-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Thu, 28 Mar 2024 11:57:05 -0400 Source: chromium Binary: chromium chromium-common chromium-common-dbgsym chromium-dbgsym chromium-driver chromium-sandbox chromium-sandbox-dbgsym chromium-shell chromium-shell-dbgsym Architecture: i386 Version: 123.0.6312.86-1~deb12u1 Distribution: bookworm-security Urgency: high Maintainer: i386 Build Daemon (x86-grnet-01) Changed-By: Timothy Pearson Description: chromium - web browser chromium-common - web browser - common resources used by the chromium packages chromium-driver - web browser - WebDriver support chromium-sandbox - web browser - setuid security sandbox for chromium chromium-shell - web browser - minimal shell Closes: 1067886 Changes: chromium (123.0.6312.86-1~deb12u1) bookworm-security; urgency=high . * New upstream stable release. - CVE-2024-2883: Use after free in ANGLE. Reported by Cassidy Kim(@cassidy6564). - CVE-2024-2885: Use after free in Dawn. Reported by wgslfuzz. - CVE-2024-2886: Use after free in WebCodecs. Reported by Seunghyun Lee (@0x10n) of KAIST Hacking Lab, via Pwn2Own 2024. - CVE-2024-2887: Type Confusion in WebAssembly. Reported by Manfred Paul, via Pwn2Own 2024. * d/patches/ppc64le: - fixes/fix-clang-selection.patch: select clang on ppc64 platforms - ppc64le/third_party/0001-Add-PPC64-support-for-boringssl.patch: fix ARM builds. . [ Andres Salomon ] * d/patches: - fixes/bad-font-gc1.patch, fixes/bad-font-gc2.patch: revert a pair of upstream commits that result in blink's garbage collector frequently deadlocking and crashing (closes: #1067886). Checksums-Sha1: 374dceb3406ff7d8695ccd65456444cec1baed70 1173832 chromium-common-dbgsym_123.0.6312.86-1~deb12u1_i386.deb 8ab0fbed46889c5d3952dc43b22ab8fb07d684ca 4982272 chromium-common_123.0.6312.86-1~deb12u1_i386.deb fb2c7b1bf26e289355a419d2051a517551d61374 35119072 chromium-dbgsym_123.0.6312.86-1~deb12u1_i386.deb 05c35f34572fba9bff8c46b475bbfc31f800d112 6249464 chromium-driver_123.0.6312.86-1~deb12u1_i386.deb 4d523d89b9e49773295c8a1063a41e12c7bda9ef 13952 chromium-sandbox-dbgsym_123.0.6312.86-1~deb12u1_i386.deb 476b184e7bf52551565bde8f06ced399eb67a202 87708 chromium-sandbox_123.0.6312.86-1~deb12u1_i386.deb ece93c0e4d254f0ce81d3843b5c18ea312716e87 30529672 chromium-shell-dbgsym_123.0.6312.86-1~deb12u1_i386.deb 9f7621f0c095036c9dcdd04ec796be6197d60b96 52578216 chromium-shell_123.0.6312.86-1~deb12u1_i386.deb 2a0e8e335b57f77d2a001474e395bd25be16edea 24553 chromium_123.0.6312.86-1~deb12u1_i386-buildd.buildinfo 9617e6a43e8a1804ea51ab03b0258adc4a92cc65 75245080 chromium_123.0.6312.86-1~deb12u1_i386.deb Checksums-Sha256: 5a5808229da8ce1311d3afa1aa9586a0e1da471c167d928fbda7a28a0e4c5ef7 1173832 chromium-common-dbgsym_123.0.6312.86-1~deb12u1_i386.deb 997fb6ef5e462d259336d390dcf0291b98ea3372964128033804bad5108f8e0c 4982272 chromium-common_123.0.6312.86-1~deb12u1_i386.deb 74fef31920d4d932b63c93da9d2df5dbf2647cb54c88946cb864b56ded99dc9e 35119072 chromium-dbgsym_123.0.6312.86-1~deb12u1_i386.deb 9a62409ceeeda927e897ce56d36110aaab65d57d7fa316d6bdb746cb8a7a88c8 6249464 chromium-driver_123.0.6312.86-1~deb12u1_i386.deb 0db43a108429ff5a9a6b0f9438465146f036461a88b51489abb91a8d8a759a40 13952 chromium-sandbox-dbgsym_123.0.6312.86-1~deb12u1_i386.deb 1b6e6ee5b4b6a6bf4d1d480d4dffc2a6feb492e76f50d9266d9d123e5c954929 87708 chromium-sandbox_123.0.6312.86-1~deb12u1_i386.deb eabc584a6413e58724d50cf6536038befb5175034edb13e0a80473f6db07afd0 30529672 chromium-shell-dbgsym_123.0.6312.86-1~deb12u1_i386.deb 161f1b899872ad7d32ae0792cdb916dc87e5b99b594ff43d1cc2809332948106 52578216 chromium-shell_123.0.6312.86-1~deb12u1_i386.deb bd46ce7cec93682998735ab64c54c3debbdda5da787145046cf5d56e2d78f9da 24553 chromium_123.0.6312.86-1~deb12u1_i386-buildd.buildinfo 12ea6fbb6634e164d41c24f550a31d17164cded827a9e84f4b18b773db97a53e 75245080 chromium_123.0.6312.86-1~deb12u1_i386.deb Files: 158bf005104d2d61edb1f5a790a26816 1173832 debug optional chromium-common-dbgsym_123.0.6312.86-1~deb12u1_i386.deb dd917e31d7c2a8dfd8c6c3d67887c361 4982272 web optional chromium-common_123.0.6312.86-1~deb12u1_i386.deb d130da6c481b64bd45de29a1888893a4 35119072 debug optional chromium-dbgsym_123.0.6312.86-1~deb12u1_i386.deb c2672feaa6e9543ae0c0d30904155c6a 6249464 web optional chromium-driver_123.0.6312.86-1~deb12u1_i386.deb 66b662fd800a6a52efd965d946b9a086 13952 debug optional chromium-sandbox-dbgsym_123.0.6312.86-1~deb12u1_i386.deb e31a36f13d0914c530444631f81e6aee 87708 web optional chromium-sandbox_123.0.6312.86-1~deb12u1_i386.deb 2b940bb32033cb2674b90bc47469a4d1 30529672 debug optional chromium-shell-dbgsym_123.0.6312.86-1~deb12u1_i386.deb 6e09a9a1fe4b4186b1032d97b54f1c7c 52578216 web optional chromium-shell_123.0.6312.86-1~deb12u1_i386.deb b0deacfa7920d1230e5ea198cc589006 24553 web optional chromium_123.0.6312.86-1~deb12u1_i386-buildd.buildinfo c8b22c816bde4bcc94ee6becff0f424e 75245080 web optional chromium_123.0.6312.86-1~deb12u1_i386.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEqYm4ZPyuLwhx8Meo2VckltclZ4AFAmYGK4cACgkQ2Vckltcl Z4BVbhAAx+8u4TsLaYR1Z0ez7bNpLZ1jgDEBvAD/m1aAHeR6pPC3aFmI/yO+519A 0k3SaMUSornaNeioKpigQzqglooE+sYaTNjjrUslCI8LKAyFt7vugXpH/6Sy4GeM 1asaWJF2ydHouIBLlbH+U3vEgNZSVYPn411H+9EYA3lygNi+Qtxz+6LvptkEtSGY BwRJz/uYXmiROzvxBNXjUSuAJConwPUzj8xJ+r81+G21UA61hVDMk3+eGzhqnF55 sLV+A1EvWDKs7aHPn2L65bM6mfg1PiGhPo2CN0iuTyoFqyP7oubTKjZUe3gE96R0 QnIzvG7oB+4mknh1KGU4kfS/enZMqi2FmYeT7LIVeVwK67KNKxssugz5HB5YogzD zcjC2i5epZMvm8W++t6K+UaiV5uSgbycisKNV3Af7IsWuAJBjL1HAQ+v2b6Gp2eu t52d3AHxpVOHKwjajSFdMthKNmEVpZxxlHwHCKbbX5Mgmo5UNO+3rttlGbEJBljb otIV7p5ANs7+zm39L/lAKseGBLXlWdu3JELVYklpc8OIky+wB0VySA3hb9i7s7a7 /MDkAiOdwAKC/aVwFG/NCW/YV/Chec+NfIPTZPuGTKElk0Hc5YbTfaPmbJ9ms+5u DOz9BRbNJ+U069gULlW2PT1S7BOK47jVq2c5vRYWL6yRuepqgRA= =8c0f -----END PGP SIGNATURE-----