariel Simon. - CVE-2026-5277: Integer overflow in ANGLE. Reported by c6eed09fc8b174b0f3eebedcceb1e792. - CVE-2026-5278: Use after free in Web MIDI. Reported by c6eed09fc8b174b0f3eebedcceb1e792. - CVE-2026-5279: Object corruption in V8. Reported by Hyeonjun Ahn (@_deayzl). - CVE-2026-5280: Use after free in WebCodecs. Reported by heapracer (@heapracer). - CVE-2026-5281: Use after free in Dawn. Reported by 86ac1f1587b71893ed2ad792cd7dde32. - CVE-2026-5282: Out of bounds read in WebCodecs. Reported by c6eed09fc8b174b0f3eebedcceb1e792. - CVE-2026-5283: Inappropriate implementation in ANGLE. Reported by sweetchip. - CVE-2026-5284: Use after free in Dawn. Reported by 86ac1f1587b71893ed2ad792cd7dde32. - CVE-2026-5285: Use after free in WebGL. Reported by c6eed09fc8b174b0f3eebedcceb1e792. - CVE-2026-5286: Use after free in Dawn. Reported by sweetchip. - CVE-2026-5287: Use after free in PDF. Reported by Syn4pse. - CVE-2026-5288: Use after free in WebView. Reported by Google. - CVE-2026-5289: Use after free in Navigation. Reported by Google. - CVE-2026-5290: Use after free in Compositing. Reported by Google. - CVE-2026-5291: Inappropriate implementation in WebGL. Reported by heapracer (@heapracer). - CVE-2026-5292: Out of bounds read in WebCodecs. Reported by Google. * d/patches: - upstream/Fix-blink-compilation-for-platforms-other-than-x86-and-arm.patch: drop, merged upstream. - ungoogled/disable-ai.patch: resync with u-c. . [ Daniel Richard G. ] * d/copyright: Exclude *.pb (protobuf) binary files. * d/patches: Various ungoogled-chromium-related updates. - disable/glic.patch: Drop, replaced with disable-ai.patch from the ungoogled-chromium project. - ungoogled/disable-ai.patch: Import new patch from ungoogled-chromium that zaps glic, screen_ai, and various other adjacent AI-based features. - ungoogled/disable-mei-preload.patch: Import patch to allow building without *.pb files. - ungoogled/disable-privacy-sandbox.patch: Update imported patch. . [ Timothy Pearson ] * d/patches/ppc64le: - third_party/0005-blink-add-audio-vector-support.patch: Fix FBTFS from upstream adding vector-accelerated audio delay functions . [ Jianfeng Liu ] * d/patches/upstream: - Fix-blink-compilation-for-platforms-other-than-x86-and-arm.patch: Fix FBTFS from upstream for blink audio delay function on loong64 Checksums-Sha1: 5e324f9c9366851793b9e7c445d28abaf25531d2 5709808 chromium-common-dbgsym_146.0.7680.177-1~deb13u1_ppc64el.deb 4acd3733e7a078466bbbcd7047ac1e9d61ab0da2 35112344 chromium-common_146.0.7680.177-1~deb13u1_ppc64el.deb 7e71b0cda07fec0337f35fadc7ed9adac2fb96fd 29868828 chromium-dbgsym_146.0.7680.177-1~deb13u1_ppc64el.deb c76ff280be9499a5c8d1fcb1cedb10e845f4fa66 7160080 chromium-driver_146.0.7680.177-1~deb13u1_ppc64el.deb a5d47d6fc5f1f0abf95a9095e15422979ba6dbe3 24807000 chromium-headless-shell-dbgsym_146.0.7680.177-1~deb13u1_ppc64el.deb fcdd202fdc63fe17d2ecc384108627b670832f3c 58088344 chromium-headless-shell_146.0.7680.177-1~deb13u1_ppc64el.deb 7e34dc1d9640bdb51f5e04a987cfb792284648ab 20336 chromium-sandbox-dbgsym_146.0.7680.177-1~deb13u1_ppc64el.deb 4553f42dfcaa090e54bfa83b83fd4b7ba96c997b 112236 chromium-sandbox_146.0.7680.177-1~deb13u1_ppc64el.deb a5eba797e657591a09b5b659c91364c152d77ac0 25531620 chromium-shell-dbgsym_146.0.7680.177-1~deb13u1_ppc64el.deb c6a99f184f1ceec78572cd0dbbfbdaf5799b22e1 57579620 chromium-shell_146.0.7680.177-1~deb13u1_ppc64el.deb 3c9a9e45b9cb30803a313aaaac9cbbe67b470789 30330 chromium_146.0.7680.177-1~deb13u1_ppc64el-buildd.buildinfo 2e1d973475bc779fd3cac3231e948266c802bc6a 78005052 chromium_146.0.7680.177-1~deb13u1_ppc64el.deb Checksums-Sha256: 7084cd7aeabe42bff6748adb9fb302996516e1dc661bcae9b1a3efb623b26c40 5709808 chromium-common-dbgsym_146.0.7680.177-1~deb13u1_ppc64el.deb 084272ba1d7ae001b96520b76083fcd9bac5b70f6fa73ab7791d2ad4f1781279 35112344 chromium-common_146.0.7680.177-1~deb13u1_ppc64el.deb 7cef4dbb8f8fd16ad9407e84f55d549e7af076598956d377082183157717be3a 29868828 chromium-dbgsym_146.0.7680.177-1~deb13u1_ppc64el.deb 1d499b943763896528a5f0f36267ce4c75ac56407369201aed186c2900860ae0 7160080 chromium-driver_146.0.7680.177-1~deb13u1_ppc64el.deb a70fb6dec6e249c784eb31fa6b72ff44ccc0e72c7a0197a233fcc9fd6b56849a 24807000 chromium-headless-shell-dbgsym_146.0.7680.177-1~deb13u1_ppc64el.deb 5ad729b79f2142c3754b424a824b40da2e9cba7c01d0f0dba15929f5c0c174ed 58088344 chromium-headless-shell_146.0.7680.177-1~deb13u1_ppc64el.deb eb7d00156ef05d96adc637599449ae3647da8996d7e719f1d5702308fe0b6cf2 20336 chromium-sandbox-dbgsym_146.0.7680.177-1~deb13u1_ppc64el.deb bb28b0c313858b9498b7e66a24a1f04ad86d9e0e437b56acdfae1cb767a2edc4 112236 chromium-sandbox_146.0.7680.177-1~deb13u1_ppc64el.deb bcf6f768e68a1e78256e48317f44a272701e9f0ca5bb9fda7ff8a03f6d0b1beb 25531620 chromium-shell-dbgsym_146.0.7680.177-1~deb13u1_ppc64el.deb 10b44e2a5365cc07be9ee93e4f73af5700c2639e765f3ff93c42fe202e64b3e4 57579620 chromium-shell_146.0.7680.177-1~deb13u1_ppc64el.deb b59bf73fd42bb8ffd591a359e3c9614482cecc61f4997776d6eb8c916e1800d6 30330 chromium_146.0.7680.177-1~deb13u1_ppc64el-buildd.buildinfo 5ff72eb6bae6aae58e337e81525812e18e3e571071f9ae8f75953f24af2c1d55 78005052 chromium_146.0.7680.177-1~deb13u1_ppc64el.deb Files: dc37659b4402ea1e4da734a624f20d86 5709808 debug optional chromium-common-dbgsym_146.0.7680.177-1~deb13u1_ppc64el.deb 3bc6e4e90ba495dc79320aeda11742f6 35112344 web optional chromium-common_146.0.7680.177-1~deb13u1_ppc64el.deb babe3aed014cafd8f50d85d1bb8f7ca1 29868828 debug optional chromium-dbgsym_146.0.7680.177-1~deb13u1_ppc64el.deb df91d42ca4f0e70a41f9edcaf865dcce 7160080 web optional chromium-driver_146.0.7680.177-1~deb13u1_ppc64el.deb eea7133b1891dd6c29ae3c7b0ded281b 24807000 debug optional chromium-headless-shell-dbgsym_146.0.7680.177-1~deb13u1_ppc64el.deb b2061ec5f2cd7eaab6f8800e9333341c 58088344 web optional chromium-headless-shell_146.0.7680.177-1~deb13u1_ppc64el.deb bdaa7ab94cf8ca2c5032fa6738ab58bd 20336 debug optional chromium-sandbox-dbgsym_146.0.7680.177-1~deb13u1_ppc64el.deb 2dc50bf4486cf31d084b31bd15a392c9 112236 web optional chromium-sandbox_146.0.7680.177-1~deb13u1_ppc64el.deb 7f0e99b321d7831e750812ff522376e3 25531620 debug optional chromium-shell-dbgsym_146.0.7680.177-1~deb13u1_ppc64el.deb 515c741799ac83c471c8fc9d99774b51 57579620 web optional chromium-shell_146.0.7680.177-1~deb13u1_ppc64el.deb d0480c7cc3db940942a2470b24055c68 30330 web optional chromium_146.0.7680.177-1~deb13u1_ppc64el-buildd.buildinfo 3cd633d051c8ed53e970096faf0ecdaa 78005052 web optional chromium_146.0.7680.177-1~deb13u1_ppc64el.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEDoRc43uRWMOoIqIgDNLUPhbmg7MFAmnOwWsACgkQDNLUPhbm g7MD1g//fP7imurux9idGXjVkEWNQZ4WhddfG+AG1S5ZNEdi7xTSxRLM+po8pVpK J9rRBeqBvJk6VjC5XA+22M6ii6uDZ+KnPNvYsQ5xvPNMgIGpu3zkFRBNIG+O1PPp iWq1vTYW8YLg7Z0yJIjSEf+SKDl7/h+NAk0/MPjaehJpVvjiosQE0mSppCvR5pIn tKLaHmVLvMwPXtd8tXdcR2mumOPCdk8ts9B6ylCXJ/I566/fyuuhBFEy5XU7IcQO I3yhDEvEMwQhKG1+k3uez8N8KT5paAzd/kI4+V7xD9pRzLAzdUqRNb+dtNc2qi8u SlXyOI0oHI/3oIVxZ/hK8cRFV7H/XR9jM+CXDTF2qUZvoDMoWs8h/z5xj4Upte7C 8wMMwDwzjw8xQ+h9oMPTzGTLTNmwAclrkvu7k9sSEj+azt0ve531TItGj2XTqBsz HTysQqvocpXBXKKApjpY/3Yw7CWG4+3rucOlfgTRzUNf0XX6du6f7yqOnnTjB2EG ggKGGtruvT7Q2DLJDt8c8fiLPHBuojoUnLA/W/IvnAid+6jkpo7DSzma6p30D9wD 94otT7zZitBhiZPvFACPWPubg31VO2DiMj21eB7fc+VILfKsLpN1YOdNyvrvJzE2 QnTi6LYiFklIAOEyc/zAYLhYGeMA43ttHsLsoh2CZBkjx0MDZlY= =2zRd -----END PGP SIGNATURE-----