-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 29 Oct 2025 13:44:37 -0400 Source: chromium Binary: chromium chromium-common chromium-common-dbgsym chromium-dbgsym chromium-driver chromium-headless-shell chromium-headless-shell-dbgsym chromium-sandbox chromium-sandbox-dbgsym chromium-shell chromium-shell-dbgsym Architecture: ppc64el Version: 142.0.7444.59-1~deb13u1 Distribution: trixie-security Urgency: high Maintainer: ppc64el Build Daemon (ppc64el-osuosl-01) Changed-By: Andres Salomon Description: chromium - web browser chromium-common - web browser - common resources used by the chromium packages chromium-driver - web browser - WebDriver support chromium-headless-shell - web browser - old headless shell chromium-sandbox - web browser - setuid security sandbox for chromium chromium-shell - web browser - minimal shell Changes: chromium (142.0.7444.59-1~deb13u1) trixie-security; urgency=high . * New upstream stable release. - CVE-2025-12428: Type Confusion in V8. Reported by Man Yue Mo of GitHub Security Lab. - CVE-2025-12429: Inappropriate implementation in V8. Reported by Aorui Zhang. - CVE-2025-12430: Object lifecycle issue in Media. Reported by round.about. - CVE-2025-12431: Inappropriate implementation in Extensions. Reported by Alesandro Ortiz. - CVE-2025-12432: Race in V8. Reported by Google Big Sleep. - CVE-2025-12433: Inappropriate implementation in V8. Reported by Google Big Sleep. - CVE-2025-12036: Inappropriate implementation in V8. Reported by Google Big Sleep. - CVE-2025-12434: Race in Storage. Reported by Lijo A.T. - CVE-2025-12435: Incorrect security UI in Omnibox. Reported by Hafiizh. - CVE-2025-12436: Policy bypass in Extensions. Reported by Luan Herrera (@lbherrera_). - CVE-2025-12437: Use after free in PageInfo. Reported by Umar Farooq. - CVE-2025-12438: Use after free in Ozone. Reported by Wei Yuan of MoyunSec VLab. - CVE-2025-12439: Inappropriate implementation in App-Bound Encryption. Reported by Ari Novick. - CVE-2025-12440: Inappropriate implementation in Autofill. Reported by Khalil Zhani. - CVE-2025-12441: Out of bounds read in V8. Reported by Google Big Sleep. - CVE-2025-12443: Out of bounds read in WebXR. Reported by Aisle Research - CVE-2025-12444: Incorrect security UI in Fullscreen UI. Reported by syrf. - CVE-2025-12445: Policy bypass in Extensions. Reported by Thomas Greiner - CVE-2025-12446: Incorrect security UI in SplitView. Reported by Hafiizh - CVE-2025-12447: Incorrect security UI in Omnibox. Reported by Khalil Zhani. * d/patches: - disable/android.patch: drop part of patch related to md5sum tool. - disable/catapult.patch: refresh. - bookworm/clang19.patch: also drop uninit-const-pointer and unnecessary-virtual-specifier warnings. - ungoogled/disable-privacy-sandbox.patch: sync from upstream. - i386/support-i386.patch: refresh. - trixie/rust-sanitize.patch: add a workaround for older rustc. - fixes/chromium-142-iwyu-field-form-data.patch: pull in build fix from gentoo. - trixie/rust-no-alloc-shim.patch: add another missing symbol that's provided by newer versions of rust. . [ Timothy Pearson ] * d/patches/ppc64le: - third_party/0001-third-party-hwy-wrong-include.patch: Drop due to upstream fixes - ppc64le/third_party/0002-regenerate-xnn-buildgn.patch: Regenerate from upstream sources - core/add-ppc64-architecture-to-extensions.diff: Refresh for upstream changes Checksums-Sha1: 5673d9310daeb227cbad10a05ba915285378c863 5661264 chromium-common-dbgsym_142.0.7444.59-1~deb13u1_ppc64el.deb a277c47740e41c48aa9769c9624fd72f25389a34 28622804 chromium-common_142.0.7444.59-1~deb13u1_ppc64el.deb 66c2b548c2872f708e86bcb6d7a5e840500f78a6 28607812 chromium-dbgsym_142.0.7444.59-1~deb13u1_ppc64el.deb 675a284e16b7b9a85e38a49da8a3050b1d754571 6902728 chromium-driver_142.0.7444.59-1~deb13u1_ppc64el.deb be06bdf8bac332611f172a50fa62dc667b1e649f 23711636 chromium-headless-shell-dbgsym_142.0.7444.59-1~deb13u1_ppc64el.deb 5c156ef6ba1abfabee8d765b14bbab87f4f78f26 56143164 chromium-headless-shell_142.0.7444.59-1~deb13u1_ppc64el.deb 58e10638b8543c3442b0b624618d37ee3ac05b06 20332 chromium-sandbox-dbgsym_142.0.7444.59-1~deb13u1_ppc64el.deb 8e051d122f0836365930a26b4e5fdf5d4add766c 105856 chromium-sandbox_142.0.7444.59-1~deb13u1_ppc64el.deb 63663ce119e96c95303dafcc38fd6fc1d03594bf 24462644 chromium-shell-dbgsym_142.0.7444.59-1~deb13u1_ppc64el.deb 8a000d36c4ab3f3b888ed03f32e3f2909817e3b3 55531344 chromium-shell_142.0.7444.59-1~deb13u1_ppc64el.deb 7004e00447a105a3fdb3ab4368f347fe67d873d3 30025 chromium_142.0.7444.59-1~deb13u1_ppc64el-buildd.buildinfo 087b5d3c5b12ee71c17c916c4c7de0447f54d673 75909936 chromium_142.0.7444.59-1~deb13u1_ppc64el.deb Checksums-Sha256: babb3e2e37e660968ceceedec123998585671a04d528e491bc2e558ebe029b5f 5661264 chromium-common-dbgsym_142.0.7444.59-1~deb13u1_ppc64el.deb b9e80b4ba443338d887cf8be52c0a3804cc5a2edce4bd313e481fd49e8247512 28622804 chromium-common_142.0.7444.59-1~deb13u1_ppc64el.deb 0885e54dbdc7c0ef931a64fa62b97d51b1cb0b1c24fef6e903841be7260649da 28607812 chromium-dbgsym_142.0.7444.59-1~deb13u1_ppc64el.deb 87f2b483ed3874aa4192ab8f2eee4972ac18b71020852f58943bda7cb68ebf4d 6902728 chromium-driver_142.0.7444.59-1~deb13u1_ppc64el.deb 23b89ad6e5786a5ba451964fb05a471e11192d0ebdd08657f430e383aafbce2b 23711636 chromium-headless-shell-dbgsym_142.0.7444.59-1~deb13u1_ppc64el.deb 5360ba008b5a2207ebe5862dcd9f0dc28a4c7eba1e7a7477d3a46b4bfb7fe158 56143164 chromium-headless-shell_142.0.7444.59-1~deb13u1_ppc64el.deb 429c966e9f7e44736fee7c5ce5750a9515c452f93530149833a9b6b723a13d99 20332 chromium-sandbox-dbgsym_142.0.7444.59-1~deb13u1_ppc64el.deb 9546fbb82a923dbe1bca6bc5811858d46e6b07be1b8097446afb4623537251b6 105856 chromium-sandbox_142.0.7444.59-1~deb13u1_ppc64el.deb a5d692100ff8ae044fe1693939765d9e51371dd7d591a0847f65d912af5a39d7 24462644 chromium-shell-dbgsym_142.0.7444.59-1~deb13u1_ppc64el.deb ae1fc216e4b45fdbbb5aa3fa52873adf3e385a65a524c4f08f807a2bd6148955 55531344 chromium-shell_142.0.7444.59-1~deb13u1_ppc64el.deb 196dbf656ae3928d008e675c77a4b6263b44871526ceabef6c76818c41aa37c9 30025 chromium_142.0.7444.59-1~deb13u1_ppc64el-buildd.buildinfo 561341c1478e32091c30c5a737f58042f2a7dfc599ea5770fb8fd90745127756 75909936 chromium_142.0.7444.59-1~deb13u1_ppc64el.deb Files: 012049adb7b41d195d9d293e4a8e8d3e 5661264 debug optional chromium-common-dbgsym_142.0.7444.59-1~deb13u1_ppc64el.deb b8714841de153c025bb26d87de5f95c7 28622804 web optional chromium-common_142.0.7444.59-1~deb13u1_ppc64el.deb f43078eeaa6e9fc2704e8deb4f311417 28607812 debug optional chromium-dbgsym_142.0.7444.59-1~deb13u1_ppc64el.deb 35556ae1ffcb8e81516a50ad26f8f058 6902728 web optional chromium-driver_142.0.7444.59-1~deb13u1_ppc64el.deb 9aa59088b81f8984ca62c287602065fe 23711636 debug optional chromium-headless-shell-dbgsym_142.0.7444.59-1~deb13u1_ppc64el.deb 01353eb68dedcbd121b59ae7b8230374 56143164 web optional chromium-headless-shell_142.0.7444.59-1~deb13u1_ppc64el.deb 4c1eaa0960adeb032e2b27fc53bbe924 20332 debug optional chromium-sandbox-dbgsym_142.0.7444.59-1~deb13u1_ppc64el.deb 8a08523b6e805bd25f59796edce28fc4 105856 web optional chromium-sandbox_142.0.7444.59-1~deb13u1_ppc64el.deb f6505d4b58c3a975019d1bbcdca5d2d1 24462644 debug optional chromium-shell-dbgsym_142.0.7444.59-1~deb13u1_ppc64el.deb a533e01f1eeb6475fad11747be7e39cc 55531344 web optional chromium-shell_142.0.7444.59-1~deb13u1_ppc64el.deb db19735acef808457719ecd8f82fe00f 30025 web optional chromium_142.0.7444.59-1~deb13u1_ppc64el-buildd.buildinfo a8f65a0304583ff044036eea60bf3e7e 75909936 web optional chromium_142.0.7444.59-1~deb13u1_ppc64el.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEGHWM+bJZRznwgySGOrVShFbIMGEFAmkDvAcACgkQOrVShFbI MGEkyA//a1Uth9ie19hiRIFOt21dRignVepThGWus8T01rToKciTqEskGK7eRcEo SrD1l228VmBPfBbZBkzPoIY34XXY//Knv2rd6uncDnmwUEQ5pe5jOF8Ix7eKzUp8 ND2u5lg2vj3BopFBY/JBbUOHO4ocf6vwJyKcNu9RQQaF4ByRdCd+Yytvh+xekiUG MCdKMd35gx1vxiucvt7SDwzNPU8lr0Awhs7FbetPI5BBsVF0MuHvXr5h+JbxB3T6 CDJQQhbmpIPr4jYSw016lCfX+kr1J2hIgtRAbMaYPI8RdkDMcWBuV1PxRvWjaiut tvB3cpCS6PbGHQNP1eGjdKngLOxpjzkfmnOETlsoKuii4gUOxLvCcWhWRgP5tsO9 d4+rhXFuhGQiglhJDQNJ7r4prEzSJr22pUKJq2/bGvQDhC1xiTnZ50j3pE5O20De g5QImBDNTcb9ZkL55emHinQ/6TcoKIAW93RXiBY+zneBeg0/WE5XDFW8+A79rIdD iZOcN7z0V+vWmwTYeeX64mtuoaO2Jw0+sPnIvlWUGN4D6Houiwr4V5hdpPPZDyFV 5KqDSXXATXCipZLWnzsImNQB7mSytg8dgWXpyBb1yl8Z2Z78cgZDVQojPRMh0mMt MqJLEj098/L8D4ch0OxZFgzzaMSED5oYuwbkyzGWtd1y34dxyk0= =iU9t -----END PGP SIGNATURE-----