-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Thu, 28 Mar 2024 11:57:05 -0400 Source: chromium Binary: chromium chromium-common chromium-common-dbgsym chromium-dbgsym chromium-driver chromium-sandbox chromium-sandbox-dbgsym chromium-shell chromium-shell-dbgsym Architecture: armhf Version: 123.0.6312.86-1~deb12u1 Distribution: bookworm-security Urgency: high Maintainer: arm Build Daemon (arm-arm-04) Changed-By: Timothy Pearson Description: chromium - web browser chromium-common - web browser - common resources used by the chromium packages chromium-driver - web browser - WebDriver support chromium-sandbox - web browser - setuid security sandbox for chromium chromium-shell - web browser - minimal shell Closes: 1067886 Changes: chromium (123.0.6312.86-1~deb12u1) bookworm-security; urgency=high . * New upstream stable release. - CVE-2024-2883: Use after free in ANGLE. Reported by Cassidy Kim(@cassidy6564). - CVE-2024-2885: Use after free in Dawn. Reported by wgslfuzz. - CVE-2024-2886: Use after free in WebCodecs. Reported by Seunghyun Lee (@0x10n) of KAIST Hacking Lab, via Pwn2Own 2024. - CVE-2024-2887: Type Confusion in WebAssembly. Reported by Manfred Paul, via Pwn2Own 2024. * d/patches/ppc64le: - fixes/fix-clang-selection.patch: select clang on ppc64 platforms - ppc64le/third_party/0001-Add-PPC64-support-for-boringssl.patch: fix ARM builds. . [ Andres Salomon ] * d/patches: - fixes/bad-font-gc1.patch, fixes/bad-font-gc2.patch: revert a pair of upstream commits that result in blink's garbage collector frequently deadlocking and crashing (closes: #1067886). Checksums-Sha1: 08e5e7ecf605ecb00997ddd509618261f57b55f1 1299024 chromium-common-dbgsym_123.0.6312.86-1~deb12u1_armhf.deb fe9636e8b0586b66496f1cbac1cdb6f835cba10e 4907816 chromium-common_123.0.6312.86-1~deb12u1_armhf.deb c7a6d260118df799f6add714c3fe6ca33d259935 34538344 chromium-dbgsym_123.0.6312.86-1~deb12u1_armhf.deb d4062ce30d3d5af4e7e407d16d9948b5e59ee8a9 5761436 chromium-driver_123.0.6312.86-1~deb12u1_armhf.deb 76fce1e7ca283702e9309939cc298c9f449a4b36 12220 chromium-sandbox-dbgsym_123.0.6312.86-1~deb12u1_armhf.deb 7ebd6f7e3af7cb676495e4b47e249aeede7ecbab 87412 chromium-sandbox_123.0.6312.86-1~deb12u1_armhf.deb 4475f072ccf7bb4c4870a14711866b993a422fe4 28605044 chromium-shell-dbgsym_123.0.6312.86-1~deb12u1_armhf.deb 79ab7a0b720b5776be913af4d4e04047c7fcc0b4 47358400 chromium-shell_123.0.6312.86-1~deb12u1_armhf.deb 090171e1469638cb8cdf5fe6dbe2ecde4cb25546 24465 chromium_123.0.6312.86-1~deb12u1_armhf-buildd.buildinfo 9987f6faa993b7defc5eeac007f21857882dd1e1 68182200 chromium_123.0.6312.86-1~deb12u1_armhf.deb Checksums-Sha256: 7a741f2c117481752e83e397a940d43753757e196b33a97443adfcdc9ac9ad3d 1299024 chromium-common-dbgsym_123.0.6312.86-1~deb12u1_armhf.deb c337c05e452e5209a238ff79554baececf2f9d94269d3b6a263ba8540f9c9ecf 4907816 chromium-common_123.0.6312.86-1~deb12u1_armhf.deb 45f58914655bcc00969f28c0552c0f5a33e6b2364df9729b9da49c5089196ec0 34538344 chromium-dbgsym_123.0.6312.86-1~deb12u1_armhf.deb e79ce4ce3d996361963658e2c95b98c2b06e5643c03d404ff65abe83a1b658e2 5761436 chromium-driver_123.0.6312.86-1~deb12u1_armhf.deb 1c6630c84903764b595571cbcc7fcc84941a240da890f866f4e38f61dc425a58 12220 chromium-sandbox-dbgsym_123.0.6312.86-1~deb12u1_armhf.deb 49bf240ce2bd943f11fa0302eb6c666c9fc40534d7e433146ca9dc70ea57e1b8 87412 chromium-sandbox_123.0.6312.86-1~deb12u1_armhf.deb 9ec66613835129e1bb6545c83a258663579babc67fabc0db4689bbb6ef31c426 28605044 chromium-shell-dbgsym_123.0.6312.86-1~deb12u1_armhf.deb d41d0e25865a730eb01b2b7e8439960ffa461aab6538cf058f560c1ee13e4aca 47358400 chromium-shell_123.0.6312.86-1~deb12u1_armhf.deb a5e27e6f240da1c3db80bf63904697161697b02bd5c1586eca98f3315334dbcb 24465 chromium_123.0.6312.86-1~deb12u1_armhf-buildd.buildinfo da44769da2fb617ecdb34fdf7e0218f2678e84c609f9e1ea8659f98ba80f02ba 68182200 chromium_123.0.6312.86-1~deb12u1_armhf.deb Files: ab040ab767e008223675054684db2b31 1299024 debug optional chromium-common-dbgsym_123.0.6312.86-1~deb12u1_armhf.deb 2635f42ecf5205ad4bb785cd4951c20d 4907816 web optional chromium-common_123.0.6312.86-1~deb12u1_armhf.deb 90cd55b128d1b9a0e59e97c7858fe265 34538344 debug optional chromium-dbgsym_123.0.6312.86-1~deb12u1_armhf.deb b049a3874b9b2dd120a5429ed7dcf3f1 5761436 web optional chromium-driver_123.0.6312.86-1~deb12u1_armhf.deb 566c7f9cab12d37bd1a26a53766afaed 12220 debug optional chromium-sandbox-dbgsym_123.0.6312.86-1~deb12u1_armhf.deb 73e22af4ce0e26f27898f57e67eead7e 87412 web optional chromium-sandbox_123.0.6312.86-1~deb12u1_armhf.deb 8494431241e3f2e0b994d2876b0deacd 28605044 debug optional chromium-shell-dbgsym_123.0.6312.86-1~deb12u1_armhf.deb e655f6512ad2f9a566213dff0cff4720 47358400 web optional chromium-shell_123.0.6312.86-1~deb12u1_armhf.deb 681f430d612809f5dc23a8dd593c13ff 24465 web optional chromium_123.0.6312.86-1~deb12u1_armhf-buildd.buildinfo 4de86f84c3831b5c927f68706ddb3399 68182200 web optional chromium_123.0.6312.86-1~deb12u1_armhf.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEmUDOxnfDwdc47jJKqoc2e3yvTA0FAmYGyqMACgkQqoc2e3yv TA0XYA//fLzMeXqg51M9jynp9GKa6Ykk/Nla5OSG7shX69Tg5X/cnZd3K1EdUMwQ xzGgy1oSxYhOLLFbSA9y5+ix0FjJ9p7AmqIkqfUG55zGhS0YXdtLY5wgah0/FdbZ ts4jefGLlEeQjw62QmLut4oQrxCt5V/zRbEFLifA+NbDs43FbX4DCOLA1bQdmAcx gbhigBEJI5+ByQX4M9Pedish8biCyH0izOOxUf660xVnQETEqSmi1tfrxU4PPwMx WOcp2scaB9Rw1ZGzdhn+PWOkyfbkByE9OZMvD6nNVzwYaIW8xb4eXcIHIGKGS5av 8lXg31Yzf+4/qMz7kWikRJDhqm3iqcqWt++DfIoNJWePFQBl7XxOVMX/2AeFDtbP GycIWkt+hvO/4kCdGKY9A5Q35ZQgKTTbtIWCWrjn2cPRzoOIXouT+at/QAzZdJYn ebNU7r8eKF2nXLLxPRof9G2iGmdiB181P4L2kAqMxG46nlka541UJoQzc3IJaFX2 Qhe5d6GxSebTt/XZblWSgIj3sT65GDWE9hAGUsOOz9WF5IXDcjt07l5ovgbrOUMP IPKNlDeJJLcV/999UbJ6PkbmuykLtXCwMiDnTCJ2EVyAFNDKWkHHN+Fvuj/RNiOr /LFB0vArcGZU/f1heYXjsxEoP1iLK4HoysGvTTYvGRHjsuPD8C0= =PmVo -----END PGP SIGNATURE-----