check-manifest (0.51+git20260724-1) unstable; urgency=medium . * Team upload. * New upstream snapshot 0.51+git20260724 (Closes: #1147332, #1147554) * Refresh patches * Drop extraneous "Priority: optional" tag * Disable useless Salsa CI jobs * Rewrite d/watch in v5 format * Salsa CI: test nocheck profile * Update standards version to 4.7.4, no changes needed. * Add debian/upstream/metadata . [ Petter Reinholdtsen ] * Added d/gbp.conf to enforce the use of pristine-tar. chromium (153.0.8010.52-1) unstable; urgency=high . [ Andres Salomon ] * New upstream security release. - CVE-2026-93374: Use after free in Dawn. Reported by Florian Schweitzer. - CVE-2026-93372: Buffer overflow in WebGL. Reported by Google. - CVE-2026-93375: Incorrect reference resolution in Tracing. Reported by M. Fauzan Wijaya (Gh05t666nero). - CVE-2026-93382: Use after free in PDFium. Reported by WinD39 - Huynh Dinh Vu. - CVE-2026-93387: Improper state validation in Skia. Reported by Google. - CVE-2026-93373: Use after free in Extensions. Reported by Google. - CVE-2026-93381: Buffer overflow in PDFium. Reported by SeungMyung Lee (@sm1ee), Siung kim (@ksw9722). - CVE-2026-93379: Incorrect authorization in ORB. Reported by OGINOME Tomohito. - CVE-2026-93377: Type confusion in V8. Reported by Google. - CVE-2026-93380: Race condition in FileSystem. Reported by Google. - CVE-2026-93384: Server-side request forgery in Omnibox. Reported by Google. - CVE-2026-93383: Information leak in Permissions. Reported by Google. - CVE-2026-93376: Out of bounds read in DataTransfer. Reported by Google. - CVE-2026-93378: Missing authorization in Storage. Reported by Google. - CVE-2026-93385: Information leak in Paint. Reported by Google. - CVE-2026-93386: UI misrepresentation in WebAppInstalls. Reported by Google. chromium (153.0.8010.47-2) unstable; urgency=high . [ Andres Salomon ] * d/control: Change generate-ninja:native build-dep to generate-ninja. chromium (153.0.8010.47-1) unstable; urgency=high . [ Andres Salomon ] * New upstream stable release. - CVE-2026-87464: Use after free in WebGL. Reported by Lexi Groves (49016). - CVE-2026-87488: Use after free in WebGL. Reported by Google. - CVE-2026-87438: Out of bounds write in WebGL. Reported by Google. - CVE-2026-87527: Buffer overflow in WebGL. Reported by Google. - CVE-2026-87628: Use after free in Cast. Reported by Hafiizh. - CVE-2026-87512: Use after free in ANGLE. Reported by weihengqiuu. - CVE-2026-87585: Double free in PDFium. Reported by Jeongkihyun. - CVE-2026-87444: Memory corruption in Codecs. Reported by Casper Woudenberg. - CVE-2026-87447: Incorrect authorization in Network. Reported by Google. - CVE-2026-87440: Out of bounds read in Media. Reported by Google. - CVE-2026-87633: Use after free in Views. Reported by Google. - CVE-2026-87525: Out of bounds read in Chromoting. Reported by Google. - CVE-2026-87578: Use after free in Receiver. Reported by Google. - CVE-2026-87517: Race condition in Mobile. Reported by Google. - CVE-2026-87524: Use after free in Core. Reported by Google. - CVE-2026-87569: Missing authorization in Views. Reported by Google. - CVE-2026-87554: Race condition in Chromoting. Reported by Google. - CVE-2026-87467: Race condition in Updater. Reported by Google. - CVE-2026-87492: Incorrect authorization in DevTools. Reported by Avadhut Mahamuni. - CVE-2026-87520: Use after free in Dawn. Reported by Google. - CVE-2026-87514: Use after free in Views. Reported by Google. - CVE-2026-87650: Out of bounds read in WebGL. Reported by Google. - CVE-2026-87596: Out of bounds read in ANGLE. Reported by Google. - CVE-2026-87654: Buffer overflow in ANGLE. Reported by Google. - CVE-2026-87604: Out of bounds read in ANGLE. Reported by Google. - CVE-2026-87621: Out of bounds write in ANGLE. Reported by Google. - CVE-2026-87647: Uninitialized resource in GPU. Reported by Google. - CVE-2026-87646: Use after free in Web Authentication. Reported by h3ee. - CVE-2026-87500: Improper validation of array index in ANGLE. Reported by Google. - CVE-2026-87572: Injection in DevTools. Reported by Google. - CVE-2026-87460: Use after free in Platform. Reported by Google. - CVE-2026-87542: Use after free in Input. Reported by Google BigSleep@Grape. - CVE-2026-87639: Use after free in WebPackaging. Reported by OpenAI Codex Security (amyb). - CVE-2026-87552: Missing authorization in TrustedWebActivities. Reported by juddrouillon0. - CVE-2026-87651: Incorrect authorization in Paint. Reported by OGINOME Tomohito. - CVE-2026-87587: Use after free in V8. Reported by Jihyeon Jeong (Compsec Lab, Seoul National University / Research Intern). - CVE-2026-87564: Type confusion in V8. Reported by Tech Division (@taiphung) - Mobifone Digital Payment. - CVE-2026-87498: Missing authorization in WebUI. Reported by Google. - CVE-2026-87499: Incorrect authorization in Network. Reported by Google. - CVE-2026-87607: Use after free in Device. Reported by Google. - CVE-2026-87558: Use after free in Payments. Reported by Google. - CVE-2026-87581: Use after free in Payments. Reported by Google. - CVE-2026-87480: Use after free in Printing. Reported by Google. - CVE-2026-87612: Type confusion in V8. Reported by ywatanabee. - CVE-2026-87536: Use after free in V8. Reported by StinkyTuna56. - CVE-2026-87474: Use after free in Payments. Reported by Google. - CVE-2026-87504: Use after free in Core. Reported by c6eed09fc8b174b0f3eebedcceb1e792. - CVE-2026-87640: Out of bounds read in WebView. Reported by c6eed09fc8b174b0f3eebedcceb1e792. - CVE-2026-87491: Out of bounds write in V8. Reported by Jihyeon Jeong (Compsec Lab, Seoul National University / Research Intern). - CVE-2026-87478: Observable discrepancy in Autofill. Reported by Maurice Dauer. - CVE-2026-87446: Incomplete cleanup in Extensions. Reported by Hafiizh. - CVE-2026-87657: Use after free in V8. Reported by Jihyeon Jeong (Compsec Lab, Seoul National University / Research Intern). - CVE-2026-87434: Missing authorization in CORS. Reported by Google. - CVE-2026-87487: Missing authorization in FileSystem. Reported by Google. - CVE-2026-87453: Confused deputy in BackgroundFetch. Reported by Google. - CVE-2026-87588: Use after free in Chromecast. Reported by Google. - CVE-2026-87636: Type confusion in XML. Reported by Google. - CVE-2026-87611: Missing authorization in FileSystem. Reported by Google. - CVE-2026-87606: Missing authorization in SiteIsolation. Reported by Google. - CVE-2026-87456: Uninitialized resource in Media. Reported by Google. - CVE-2026-87553: Improper input validation in SiteIsolation. Reported by Google. - CVE-2026-87658: Information leak in Extensions. Reported by Google. - CVE-2026-87465: Incorrect authorization in Downloads. Reported by Google. - CVE-2026-87515: Incorrect authorization in FileAPI. Reported by Google. - CVE-2026-87547: Incorrect reference resolution in FileSystem. Reported by Google. - CVE-2026-87442: Confused deputy in Prerender. Reported by Google. - CVE-2026-87506: Privilege elevation in WebUI. Reported by Google. - CVE-2026-87433: Race condition in FileAPI. Reported by Google. - CVE-2026-87557: Missing authorization in LocalNetworkAccess. Reported by Google. - CVE-2026-87457: Race condition in Updater. Reported by Google. - CVE-2026-87503: Inappropriate implementation in Downloads. Reported by Google. - CVE-2026-87481: Incorrect authorization in WebView. Reported by Google. - CVE-2026-87537: Missing authorization in Extensions. Reported by Google. - CVE-2026-87471: Incorrect authorization in ServiceWorker. Reported by Google. - CVE-2026-87485: Incorrect authorization in CORS. Reported by Google. - CVE-2026-87652: Incorrect authorization in PushAPI. Reported by Google. - CVE-2026-87582: Confused deputy in DataTransfer. Reported by Google. - CVE-2026-87466: Incorrect authorization in Workers. Reported by Google. - CVE-2026-87603: Missing authorization in FileSystem. Reported by Google. - CVE-2026-87615: Race condition in Payments. Reported by Google. - CVE-2026-87642: Uninitialized resource in WebGL. Reported by Google. - CVE-2026-87577: Incorrect authorization in Isolated. Reported by Google. - CVE-2026-87449: Cross-site request forgery in DeviceBoundSessionCredentials. Reported by Google. - CVE-2026-87613: Incorrect reference resolution in Extensions. Reported by Google. - CVE-2026-87645: Improper state validation in Safebrowsing. Reported by Google. - CVE-2026-87443: Missing authorization in Actor. Reported by Google. - CVE-2026-87630: Integer overflow in WebRTC. Reported by ngrunbaum. - CVE-2026-87590: Improper input validation in Passwords. Reported by Google. - CVE-2026-87580: Incorrect authorization in WebAppInstalls. Reported by Google. - CVE-2026-87482: Cleartext transmission of sensitive data in HttpsUpgrades. Reported by Google. - CVE-2026-87497: Uninitialized resource in Codecs. Reported by Google. - CVE-2026-87579: Buffer overflow in WebRTC. Reported by Google. - CVE-2026-87576: Uninitialized resource in GPU. Reported by Google. - CVE-2026-87476: Incorrect authorization in Loader. Reported by Google. - CVE-2026-87475: Missing authorization in Omnibox. Reported by Google. - CVE-2026-87436: Incomplete cleanup in Browser. Reported by Google. - CVE-2026-87479: Insufficient policy enforcement in Extensions. Reported by Google. - CVE-2026-87513: Missing authorization in ControlledFrame. Reported by Google. - CVE-2026-87432: Incorrect authorization in Navigation. Reported by Google. - CVE-2026-87560: Missing authorization in Browser. Reported by Google. - CVE-2026-87521: Information leak in WebMCP. Reported by Google. - CVE-2026-87539: Observable discrepancy in Network. Reported by Google. - CVE-2026-87648: Use after free in ANGLE. Reported by Google. - CVE-2026-87534: Missing authorization in WebView. Reported by Google. - CVE-2026-87562: Incorrect reference resolution in Accessibility. Reported by Google. - CVE-2026-87556: Missing authorization in Browser. Reported by Google. - CVE-2026-87508: Incorrect authorization in Loader. Reported by Google. - CVE-2026-87643: Integer overflow in GPU. Reported by Google. - CVE-2026-87573: Improper input validation in Network. Reported by Google. - CVE-2026-87548: Improper state validation in Installer. Reported by Google. - CVE-2026-87501: UI misrepresentation in Passwords. Reported by Google. - CVE-2026-87452: Incorrect authorization in GPU. Reported by Google. - CVE-2026-87516: Observable discrepancy in Navigation. Reported by Google. - CVE-2026-87599: Improper input validation in Interstitials. Reported by Google. - CVE-2026-87507: UI misrepresentation in Downloads. Reported by Google. - CVE-2026-87559: UI misrepresentation in UI. Reported by Google. - CVE-2026-87472: Improper input validation in FedCM. Reported by Google. - CVE-2026-87486: Clickjacking in TrustedWebActivities. Reported by Google. - CVE-2026-87655: Clickjacking in Downloads. Reported by Google. - CVE-2026-87462: UI misrepresentation in FedCM. Reported by Google. - CVE-2026-87649: UI misrepresentation in Downloads. Reported by Google. - CVE-2026-87445: UI misrepresentation in Session. Reported by Google. - CVE-2026-87567: UI misrepresentation in UrlFormatting. Reported by Google. - CVE-2026-87496: UI misrepresentation in Browser. Reported by Google. - CVE-2026-87441: Missing authorization in Downloads. Reported by Google. - CVE-2026-87549: Incomplete cleanup in Downloads. Reported by Google. - CVE-2026-87458: UI misrepresentation in Geometry. Reported by Google. - CVE-2026-87574: Information leak in ServiceWorker. Reported by Google. - CVE-2026-87495: Information leak in Scroll. Reported by Google. - CVE-2026-87541: Information leak in Navigation. Reported by Google. - CVE-2026-87451: Information leak in Downloads. Reported by Google. - CVE-2026-87570: Incorrect authorization in SiteIsolation. Reported by Google. - CVE-2026-87555: Uninitialized resource in GPU. Reported by Google. - CVE-2026-87600: Improper input validation in Safebrowsing. Reported by Google. - CVE-2026-87532: Improper state validation in Safebrowsing. Reported by Google. - CVE-2026-87439: Information leak in ServiceWorker. Reported by Google. - CVE-2026-87450: Incorrect authorization in Permissions. Reported by Google. - CVE-2026-87505: Incorrect authorization in FileSystem. Reported by Google. - CVE-2026-87622: Missing authorization in FedCM. Reported by Google. - CVE-2026-87540: Incorrect authorization in Isolated. Reported by Google. - CVE-2026-87594: Incorrect authorization in DataTransfer. Reported by Google. - CVE-2026-87518: Observable discrepancy in Safebrowsing. Reported by Google. - CVE-2026-87589: Incorrect authorization in SiteIsolation. Reported by Google. - CVE-2026-87484: UI misrepresentation in Geometry. Reported by Google. - CVE-2026-87530: Uncontrolled search path element in CredentialProvider. Reported by Google. - CVE-2026-87550: Improper encoding or escaping of output in CSS. Reported by Google. - CVE-2026-87494: Use after free in Browser. Reported by Google. - CVE-2026-87483: Incorrect authorization in Browser. Reported by Google. - CVE-2026-87454: Information leak in Enterprise. Reported by Google. - CVE-2026-87616: Improper initialization in Views. Reported by Google. - CVE-2026-87535: Information loss or omission in Safebrowsing. Reported by Google. - CVE-2026-87644: Incorrect authorization in Views. Reported by Google. - CVE-2026-87533: Use after free in DevTools. Reported by Google. - CVE-2026-87635: UI misrepresentation in Payments. Reported by Google. - CVE-2026-87641: Race condition in Browser. Reported by Google. - CVE-2026-87431: Missing authorization in Extensions. Reported by Microsoft Edge. - CVE-2026-87493: Missing authorization in FileSystem. Reported by Google. - CVE-2026-87625: Use after free in V8. Reported by Google. - CVE-2026-87468: Incorrect authorization in Isolated. Reported by Google. - CVE-2026-87563: Origin validation error in Paint. Reported by Google. - CVE-2026-87510: Improper input validation in FileAPI. Reported by Google. - CVE-2026-87435: Information leak in ControlledFrame. Reported by Google. - CVE-2026-87531: Information leak in CORS. Reported by Google. - CVE-2026-87637: Use after free in Extensions. Reported by Google. - CVE-2026-87529: Numeric truncation error in Media. Reported by Google. - CVE-2026-87470: Improper quantity validation in Tint. Reported by Google. - CVE-2026-87586: Out of bounds read in ANGLE. Reported by Google. - CVE-2026-87584: Incorrect authorization in WebUI. Reported by Google. - CVE-2026-87632: Cross-site scripting in SanitizerAPI. Reported by Eli Ainhorn. - CVE-2026-87528: Type confusion in Rust. Reported by marcobartoli. - CVE-2026-87623: Observable discrepancy in DOM. Reported by Google. - CVE-2026-87566: Observable discrepancy in Layout. Reported by Google. - CVE-2026-87638: Out of bounds write in Media. Reported by Google. - CVE-2026-87455: Use after free in Aura. Reported by Microsoft. - CVE-2026-87591: Incorrect authorization in Extensions. Reported by antoniosmr02. - CVE-2026-87526: Use after free in Passwords. Reported by shab. - CVE-2026-87609: Use after free in Sharing. Reported by Google. - CVE-2026-87610: Incorrect authorization in Omnibox. Reported by Arni Hardarson (Neonix Security). - CVE-2026-87626: Incorrect authorization in DeviceBoundSessionCredentials. Reported by Google. - CVE-2026-87629: Incorrect authorization in Sources. Reported by lebr0nli of National Yang Ming Chiao Tung University, Dept. of CS, Security and Systems Lab. - CVE-2026-87653: UI misrepresentation in FullScreen. Reported by Lijo A.T. - CVE-2026-87634: Use after free in WebPackaging. Reported by Google. - CVE-2026-87429: Missing authorization in ServiceWorker. Reported by Google. - CVE-2026-87618: Incorrect reference resolution in Storage. Reported by Google. - CVE-2026-87614: Incorrect authorization in ServiceWorker. Reported by Google. - CVE-2026-87619: Observable discrepancy in Prefetch. Reported by Google. - CVE-2026-87561: Incorrect authorization in Web Authentication. Reported by Google. - CVE-2026-87598: Incorrect authorization in ServiceWorker. Reported by Google. - CVE-2026-87519: Incorrect authorization in Safebrowsing. Reported by Google. - CVE-2026-87543: Missing authorization in Core. Reported by Google. - CVE-2026-87522: Missing authorization in WebView. Reported by Google. - CVE-2026-87568: Improper input validation in Chromium. Reported by Google. - CVE-2026-87656: Improper state validation in Safebrowsing. Reported by Google. - CVE-2026-87511: Missing authorization in DevTools. Reported by Google. - CVE-2026-87627: Interpretation conflict in Safebrowsing. Reported by Google. - CVE-2026-87595: Server-side request forgery in Mobile. Reported by Google. - CVE-2026-87592: Out of bounds read in Tint. Reported by Google. - CVE-2026-87620: Observable discrepancy in SVG. Reported by Google. - CVE-2026-87502: Confused deputy in Fullscreen. Reported by Google. - CVE-2026-87448: Use after free in DevTools. Reported by Google. - CVE-2026-87459: Observable discrepancy in Select. Reported by Google. - CVE-2026-87463: Incorrect authorization in Certificate. Reported by Google. - CVE-2026-87546: Incorrect type conversion or cast in Safebrowsing. Reported by Google. - CVE-2026-87538: Clickjacking in Input. Reported by Google. - CVE-2026-87545: Information leak in Mobile. Reported by Google. - CVE-2026-87617: Use after free in DevTools. Reported by Google. - CVE-2026-87523: Race condition in DataTransfer. Reported by Google. - CVE-2026-87565: Information leak in Passwords. Reported by Google. - CVE-2026-87597: UI misrepresentation in CustomTabs. Reported by Google. - CVE-2026-87624: UI misrepresentation in Passwords. Reported by Google. - CVE-2026-87605: Missing authorization in Contacts. Reported by Google. - CVE-2026-87490: Information leak in Transactions Platform. Reported by Google. - CVE-2026-87583: UI misrepresentation in Passwords. Reported by Google. - CVE-2026-87509: Incorrect authorization in Updater. Reported by Google. - CVE-2026-87473: Incorrect authorization in FileHandling. Reported by Google. - CVE-2026-87461: Information leak in Core. Reported by Google. - CVE-2026-87631: Missing authorization in DOM. Reported by Google. - CVE-2026-87469: Improper input validation in Extensions. Reported by Jeong Woo Lee (@eclipse07077). - CVE-2026-87489: Memory corruption in V8. Reported by Google. - CVE-2026-87575: Incorrect authorization in Loader. Reported by Google. - CVE-2026-87571: Improper certificate validation in Loader. Reported by Google. - CVE-2026-87477: Information leak in Core. Reported by Google. - CVE-2026-87551: Improper certificate validation in CORS. Reported by Google. - CVE-2026-87608: Improper certificate validation in FedCM. Reported by Google. - CVE-2026-87437: Information leak in Frames. Reported by Google. - CVE-2026-87602: Out of bounds read in ANGLE. Reported by Hyeongeun Ji of JeroScope. - CVE-2026-87601: Race condition in V8. Reported by Salvatore Gulizia (nickname: Serotav). - CVE-2026-87544: Incorrect authorization in Extensions. Reported by antoniosmr02. - CVE-2026-87430: Buffer overflow in WebRTC. Reported by k-kyuno. - CVE-2026-87593: Information leak in Editing. Reported by Google. - CVE-2026-91726: Out of bounds read in WebGL. Reported by Google. - CVE-2026-91721: Use after free in Internals. Reported by xinyang. - CVE-2026-91749: Use after free in Workers. Reported by WinD39 - Huynh Dinh Vu. - CVE-2026-91724: Use after free in Input. Reported by Hafiizh. - CVE-2026-91728: Integer overflow in V8. Reported by Jihyeon Jeong (Compsec Lab, Seoul National University / Research Intern). - CVE-2026-91734: Incorrect authorization in Core. Reported by Google. - CVE-2026-91727: Incorrect reference resolution in Extensions. Reported by Google. - CVE-2026-91743: Race condition in Core. Reported by Google. - CVE-2026-91744: Race condition in PlatformIntegration. Reported by Google. - CVE-2026-91712: Race condition in Extensions. Reported by Google. - CVE-2026-91748: Race condition in Extensions. Reported by Google. - CVE-2026-91720: Uninitialized resource in ANGLE. Reported by Google. - CVE-2026-91731: Type confusion in Compositing. Reported by Google. - CVE-2026-91747: Use after free in Skia. Reported by Google. - CVE-2026-91733: Improper state validation in Skia. Reported by Google. - CVE-2026-91741: Type confusion in CacheStorage. Reported by Salvatore Gulizia (nickname: Serotav). - CVE-2026-91709: Type confusion in ServiceWorker. Reported by Jihyeon Jeong (Compsec Lab, Seoul National University / Research Intern). - CVE-2026-91717: Missing authorization in Android. Reported by jodyritonga. - CVE-2026-91735: Incorrect authorization in WebUI. Reported by Google. - CVE-2026-91708: Race condition in Network. Reported by Google. - CVE-2026-91736: Use after free in DOM. Reported by Google. - CVE-2026-91740: Uninitialized resource in Skia. Reported by Google. - CVE-2026-91710: Use after free in WebAppInstalls. Reported by Google. - CVE-2026-91718: Use after free in Core. Reported by Google. - CVE-2026-91716: Use after free in Auth. Reported by Google. - CVE-2026-91746: Integer overflow in Compositing. Reported by Google. - CVE-2026-91729: Use after free in DigitalCredentials. Reported by sean geofrey. - CVE-2026-91737: Use after free in PDF. Reported by SeungMyung Lee (@sm1ee), Siung kim (@ksw9722). - CVE-2026-91711: Out of bounds write in ServiceWorker. Reported by Cristian Di Nicola (@crih.exe). - CVE-2026-91715: Type confusion in ServiceWorker. Reported by Cristian Di Nicola (@crih.exe). - CVE-2026-91745: Use after free in V8. Reported by Google. - CVE-2026-91723: Race condition in WebAppInstalls. Reported by Luan Herrera (@lbherrera_). - CVE-2026-91732: Missing authorization in AppManifest. Reported by pakhunov.anton.n. - CVE-2026-91742: Confused deputy in PriceTracking. Reported by Google. - CVE-2026-91714: Observable discrepancy in Fonts. Reported by Google. - CVE-2026-91725: Observable discrepancy in CSS. Reported by Google. - CVE-2026-91739: Missing authorization in Transactions Platform. Reported by Google. - CVE-2026-91713: Missing authorization in Browser. Reported by Google. - CVE-2026-91738: Improper input validation in ANGLE. Reported by Google. - CVE-2026-91730: Incomplete cleanup in GetUserMedia. Reported by Keita Sode and Daisuke Hatakeyama (SYZD Research). - CVE-2026-91722: Use after free in Input. Reported by TIENPA. - CVE-2026-91719: Code injection in XML. Reported by Zabith Mohammed (@nmzabith). * d/copyright: - delete //third_party/cpython3/. - delete //third_party/node/node_modules/typescript/lib/. * d/control: add a build-dep on node-typescript. * d/scripts/customize-typescript.sh: copy debian's node-typescript into the chromium build tree and patch it to match what upstream uses. * d/rules: call out to customize-typescript.sh where needed. * d/patches: - debianization/cross-build.patch: refresh. - debianization/rustc-bootstrap.patch: refresh. - debianization/pre-gen.patch: refresh. - disable/google-api-warning.patch: refresh. - disable/clang-version-check.patch: refresh. - disable/libei.patch: refresh. - disable/node-ts.patch: refresh. - trixie/gn-inputs2.patch: refresh [trixie, bookworm]. - trixie/revert-v8-sanitize.patch: drop, no longer needed. - trixie/gn-unused-vars.patch: drop w/ newer generate-ninja [sid]. - llvm-22/clang22.patch: refresh and also drop Wno-stringop-overread. - ungoogled/disable-ai.patch: sync from u-c. - ungoogled/disable-mei-preload.patch: sync from u-c. - ungoogled/disable-privacy-sandbox.patch: sync from u-c. - fixes/crubit.patch: add patch to not use crubit (until we get crubit packaged for debian). - fixes/glic.patch: add another glic interface build fix. - fixes/autofill-binarypb.patch: add a new fix for the missing DE.binarypb blob. - fixes/only-address-sanitizer.patch: add patch to fix undefined __sanitizer_set_death_callback() symbols. - system/opus.patch: fix additional locations that were including bundled opus headers. - system/tsc.patch: don't fail the build due to file mismatches between the bundled typescript and debian's node-typescript. - system/tsc2.patch: don't raise an assertion error about missing tsc stuff that we purposefully removed. - debianization/strip-rlibs.patch: add patch to strip debugging symbols from libstd-rust-dev's .rlibs before we use them. . [ Timothy Pearson ] * d/patches/ppc64le: - v8/0002-Add-ppc64-trap-instructions.patch: drop, no longer needed - workarounds/HACK-debian-clang-disable-pa-musttail.patch: refresh for upstream changes - third_party/0002-regenerate-xnn-buildgn.patch: refresh for upstream changes . [ Daniel Richard G. ] * d/control, d/rules, d/patches/debianization/cross-build.patch: Get cross builds working again after various recent updates broke it, along with improvements in the overall approach and copy-editing of the documentation in the patch file. * d/control: add versioning to the node-typescript build-dep [sid]. * d/deb_pre_gen.py: Update to account for /usr/bin/ prefix on python3. * d/patches: - bookworm/gn-absl.patch: Refresh [bookworm]. - trixie/gn-funcs.patch: Zap the newer expand_directory() function [trixie, bookworm]. - rust-1.85/mojo-features.patch: Refresh. - system/python.patch: New patch to use the system Python interpreter. - trixie/gn-unused-vars.patch: Refresh (and fix patch format) [trixie, bookworm]. * d/rules: Update template-variable convention used when generating the man page, to match an upstream change (crrev.com/c/7253206). . [ Jianfeng Liu ] * d/rules: enable vaapi for arm64 because upstream has supported both v4l2_codec and vaapi since v152. chromium (152.0.7977.82-1) unstable; urgency=high . [ Andres Salomon ] * d/patches: - debianization/clang-version: fix to stop using gnu ld and instead use llvm's lld-22 when linking rust libs. - debianization/rust-disable-debugsym.patch: refresh for prior patch changes. * New upstream security release. - CVE-2026-85046: Type confusion in V8. Reported by Salvatore Gulizia (nickname: Serotav). - CVE-2026-85052: Out of bounds read in CrashReporting. Reported by Google. - CVE-2026-85043: Incomplete cleanup in Network. Reported by Google. - CVE-2026-85048: Use after free in Compositing. Reported by Ngoc Hieu. - CVE-2026-85045: Race condition in V8. Reported by Brendan Dolan-Gavitt, XBOW. - CVE-2026-85050: Out of bounds write in WebGL. Reported by Google. - CVE-2026-85053: Improper resource exposure in CacheStorage. Reported by Salvatore Gulizia (Serotav). - CVE-2026-85042: Use after free in DevTools. Reported by Google. - CVE-2026-85049: Use after free in Skia. Reported by Google. - CVE-2026-85051: Type confusion in Compositing. Reported by Google. - CVE-2026-85047: Improper input validation in Transactions Platform. Reported by Google. - CVE-2026-85044: Use of released resource in Mobile. Reported by Google. chromium (152.0.7977.75-1) unstable; urgency=high . [ Andres Salomon ] * New upstream security release. - CVE-2026-84353: Use after free in Shared Tab Groups. Reported by Google. - CVE-2026-84352: Use after free in WebGL. Reported by Google. - CVE-2026-84354: Incorrect authorization in FileSystem. Reported by Google. - CVE-2026-84359: Information leak in Skia. Reported by Google. - CVE-2026-84357: Improper input validation in Omnibox. Reported by Google. - CVE-2026-84324: Use after free in Proxy. Reported by Google. - CVE-2026-84349: Use after free in Browser. Reported by Google. - CVE-2026-84326: Uninitialized resource in V8. Reported by Jihyeon Jeong (Compsec Lab, Seoul National University / Research Intern). - CVE-2026-84333: Use after free in Dawn. Reported by Google. - CVE-2026-84351: Buffer overflow in GPU. Reported by Cassio Lima. - CVE-2026-84325: Improper input validation in DataTransfer. Reported by Google. - CVE-2026-84328: Missing authorization in FileSystem. Reported by Google. - CVE-2026-84347: Use after free in WebRTC. Reported by Google. - CVE-2026-84323: Missing authorization in FileSystem. Reported by Google. - CVE-2026-84355: Incorrect authorization in Navigation. Reported by Google. - CVE-2026-84358: Improper privilege management in Downloads. Reported by Google. - CVE-2026-84332: Incorrect authorization in SiteSettings. Reported by Google. - CVE-2026-84330: UI misrepresentation in FullScreen. Reported by Google. - CVE-2026-84334: Incorrect authorization in Chromoting. Reported by Google. - CVE-2026-84348: Information leak in MediaCapture. Reported by Google. - CVE-2026-84335: Incorrect authorization in TabStrip. Reported by Google. - CVE-2026-84327: Incorrect authorization in Autofill. Reported by Google. - CVE-2026-84329: Confused deputy in CredentialProvider. Reported by Google. - CVE-2026-84356: UI misrepresentation in FullScreen. Reported by Francesco Topol (k4tedu). - CVE-2026-84350: Use after free in TabStrip. Reported by Google. - CVE-2026-84331: Incorrect authorization in Actor. Reported by Google. * d/patches: - trixie/rust-no-alloc-shim.patch: drop, no longer needed with newer rust. - trixie/rust-sanitize.patch: drop, no longer needed with newer rust. - debianization/rust-disable-debugsym.patch: add --no-mmap-output-file to link flags (another attempt to reduce armhf memory usage). . [ Daniel Richard G. ] * d/deb_pre_gen.py: Exclude a couple of targets from the pre-gen process as making them causes files to be written to the source tree. . [ Timothy Pearson ] * d/patches/ppc64le: - third_party/0003-third_party-ffmpeg-Add-ppc64-generated-config.patch: Fix FTBFS on ppc64le systems due to FFmpeg patch update. chromium (152.0.7977.64-1) unstable; urgency=high . * New upstream stable release. - CVE-2026-79282: Use after free in ANGLE. Reported by Goodluck. - CVE-2026-79290: Use after free in Aura. Reported by Google. - CVE-2026-79054: Use after free in Chromecast. Reported by Google. - CVE-2026-79121: Improper input validation in Chromecast. Reported by Google. - CVE-2026-79224: Use after free in Chromecast. Reported by Google. - CVE-2026-79052: Use after free in Aura. Reported by Google. - CVE-2026-79150: Use after free in Views. Reported by Google. - CVE-2026-78935: Use of uninitialized variable in Mobile. Reported by Google. - CVE-2026-79012: Use after free in Safebrowsing. Reported by Google. - CVE-2026-79200: Use after free in Aura. Reported by Google. - CVE-2026-78989: Out of bounds read in ANGLE. Reported by Đặng Thế Tuyến. - CVE-2026-79069: Memory corruption in Tint. Reported by andryskowski.michal. - CVE-2026-79175: Type confusion in Accessibility. Reported by Google. - CVE-2026-79218: Incorrect authorization in Sandbox. Reported by Google. - CVE-2026-79195: Use after free in Script. Reported by Google. - CVE-2026-78939: Use after free in Chromecast. Reported by Google. - CVE-2026-79194: Use after free in Chromoting. Reported by Google. - CVE-2026-79247: Use after free in Chromoting. Reported by Google. - CVE-2026-79219: Use after free in Bluetooth. Reported by Google. - CVE-2026-79047: Use after free in Views. Reported by Google. - CVE-2026-79292: Integer overflow in Chromecast. Reported by Google. - CVE-2026-78986: Uninitialized resource in GPU. Reported by Google. - CVE-2026-79039: Use after free in Mobile. Reported by Google. - CVE-2026-78934: Race condition in ReadAloud. Reported by Google. - CVE-2026-79011: UI misrepresentation in Browser. Reported by Google. - CVE-2026-78911: Incorrect authorization in USB. Reported by Google. - CVE-2026-79257: Use after free in Views. Reported by Google. - CVE-2026-79202: Use after free in Chromecast. Reported by Google. - CVE-2026-79212: Missing authorization in Passwords. Reported by Google. - CVE-2026-79183: Use after free in Accessibility. Reported by Google. - CVE-2026-79155: Race condition in FileSystem. Reported by Google. - CVE-2026-79093: Incorrect authorization in Paint. Reported by Google. - CVE-2026-79019: Out of bounds write in ANGLE. Reported by Google. - CVE-2026-79187: Use after free in WebRTC. Reported by Google. - CVE-2026-79288: Improper input validation in Autofill. Reported by Google. - CVE-2026-79130: Buffer overflow in ANGLE. Reported by Google. - CVE-2026-78965: Uninitialized resource in ANGLE. Reported by Google. - CVE-2026-79117: Race condition in WebAppInstalls. Reported by Google. - CVE-2026-79082: Incorrect authorization in Transactions Platform. Reported by Google. - CVE-2026-79111: Improper input validation in Dawn. Reported by Google. - CVE-2026-79072: Improper state validation in Performance. Reported by Google. - CVE-2026-79142: Buffer overflow in ANGLE. Reported by Google. - CVE-2026-78948: Buffer overflow in WebGL. Reported by Google. - CVE-2026-78908: Information leak in Canvas. Reported by Google. - CVE-2026-78895: Information leak in Paint. Reported by Google. - CVE-2026-79043: Out of bounds write in ANGLE. Reported by Google. - CVE-2026-79235: Use after free in WebGL. Reported by Google. - CVE-2026-79232: Use after free in Aura. Reported by Google. - CVE-2026-79118: Uninitialized resource in ANGLE. Reported by Google. - CVE-2026-79174: Incorrect authorization in Extensions. Reported by 章鱼哥@aipyaipy.com. - CVE-2026-78900: Improper input validation in Media. Reported by Google. - CVE-2026-79188: Out of bounds write in ANGLE. Reported by Google. - CVE-2026-79189: Out of bounds write in ANGLE. Reported by Google. - CVE-2026-79048: Out of bounds write in ANGLE. Reported by Google. - CVE-2026-79240: Out of bounds write in ANGLE. Reported by Google. - CVE-2026-79014: Race condition in Autofill. Reported by Google. - CVE-2026-79198: Use after free in Platform. Reported by Google. - CVE-2026-79131: Out of bounds write in ANGLE. Reported by Google. - CVE-2026-79149: Use after free in ANGLE. Reported by Google. - CVE-2026-79275: Use after free in ANGLE. Reported by Google. - CVE-2026-79138: Out of bounds write in ANGLE. Reported by Google. - CVE-2026-79026: Use after free in Extensions. Reported by Google. - CVE-2026-79027: Use after free in WebRTC. Reported by Mozilla. - CVE-2026-78904: Type confusion in ANGLE. Reported by Google. - CVE-2026-78899: Use after free in V8. Reported by Jihyeon Jeong (Compsec Lab, Seoul National University / Research Intern). - CVE-2026-78954: Incorrect authorization in Extensions. Reported by Google. - CVE-2026-79274: Information leak in GPU. Reported by weihengqiuu. - CVE-2026-78938: Type confusion in V8. Reported by Zhenpeng (Leo) Lin at depthfirst. - CVE-2026-78952: Out of bounds write in Crashpad. Reported by Brendan Dolan-Gavitt, XBOW. - CVE-2026-79236: Type confusion in V8. Reported by Zhenpeng (Leo) Lin. - CVE-2026-79078: Use after free in FedCM. Reported by m0omo0d. - CVE-2026-79209: Type confusion in Animation. Reported by ochko. - CVE-2026-79030: Observable discrepancy in Autofill. Reported by Young Min Kim (@ylemkimon), CompSec Lab at Seoul National University. - CVE-2026-79216: Buffer overflow in Blink. Reported by Found by XBOW and triaged by Andrés Luksenberg. - CVE-2026-79007: Uninitialized resource in GPU. Reported by Google. - CVE-2026-78893: Information leak in QUIC. Reported by Google. - CVE-2026-79222: Incorrect authorization in CustomTabs. Reported by Google. - CVE-2026-79071: Race condition in GPU. Reported by Google. - CVE-2026-79076: Improper input validation in Sync. Reported by Google. - CVE-2026-79088: Incorrect authorization in FileSystem. Reported by Google. - CVE-2026-79104: Missing authorization in Sensor. Reported by Google. - CVE-2026-79044: Missing authorization in WebAppInstalls. Reported by Google. - CVE-2026-78958: Uninitialized resource in Skia. Reported by Google. - CVE-2026-78961: Incorrect authorization in Core. Reported by Google. - CVE-2026-79262: Incorrect authorization in Network. Reported by Google. - CVE-2026-79106: Improper input validation in Input. Reported by Google. - CVE-2026-79176: UI misrepresentation in Extensions. Reported by Google. - CVE-2026-78966: Externally controlled reference in QUIC. Reported by Google. - CVE-2026-79186: Incorrect authorization in Network. Reported by Google. - CVE-2026-79267: Race condition in Workers. Reported by Google. - CVE-2026-79016: Observable discrepancy in SVG. Reported by Google. - CVE-2026-79010: Operation on a resource after expiration or release in Network. Reported by Google. - CVE-2026-79286: Missing authorization in CustomTabs. Reported by Google. - CVE-2026-78945: Use after free in Views. Reported by Google. - CVE-2026-78999: Improper privilege management in Navigation. Reported by Google. - CVE-2026-78941: Information leak in Core. Reported by Google. - CVE-2026-79032: Improper input validation in Network. Reported by Google - CVE-2026-79109: Improper input validation in Printing. Reported by Google. - CVE-2026-79256: Externally controlled reference in WebView. Reported by Google. - CVE-2026-79237: Incorrect authorization in Navigation. Reported by Google. - CVE-2026-78898: Incorrect authorization in Downloads. Reported by Google - CVE-2026-78985: Incorrect reference resolution in FileSystem. Reported by Google. - CVE-2026-79028: Observable discrepancy in Network. Reported by Google. - CVE-2026-79210: Use after free in Audio. Reported by Google. - CVE-2026-79046: Race condition in Permissions. Reported by Google. - CVE-2026-79129: Use after free in Sessions. Reported by Google. - CVE-2026-78937: Use after free in Search. Reported by Google. - CVE-2026-78987: Information leak in Canvas. Reported by Google. - CVE-2026-78990: Use after free in Compositing. Reported by Google. - CVE-2026-78909: Use after free in Views. Reported by Google. - CVE-2026-79271: Information leak in DOM. Reported by Google. - CVE-2026-79144: Information leak in Skia. Reported by Google. - CVE-2026-79065: Improper input validation in Network. Reported by Google - CVE-2026-79192: Improper input validation in Variations. Reported by Google. - CVE-2026-79140: Use after free in Views. Reported by Google. - CVE-2026-79128: Use after free in Views. Reported by Google. - CVE-2026-78942: Incorrect reference resolution in Loader. Reported by Google. - CVE-2026-79116: Missing authorization in Viz. Reported by Google. - CVE-2026-79006: Protection mechanism failure in HttpsUpgrades. Reported by Google. - CVE-2026-79095: Information leak in Payments. Reported by Google. - CVE-2026-79084: Inadequate encryption strength in Notifications. Reported by Google. - CVE-2026-78991: Race condition in WebProtect. Reported by Google. - CVE-2026-79248: Incorrect authorization in Input. Reported by Google. - CVE-2026-78891: Buffer overflow in WebRTC. Reported by ngrunbaum. - CVE-2026-79031: Improper resource exposure in Preload. Reported by Google. - CVE-2026-79110: Missing authorization in Preload. Reported by Google. - CVE-2026-79136: Incorrect authorization in ServiceWorker. Reported by Google. - CVE-2026-78907: Incorrect authorization in WebProtect. Reported by Google. - CVE-2026-79087: Injection in Chrome Tabs. Reported by Google. - CVE-2026-79231: Buffer overflow in Media. Reported by Google. - CVE-2026-78969: Uninitialized resource in Video. Reported by Google. - CVE-2026-79137: Incorrect authorization in Extensions. Reported by Google. - CVE-2026-79057: Race condition in Start. Reported by Google. - CVE-2026-78894: Race condition in Payments. Reported by Google. - CVE-2026-79264: Incorrect reference resolution in Preload. Reported by Google. - CVE-2026-78910: Buffer overflow in V8. Reported by Google. - CVE-2026-79066: Improper input validation in Navigation. Reported by Google. - CVE-2026-79255: Improper input validation in WebRTC. Reported by Google. - CVE-2026-79086: Missing authorization in CustomTabs. Reported by Google. - CVE-2026-79038: Incorrect authorization in WebProtect. Reported by Google. - CVE-2026-78940: Improper initialization in Network. Reported by Google. - CVE-2026-79107: Incorrect authorization in TabGroups. Reported by Google - CVE-2026-79120: Uninitialized resource in ANGLE. Reported by Google. - CVE-2026-79270: Uninitialized resource in ANGLE. Reported by Google. - CVE-2026-79067: Missing authorization in Network. Reported by Google. - CVE-2026-79213: Incorrect authorization in WebAppInstalls. Reported by Google. - CVE-2026-78943: Improper input validation in Editing. Reported by Google - CVE-2026-79259: Improper input validation in Safebrowsing. Reported by Google. - CVE-2026-79208: Missing authorization in HTTP2. Reported by Google. - CVE-2026-79251: Improper input validation in Network. Reported by Google - CVE-2026-79226: Improper privilege management in Regional Capabilities. Reported by Google. - CVE-2026-79042: Missing authorization in Payments. Reported by Google. - CVE-2026-79122: Information leak in SignIn. Reported by Google. - CVE-2026-79199: Incorrect authorization in Network. Reported by Google. - CVE-2026-79013: Improper input validation in Sync. Reported by Google. - CVE-2026-79074: Information leak in Network. Reported by Google. - CVE-2026-79215: Integer overflow in WebGL. Reported by Google. - CVE-2026-79049: Incorrect reference resolution in Passwords. Reported by Google. - CVE-2026-79132: Improper input validation in Input. Reported by Google. - CVE-2026-79201: Improper access control in Workers. Reported by Google. - CVE-2026-79051: Incorrect authorization in Loader. Reported by Google. - CVE-2026-79053: Missing authorization in Lighthouse. Reported by Google - CVE-2026-79285: Uninitialized resource in ANGLE. Reported by Google. - CVE-2026-78906: Race condition in ANGLE. Reported by Google. - CVE-2026-79250: UI misrepresentation in Navigation. Reported by Google. - CVE-2026-79020: Out of bounds read in Skia. Reported by Google. - CVE-2026-79217: Incorrect authorization in Mobile. Reported by Google. - CVE-2026-79204: UI misrepresentation in Input. Reported by Google. - CVE-2026-78912: UI misrepresentation in Browser. Reported by Google. - CVE-2026-78955: Observable discrepancy in PerformanceAPIs. Reported by Google. - CVE-2026-79143: Incorrect authorization in FileSystem. Reported by Google. - CVE-2026-79241: Out of bounds read in GPU. Reported by Google. - CVE-2026-78967: Missing authorization in BFCache. Reported by Google. - CVE-2026-79214: Improper input validation in Preload. Reported by Google - CVE-2026-79228: Incorrect authorization in SiteIsolation. Reported by Google. - CVE-2026-78953: Missing authorization in SiteIsolation. Reported by Google. - CVE-2026-79229: Uninitialized resource in ANGLE. Reported by Google. - CVE-2026-79002: Incorrect authorization in SiteIsolation. Reported by Google. - CVE-2026-79272: Improper input validation in FindInPage. Reported by Google. - CVE-2026-79127: Out of bounds write in ANGLE. Reported by Google. - CVE-2026-79151: Improper input validation in Safebrowsing. Reported by Google. - CVE-2026-78936: Observable discrepancy in CustomTabs. Reported by Google - CVE-2026-78905: Type confusion in ANGLE. Reported by Google. - CVE-2026-79050: Incorrect authorization in Network. Reported by Google. - CVE-2026-79008: Improper input validation in GPU. Reported by Google. - CVE-2026-78975: Incorrect authorization in DOM. Reported by Google. - CVE-2026-79287: Observable discrepancy in Forms. Reported by Google. - CVE-2026-79094: Race condition in Workers. Reported by Google. - CVE-2026-79173: UI misrepresentation in WebAppInstalls. Reported by Google. - CVE-2026-78976: Improper input validation in StorageAccessAPI. Reported by Google. - CVE-2026-79276: Improper privilege management in FileSystem. Reported by Google. - CVE-2026-79191: Incorrect authorization in SiteIsolation. Reported by Google. - CVE-2026-79099: Missing authorization in Network. Reported by Google. - CVE-2026-79024: Information leak in ServiceWorker. Reported by Google. - CVE-2026-79193: Information leak in Canvas. Reported by Google. - CVE-2026-79242: Observable discrepancy in HTML. Reported by Google. - CVE-2026-79180: UI misrepresentation in CustomTabs. Reported by Google. - CVE-2026-79293: Information leak in Animation. Reported by Google. - CVE-2026-79023: Incorrect authorization in Editing. Reported by Google. - CVE-2026-79146: Information leak in CustomTabs. Reported by Google. - CVE-2026-79238: Incorrect authorization in ServiceWorker. Reported by Google. - CVE-2026-78949: Observable discrepancy in CustomTabs. Reported by Google - CVE-2026-79291: Information leak in CSS. Reported by Google. - CVE-2026-79283: UI misrepresentation in Geometry. Reported by Google. - CVE-2026-78892: Incorrect authorization in Chromoting. Reported by Google. - CVE-2026-79070: Incorrect reference resolution in Cache. Reported by Google. - CVE-2026-79205: Incorrect authorization in Network. Reported by Google. - CVE-2026-78903: Incomplete cleanup in SiteIsolation. Reported by Google - CVE-2026-78959: Improper handling of case sensitivity in FileSystem. Reported by Google. - CVE-2026-79234: Injection in CSS. Reported by Google. - CVE-2026-78983: Use after free in Views. Reported by Google. - CVE-2026-79083: Improper enforcement of behavioral workflow in Media. Reported by Google. - CVE-2026-78944: Use after free in DevTools. Reported by yupyon.itome. - CVE-2026-79178: Incorrect authorization in Web Authentication (Passkeys & Security Keys). Reported by Google. - CVE-2026-79059: Information leak in BFCache. Reported by Google. - CVE-2026-79245: Use after free in UI. Reported by Google. - CVE-2026-78978: Out of bounds read in ANGLE. Reported by Google. - CVE-2026-79103: Incorrect reference resolution in Speech. Reported by Google. - CVE-2026-79154: Missing authorization in DevTools. Reported by Google. - CVE-2026-79230: Improper input validation in ANGLE. Reported by Google. - CVE-2026-79068: Improper resource exposure in StreamsAPI. Reported by Google. - CVE-2026-79269: Uninitialized resource in ANGLE. Reported by Google. - CVE-2026-79085: Missing authorization in Network. Reported by Google. - CVE-2026-79134: Incorrect authorization in GetUserMedia. Reported by Google. - CVE-2026-79064: Use after free in Network. Reported by Google. - CVE-2026-79003: Incorrect authorization in Device. Reported by Google. - CVE-2026-79220: Information leak in Network. Reported by Google. - CVE-2026-78951: Use after free in ServiceWorker. Reported by Google. - CVE-2026-79249: Code injection in Bisection. Reported by Google. - CVE-2026-79091: Use after free in Bluetooth. Reported by Google. - CVE-2026-79265: Incomplete cleanup in GetUserMedia. Reported by Google. - CVE-2026-78913: Use after free in Chromoting. Reported by Google. - CVE-2026-79258: Incorrect authorization in WebXR. Reported by Google. - CVE-2026-79211: Incorrect authorization in USB. Reported by hongan. - CVE-2026-79252: Information leak in ServiceWorker. Reported by Google. - CVE-2026-78962: Uninitialized resource in WebXR. Reported by Google. - CVE-2026-78901: Race condition in V8. Reported by Google. - CVE-2026-79097: Use after free in V8. Reported by Google. - CVE-2026-79227: Type confusion in DevTools. Reported by Google. - CVE-2026-79203: Improper input validation in DevTools. Reported by Google. - CVE-2026-79033: Insufficient control flow management in DevTools. Reported by Google. - CVE-2026-79139: Improper input validation in Media. Reported by Google. - CVE-2026-79221: Uninitialized resource in Dawn. Reported by Google. - CVE-2026-79034: Information leak in CORS. Reported by Google. - CVE-2026-79075: Information leak in Geolocation. Reported by Google. - CVE-2026-78960: Information leak in Extensions. Reported by Oran Simhony from Palo Alto Networks. - CVE-2026-78984: Uninitialized resource in GPU. Reported by Google. - CVE-2026-78963: Improper input validation in Media. Reported by Google. - CVE-2026-79004: Out of bounds read in Media. Reported by Google. - CVE-2026-79182: Improper input validation in Media. Reported by Google. - CVE-2026-79185: Information leak in DOM. Reported by avlidienbrunn. - CVE-2026-79073: Improper state validation in Parser. Reported by Google. - CVE-2026-79266: Use after free in DevTools. Reported by Google. - CVE-2026-79025: Improper input validation in Workers. Reported by Google - CVE-2026-79141: Incorrect authorization in Browser. Reported by M. Fauzan Wijaya (Gh05t666nero). - CVE-2026-78974: UI misrepresentation in Linux Toolkit Theming. Reported by Francesco Topol. - CVE-2026-79055: Information leak in Sharing. Reported by Google. - CVE-2026-79263: Race condition in Extensions. Reported by Google. - CVE-2026-79124: Information leak in Intents. Reported by Google. - CVE-2026-79184: Missing authorization in Preload. Reported by Google. - CVE-2026-79289: Improper control of a resource through its lifetime in Workers. Reported by Google. - CVE-2026-79001: Information leak in Bluetooth. Reported by Google. - CVE-2026-79077: Incorrect authorization in WebProtect. Reported by Google. - CVE-2026-78950: Integer overflow in WebRTC. Reported by Ashutosh. - CVE-2026-79196: Race condition in Editing. Reported by Google. - CVE-2026-79000: Improper input validation in DeviceBoundSessionCredentials. Reported by Google. - CVE-2026-78979: Race condition in Core. Reported by Google. - CVE-2026-79181: Observable discrepancy in Glic. Reported by Google. - CVE-2026-79190: Incorrect authorization in Extensions. Reported by Google. - CVE-2026-79206: Out of bounds read in FileSystem. Reported by Google. - CVE-2026-78897: Missing authorization in BrowserTag. Reported by Google. - CVE-2026-79119: Use after free in PDF. Reported by Google. - CVE-2026-79089: Race condition in Transactions Platform. Reported by Google. - CVE-2026-79147: Information leak in Skia. Reported by Google. - CVE-2026-79098: UI misrepresentation in PermissionElement. Reported by Google. - CVE-2026-79022: UI misrepresentation in Transactions Platform. Reported by Google. - CVE-2026-79233: UI misrepresentation in CustomTabs. Reported by Google. - CVE-2026-79261: Incorrect authorization in Controls. Reported by Google - CVE-2026-78977: Uninitialized resource in GPU. Reported by Google. - CVE-2026-79040: Uninitialized resource in GPU. Reported by Google. - CVE-2026-79273: Incorrect reference resolution in WebView. Reported by Google. - CVE-2026-79243: Improper input validation in ReadingList. Reported by Orange Tsai (@orange_8361) of DEVCORE Research Team. - CVE-2026-79123: Improper input validation in NTP Footer. Reported by Orange Tsai (@orange_8361) of DEVCORE Research Team. - CVE-2026-79005: Incorrect authorization in StorageAccessAPI. Reported by Google. - CVE-2026-79090: Improper privilege management in Actor. Reported by Google. - CVE-2026-78946: Incorrect authorization in Select. Reported by Google. - CVE-2026-78968: Missing authorization in Core. Reported by Google. - CVE-2026-79041: Missing authorization in Browser. Reported by Google. - CVE-2026-79284: UI misrepresentation in Core. Reported by Google. - CVE-2026-78896: Information leak in StorageAccessAPI. Reported by Google - CVE-2026-79058: Missing authorization in Passwords. Reported by Google. - CVE-2026-79009: UI misrepresentation in UI. Reported by Google. - CVE-2026-79060: Incorrect authorization in StorageAccessAPI. Reported by Google. - CVE-2026-79177: Incorrect authorization in Media. Reported by Google. - CVE-2026-78956: Type confusion in V8. Reported by Google. - CVE-2026-79239: Out of bounds read in Tint. Reported by Michal Andryskowski, Imperial College London. - CVE-2026-79015: Improper input validation in ServiceWorker. Reported by Google. - CVE-2026-79108: UI misrepresentation in Web Authentication (Passkeys & Security Keys). Reported by Google. - CVE-2026-79056: Use after free in ServiceWorker. Reported by Google. - CVE-2026-79018: Information leak in FoldableAPIs. Reported by Google. - CVE-2026-78980: Improper input validation in ReaderMode. Reported by Google. - CVE-2026-78947: Incomplete cleanup in Chromium. Reported by Microsoft Edge. - CVE-2026-79244: Use after free in Animation. Reported by Google. - CVE-2026-79112: Out of bounds read in Skia. Reported by Quan Huynh x Amaterasu. - CVE-2026-79246: Information leak in DataTransfer. Reported by Google. - CVE-2026-79223: Integer overflow in Chromium. Reported by Youngjin Ju. - CVE-2026-79045: Type confusion in V8. Reported by Google. - CVE-2026-79197: Use after free in V8. Reported by Google. - CVE-2026-79148: Off-by-one error in DevTools. Reported by Google. - CVE-2026-79125: Information leak in XR. Reported by Google. - CVE-2026-79207: Information leak in Passwords. Reported by Google. - CVE-2026-79017: Race condition in Extensions. Reported by Google. - CVE-2026-79105: Improper input validation in Mobile. Reported by Google. - CVE-2026-79225: Incorrect authorization in Browser. Reported by Google. - CVE-2026-79021: Missing authorization in InterestGroups. Reported by Google. - CVE-2026-79133: Incorrect authorization in Forms. Reported by Google. - CVE-2026-79179: Incorrect authorization in DOM. Reported by Google. - CVE-2026-79152: Incorrect authorization in CustomTabs. Reported by Google. - CVE-2026-78981: Information leak in Mobile. Reported by Google. - CVE-2026-78957: Information leak in Mobile. Reported by Google. - CVE-2026-79126: Incorrect provision of specified functionality in Proxy. Reported by Google. - CVE-2026-78915: Race condition in Enterprise. Reported by Google. - CVE-2026-79253: Improper input validation in Network. Reported by Google - CVE-2026-79260: Improper input validation in Cookies. Reported by Google - CVE-2026-79254: Incorrect reference resolution in CustomTabs. Reported by Google. - CVE-2026-78914: Uninitialized resource in Skia. Reported by Google. - CVE-2026-78964: Use after free in Sync. Reported by Google. * d/patches: - debianization/rustc-bootstrap.patch: update for upstream renamed var. - fixes/libcpp-headers.patch: refresh. - disable/catapult.patch: refresh. - system/llvm.patch: refresh. - ungoogled/disable-ai.patch: sync from u-c. - ungoogled/disable-privacy-sandbox.patch: sync from u-c. - system/rust-cbor.patch: add a patch (taken from u-c) that skips using vendored rust Crubit. - llvm-22/shut-up-clang.patch: add patch to stop clang from complaining every single time it's called if gcc crossbuild libs are installed. - debianization/rust-disable-debugsym.patch: do some more build flags to reduce size of rust libs on armhf. . [ Daniel Richard G. ] * d/dummy/copy_file.py: Simple script to copy a file from GN. * d/dummy/enum_conversions.ts: Dummy version of a file which is normally generated by running gen_enum_conversions.ts directly via node(1), which is not supported by Node.js prior to v26. * d/patches: - bookworm/dav1d-drop-hdr.patch: Refresh [bookworm]. - bookworm/gn-absl.patch: Refresh [bookworm]. - bookworm/gn-revert-path-exists.patch: Refresh and extend [bookworm]. - disable/node-ts.patch: Use the dummy enum_conversions.ts file instead of running the TypeScript generation logic normally, so that the build doesn't break due to our non-bleeding-edge nodejs package. - llvm-22/clang22.patch: clang-22 still doesn't know about -Wlifetime-safety-permissive, and some other lifetime-safety flags. - trixie/gn-additional-outputs.patch: Drop, consolidated into gn-unused-vars.patch . - trixie/gn-expand-dir-allowlist.patch: Drop, consolidated into gn-unused-vars.patch . - trixie/gn-module-name.patch: Refresh [trixie, bookworm]. - trixie/gn-unused-vars.patch: Subsume two other patches, and add more such variables. . [ Timothy Pearson ] * d/patches/ppc64le: - third_party/0002-regenerate-xnn-buildgn.patch: refresh for upstream changes - third_party/0003-third_party-libvpx-Add-ppc64-generated-config.patch: regenerate - 0001-Add-pregenerated-config-for-libaom-on-ppc64.patch: refresh for upstream changes - third_party/skia-vsx-instructions.patch: Reenable VSX and reset to POWER ISA 2.07 baseline (POWER8) . [ Jianfeng Liu ] * d/patches/loongarch64: - 0015-ffmpeg-support-for-loongarch.patch: refresh for upstream chromium (151.0.7922.173-1) unstable; urgency=high . * d/rules, d/control: switch to clang-22 now that it's also backported to stable and olstable (closes: #1124059). * d/patches: - llvm-19/static-assert.patch: drop, workaround no longer needed. - llvm-19/clang-19-crash.patch: drop, workaround no longer needed. - llvm-19/octal.patch: drop, workaround no longer needed. - llvm-19/value-or.patch: drop, workaround no longer needed. - llvm-19/clang19.patch: drop, workaround no longer needed. - llvm-19/iota.patch: drop, workaround no longer needed. - llvm-19/i18n-builder-enum.patch: drop, workaround no longer needed. - llvm-19/0001-revert-v8-libm.patch: drop, workaround no longer needed. - llvm-19/0002-revert-v8-libm.patch: drop, workaround no longer needed. - llvm-19/0003-revert-v8-libm.patch: drop, workaround no longer needed. - llvm-19/0004-revert-v8-libm.patch: drop, workaround no longer needed. - llvm-19/0005-revert-v8-libm.patch: drop, workaround no longer needed. - llvm-19/0007-revert-v8-libm.patch: drop, workaround no longer needed. - llvm-19/0008-revert-v8-libm.patch: drop, workaround no longer needed. - llvm-19/0009-revert-v8-libm.patch: drop, workaround no longer needed. - llvm-19/0011-revert-v8-libm.patch: drop, workaround no longer needed. - llvm-19/privatefriends.patch: drop, workaround no longer needed. - llvm-19/constexpr.patch: drop, workaround no longer needed. - system/llvm.patch: add patch to remove dependencies on vendored llvm. - llvm-22/clang22.patch: add patch for unsupported compiler options. - llvm-19/clone-traits.patch -> llvm-22/clone-traits.patch. - llvm-19/const-profile.patch -> llvm-22/const-profile.patch. - llvm-19/keyfactory.patch -> llvm-22/keyfactory.patch. - llvm-19/raw-ref-map-find.patch -> llvm-22/raw-ref-map-find.patch. - ungoogled/disable-tos-dialog.patch: add patch from u-c to disable initial pop-up terms of service screen (closes: #1145071). * New upstream security release. - CVE-2026-76017: Use after free in Chromoting. Reported by Google. - CVE-2026-76018: Privilege elevation in Import. Reported by Google. - CVE-2026-76019: Incorrect authorization in Workers. Reported by Anonymous. - CVE-2026-76020: Race condition in V8. Reported by Salvatore Gulizia (nickname: Serotav). - CVE-2026-76021: Use after free in DOM. Reported by Google BigSleep@Grape. - CVE-2026-76022: Buffer overflow in Network. Reported by 0xAlessandro. - CVE-2026-76023: Improper resource control in Linux Toolkit Theming. Reported by Keita Sode and Daisuke Hatakeyama of SYZD Research. chromium (151.0.7922.169-1) unstable; urgency=high . * d/rules: remove optimize_for_size=true on armhf, as it didn't help. * d/patches/debianization/rust-disable-debugsym.patch: add patch to disable debug symbols for rust libs (to hopefully fix armhf linking). * New upstream security release. - CVE-2026-76034: Buffer overflow in WebGL. Reported by Google. - CVE-2026-76036: Buffer overflow in Dawn. Reported by Google. - CVE-2026-76033: Inappropriate implementation in CORS. Reported by Google - CVE-2026-76037: Link following in CredentialProvider. Reported by Google - CVE-2026-76044: Race condition in USB. Reported by Google. - CVE-2026-76039: Incorrect reference resolution in Core. Reported by Google. - CVE-2026-76040: Use after free in Browser. Reported by Google. - CVE-2026-76035: Inappropriate implementation in Media. Reported by Google. - CVE-2026-76042: Use of uninitialized resource in GPU. Reported by Google - CVE-2026-76046: Buffer overflow in ANGLE. Reported by Google. - CVE-2026-76043: Incorrect calculation in V8. Reported by Raghav Maheshwari. - CVE-2026-76041: Information leak in Skia. Reported by Google. - CVE-2026-76047: Type confusion in V8. Reported by ywatanabee. - CVE-2026-76038: Type confusion in V8. Reported by un3xploitable && GF. - CVE-2026-76045: Use after free in WebGL. Reported by OpenAI Codex Security (amyb). chromium (151.0.7922.137-2) unstable; urgency=high . [ Andres Salomon ] * d/rules: set optimize_for_size=true on armhf in an attempt to not run out of memory when linking. chromium (151.0.7922.137-1) unstable; urgency=high . [ Andres Salomon ] * d/patches/debianization/pre-gen.patch: Re-enable. * New upstream security release. - CVE-2026-19556: Use after free in V8. Reported by Jihyeon Jeong (Compsec Lab, Seoul National University / Research Intern). - CVE-2026-19557: Use after free in TabStrip. Reported by Google. - CVE-2026-19558: Use after free in Extensions. Reported by @bean5oup. - CVE-2026-19559: Use after free in HTML. Reported by Google. - CVE-2026-19560: Use after free in Blink. Reported by WinD39 - Huynh Dinh Vu. chromium (151.0.7922.108-2) unstable; urgency=high . [ Andres Salomon ] * d/patches/debianization/pre-gen.patch: Temporarily disable to make absolutely certain it is not related to armhf builds running out of memory while linking. chromium (151.0.7922.108-1) unstable; urgency=high . [ Daniel Richard G. ] * d/deb_pre_gen.py: Minor fixes to the pre-gen framework: - Always record target outputs in an .OUTPUTS file, even if a target has only a single output. This incurs only a small (tarball) size penalty, and catches cases where there is disagreement on which is the first output file of a .ninja target. - Update the handling logic for generate_css_js_files.js, as the first output file of the .ninja target changed from v150. - Add an extra check to ensure that target outputs are unique. * d/patches/debianization/pre-gen.patch: Tweak a script so that it outputs a constant UUID, instead of one dependent on the build path. * d/patches/system/golang.patch: Prevent the Go compiler from writing things into our home dir, or accessing the network. * d/scripts/init-pre-gen.sh: Don't hard-code the package name, as we might be doing init-pre-gen for ungoogled-chromium. . [ Andres Salomon ] * New upstream security release. - CVE-2026-19137: Use after free in WebGL. Reported by anonymous. - CVE-2026-19149: Use after free in Aura. Reported by Google. - CVE-2026-19154: Use after free in Skia. Reported by Google. - CVE-2026-19157: Out of bounds write in ANGLE. Reported by Google. - CVE-2026-19170: Use after free in WebGL. Reported by Muhammad Alifa Ramdhan, Pan ZhenPeng, Billy Jheng Bing Jhong of STAR Labs SG Pte. Ltd. - CVE-2026-19172: Use after free in Views. Reported by Google. - CVE-2026-19169: Insufficient validation of untrusted input in Contextual Tasks. Reported by Sven Dysthe (@svn-dys). - CVE-2026-19168: Inappropriate implementation in V8. Reported by XBOW and triaged by Andrés Luksenberg. - CVE-2026-19138: Heap buffer overflow in CrashReporting. Reported by Google. - CVE-2026-19139: Race in CredentialProvider. Reported by Google. - CVE-2026-19140: Use after free in GPU. Reported by Google. - CVE-2026-19141: Use after free in Resources. Reported by Google. - CVE-2026-19142: Use after free in Views. Reported by Google. - CVE-2026-19143: Insufficient validation of untrusted input in WebAPKs. Reported by Google. - CVE-2026-19144: Use after free in HTML. Reported by Google. - CVE-2026-19145: Use after free in Translate. Reported by Google. - CVE-2026-19146: Uninitialized Use in GPU. Reported by Google. - CVE-2026-19147: Use after free in Aura. Reported by Google. - CVE-2026-19148: Out of bounds write in GPU. Reported by Google. - CVE-2026-19150: Inappropriate implementation in V8. Reported by Google. - CVE-2026-19151: Use after free in V8. Reported by Google. - CVE-2026-19152: Inappropriate implementation in Navigation. Reported by Google. - CVE-2026-19153: Insufficient validation of untrusted input in Workers. Reported by Google. - CVE-2026-19155: Use after free in Payments. Reported by Google. - CVE-2026-19156: Heap buffer overflow in Base. Reported by Viktoria Zlatinova. - CVE-2026-19158: Use after free in Views. Reported by Google. - CVE-2026-19159: Use after free in Views. Reported by Google. - CVE-2026-19160: Uninitialized Use in Skia. Reported by Google. - CVE-2026-19161: Uninitialized Use in Skia. Reported by Google. - CVE-2026-19162: Out of bounds write in V8. Reported by OpenAI Codex Security (amyb). - CVE-2026-19163: Use after free in Media. Reported by Google. - CVE-2026-19164: Insufficient validation of untrusted input in Codecs. Reported by Google. - CVE-2026-19165: Use after free in Extensions. Reported by @bean5oup. - CVE-2026-19166: Use after free in Web Authentication. Reported by heesun. - CVE-2026-19167: Integer overflow in GPU. Reported by Google. - CVE-2026-19171: Use after free in Media. Reported by Google. - CVE-2026-19173: Out of bounds write in Skia. Reported by Vu Van Tien (@n0_Be3r). - CVE-2026-19174: Integer overflow in V8. Reported by Seunghyun Lee (@0x10n) of QED Audit (qedaudit.io). - CVE-2026-19175: Use after free in Payments. Reported by Google. - CVE-2026-19176: Use after free in Skia. Reported by WinD39 - Huynh Dinh Vu. - CVE-2026-19177: Insufficient validation of untrusted input in UI. Reported by Fabian Wahle (Hap Security). chromium (151.0.7922.71-1) unstable; urgency=high . [ Andres Salomon ] * New upstream security release. - CVE-2026-17650: Use after free in Compositing. Reported by Google. - CVE-2026-17651: Insufficient validation of untrusted input in Dawn. Reported by Google. - CVE-2026-17652: Use after free in Views. Reported by Google. - CVE-2026-17653: Use after free in Skia. Reported by Google. - CVE-2026-17654: Race in Updater. Reported by Google. - CVE-2026-17655: Insufficient validation of untrusted input in ANGLE. Reported by Google. - CVE-2026-17656: Use after free in Ozone. Reported by Google. - CVE-2026-17657: Use after free in Navigation. Reported by c6eed09fc8b174b0f3eebedcceb1e792. - CVE-2026-17658: Use after free in V8. Reported by Duc Nguyen of Calif.io in collaboration with OpenAI Codex Security. - CVE-2026-17659: Inappropriate implementation in SiteIsolation. Reported by Google. - CVE-2026-17660: Insufficient validation of untrusted input in Network. Reported by Google. - CVE-2026-17661: Use after free in Loader. Reported by Google. - CVE-2026-17662: Insufficient policy enforcement in Prefetch. Reported by Google. - CVE-2026-17663: Insufficient validation of untrusted input in GPU. Reported by Google. - CVE-2026-17664: Insufficient validation of untrusted input in Loader. Reported by Google. - CVE-2026-17665: Use after free in V8. Reported by Google. - CVE-2026-17666: Cryptographic Flaw in Enterprise. Reported by Google. - CVE-2026-17667: Uninitialized Use in ANGLE. Reported by Google. - CVE-2026-17668: Uninitialized Use in ANGLE. Reported by Google. - CVE-2026-17669: Inappropriate implementation in Chrome for iOS. Reported by Google. - CVE-2026-17670: Use after free in Views. Reported by Google. - CVE-2026-17671: Insufficient validation of untrusted input in ANGLE. Reported by Google. - CVE-2026-17672: Insufficient validation of untrusted input in Chromecast. Reported by Google. - CVE-2026-17673: Integer overflow in QUIC. Reported by Google. - CVE-2026-17674: Inappropriate implementation in HTML. Reported by Google. - CVE-2026-17675: Out of bounds write in ANGLE. Reported by Google. - CVE-2026-17676: Inappropriate implementation in ANGLE. Reported by Google. - CVE-2026-17677: Inappropriate implementation in ANGLE. Reported by Google. - CVE-2026-17678: Out of bounds read in ANGLE. Reported by Google. - CVE-2026-17679: Insufficient validation of untrusted input in Print Preview. Reported by Google. - CVE-2026-17680: Heap buffer overflow in Color. Reported by Google. - CVE-2026-17681: Insufficient validation of untrusted input in Web Authentication. Reported by Google. - CVE-2026-17682: Integer overflow in ANGLE. Reported by Google. - CVE-2026-17683: Inappropriate implementation in ANGLE. Reported by Google. - CVE-2026-17684: Insufficient validation of untrusted input in Chrome for iOS. Reported by Google. - CVE-2026-17685: Use after free in Autofill. Reported by Google. - CVE-2026-17686: Insufficient validation of untrusted input in Passwords. Reported by Google. - CVE-2026-17687: Type Confusion in ANGLE. Reported by Google. - CVE-2026-17688: Use after free in Input. Reported by Google. - CVE-2026-17689: Uninitialized Use in ANGLE. Reported by Google. - CVE-2026-17690: Insufficient validation of untrusted input in PDF. Reported by Google. - CVE-2026-17691: Out of bounds write in ANGLE. Reported by Google. - CVE-2026-17692: Use after free in DataTransfer. Reported by Google. - CVE-2026-17693: Inappropriate implementation in FileSystem. Reported by Google. - CVE-2026-17694: Use after free in DOM. Reported by Google. - CVE-2026-17695: Inappropriate implementation in ANGLE. Reported by Google. - CVE-2026-17696: Side-channel information leakage in Media. Reported by Google. - CVE-2026-17697: Type Confusion in ANGLE. Reported by Google. - CVE-2026-17698: Insufficient validation of untrusted input in UI. Reported by Google. - CVE-2026-17699: Use after free in Views. Reported by Google. - CVE-2026-17700: Insufficient validation of untrusted input in Actor. Reported by Google. - CVE-2026-17701: Out of bounds read in ANGLE. Reported by Google. - CVE-2026-17702: Inappropriate implementation in Skia. Reported by Google. - CVE-2026-17703: Policy bypass in Chrome for iOS. Reported by Google. - CVE-2026-17704: Use after free in ANGLE. Reported by Google. - CVE-2026-17705: Integer overflow in libxml. Reported by ebassi of Igalia. - CVE-2026-17706: Insufficient validation of untrusted input in Media. Reported by Google. - CVE-2026-17707: Uninitialized Use in Media. Reported by Google. - CVE-2026-17708: Use after free in Audio. Reported by Google. - CVE-2026-17709: Race in Downloads. Reported by Google. - CVE-2026-17710: Inappropriate implementation in MHTML. Reported by Google. - CVE-2026-17711: Race in Downloads. Reported by Google. - CVE-2026-17712: Race in Skia. Reported by Google. - CVE-2026-17713: Insufficient validation of untrusted input in Accessibility. Reported by Google. - CVE-2026-17714: Uninitialized Use in ANGLE. Reported by Google. - CVE-2026-17715: Inappropriate implementation in Passwords. Reported by Google. - CVE-2026-17716: Use after free in Updater. Reported by Google. - CVE-2026-17717: Integer overflow in ANGLE. Reported by Google. - CVE-2026-17718: Use after free in ANGLE. Reported by Google. - CVE-2026-17719: Use after free in Input. Reported by Google. - CVE-2026-17720: Insufficient policy enforcement in Passwords. Reported by Google. - CVE-2026-17721: Out of bounds write in ANGLE. Reported by Google. - CVE-2026-17722: Object lifecycle issue in WebView. Reported by Google. - CVE-2026-17723: Use after free in Media. Reported by Google. - CVE-2026-17724: Race in Chrome for iOS. Reported by Google. - CVE-2026-17725: Type Confusion in V8. Reported by nh.dev2022. - CVE-2026-17726: Integer overflow in WebGL. Reported by Google. - CVE-2026-17727: Out of bounds write in WebGL. Reported by Google. - CVE-2026-17728: Inappropriate implementation in Extensions. Reported by Suhas S P. - CVE-2026-17758: Heap buffer overflow in Dawn. Reported by Hyeonjun Ahn (@_deayzl). - CVE-2026-17732: Inappropriate implementation in SVG. Reported by Lyra Rebane (rebane2001). - CVE-2026-17729: Use after free in V8. Reported by wang1r && lhfff. - CVE-2026-17730: Side-channel information leakage in Autofill. Reported by Google. - CVE-2026-17731: Inappropriate implementation in Autofill. Reported by Manojkumar Jaganathan Aka TheWhiteEvil with HackerBro Technologies. - CVE-2026-17733: Inappropriate implementation in QUIC. Reported by Google. - CVE-2026-17734: Inappropriate implementation in Autofill. Reported by Google. - CVE-2026-17735: Insufficient validation of untrusted input in BFCache. Reported by Google. - CVE-2026-17736: Insufficient validation of untrusted input in WebView. Reported by Google. - CVE-2026-17737: Use after free in Bluetooth. Reported by Google. - CVE-2026-17738: Insufficient validation of untrusted input in Payments. Reported by Google. - CVE-2026-17739: Insufficient policy enforcement in Extensions. Reported by Google. - CVE-2026-17740: Uninitialized Use in ANGLE. Reported by Google. - CVE-2026-17741: Insufficient validation of untrusted input in WebView. Reported by Google. - CVE-2026-17742: Insufficient policy enforcement in Payments. Reported by Google. - CVE-2026-17743: Insufficient policy enforcement in ControlledFrame. Reported by Google. - CVE-2026-17744: Inappropriate implementation in File Input. Reported by Google. - CVE-2026-17745: Out of bounds read in Skia. Reported by Google. - CVE-2026-17746: Use after free in GPU. Reported by Google. - CVE-2026-17747: Insufficient validation of untrusted input in Payments. Reported by Google. - CVE-2026-17748: Inappropriate implementation in Extensions. Reported by Google. - CVE-2026-17749: Insufficient validation of untrusted input in Extensions. Reported by Google. - CVE-2026-17750: Use after free in ANGLE. Reported by Google. - CVE-2026-17751: Inappropriate implementation in AdFilter. Reported by Google. - CVE-2026-17752: Use after free in Views. Reported by Google. - CVE-2026-17753: Inappropriate implementation in Autofill. Reported by Google. - CVE-2026-17754: Inappropriate implementation in Blink. Reported by Google. - CVE-2026-17755: Incorrect security UI in Extensions. Reported by Google. - CVE-2026-17756: Insufficient policy enforcement in Presentation. Reported by Google. - CVE-2026-17757: Uninitialized Use in Skia. Reported by Google. - CVE-2026-17759: Uninitialized Use in Codecs. Reported by Google. - CVE-2026-17760: Side-channel information leakage in NoStatePrefetch. Reported by Google. - CVE-2026-17761: Insufficient validation of untrusted input in Chrome for iOS. Reported by Google. - CVE-2026-17762: Inappropriate implementation in Chrome for iOS. Reported by Google. - CVE-2026-17763: Inappropriate implementation in GPU. Reported by Google. - CVE-2026-17764: Inappropriate implementation in FedCM. Reported by Google. - CVE-2026-17765: Inappropriate implementation in WebProtect. Reported by Google. - CVE-2026-17766: Insufficient validation of untrusted input in Clipboard. Reported by Google. - CVE-2026-17767: Insufficient validation of untrusted input in WebView. Reported by Google. - CVE-2026-17768: Insufficient validation of untrusted input in WebSockets. Reported by Google. - CVE-2026-17769: Insufficient validation of untrusted input in Cast. Reported by Google. - CVE-2026-17770: Out of bounds read in Media. Reported by Google. - CVE-2026-17771: Uninitialized Use in Skia. Reported by Google. - CVE-2026-17772: Out of bounds read in WebGL. Reported by Google. - CVE-2026-17773: Insufficient validation of untrusted input in Cast. Reported by Google. - CVE-2026-17774: Insufficient validation of untrusted input in Variations. Reported by Google. - CVE-2026-17775: Inappropriate implementation in PresentationAPI. Reported by Google. - CVE-2026-17776: Policy bypass in Receiver. Reported by Google. - CVE-2026-17777: Inappropriate implementation in Autofill. Reported by Google. - CVE-2026-17778: Use after free in Extensions. Reported by Google. - CVE-2026-17779: Inappropriate implementation in Site Isolation. Reported by Google. - CVE-2026-17780: Inappropriate implementation in Isolated Web Apps. Reported by Google. - CVE-2026-17781: Inappropriate implementation in Extensions. Reported by Google. - CVE-2026-17782: Incorrect security UI in Chrome for iOS. Reported by Google. - CVE-2026-17783: Inappropriate implementation in Loader. Reported by Google. - CVE-2026-17784: Use after free in Audio. Reported by Google. - CVE-2026-17785: Uninitialized Use in ANGLE. Reported by Google. - CVE-2026-17786: Insufficient validation of untrusted input in DevTools. Reported by Google. - CVE-2026-17787: Inappropriate implementation in DevTools. Reported by Google. - CVE-2026-17788: Inappropriate implementation in Blink. Reported by Google. - CVE-2026-17789: Insufficient validation of untrusted input in Chrome for iOS. Reported by Google. - CVE-2026-17790: Uninitialized Use in ANGLE. Reported by Google. - CVE-2026-17791: Insufficient validation of untrusted input in Payments. Reported by Google. - CVE-2026-17792: Inappropriate implementation in Credential Management. Reported by Google. - CVE-2026-17793: Inappropriate implementation in Messages. Reported by Google. - CVE-2026-17794: Insufficient validation of untrusted input in Mobile. Reported by Google. - CVE-2026-17795: Insufficient validation of untrusted input in GetUserMedia. Reported by Mihnea Nicolau. - CVE-2026-17796: Side-channel information leakage in WebXR. Reported by Google. - CVE-2026-17797: Inappropriate implementation in CSS. Reported by Google - CVE-2026-17798: Inappropriate implementation in Cast. Reported by Google. - CVE-2026-17799: Insufficient validation of untrusted input in Safe Browsing. Reported by Google. - CVE-2026-17800: Side-channel information leakage in MediaRecording. Reported by Google. - CVE-2026-17801: Out of bounds memory access in ANGLE. Reported by Google. - CVE-2026-17802: Side-channel information leakage in GPU. Reported by Google. - CVE-2026-17803: Insufficient validation of untrusted input in Save to Drive. Reported by Google. - CVE-2026-17804: Use after free in Media. Reported by Google. - CVE-2026-17805: Insufficient policy enforcement in Glic. Reported by Google. - CVE-2026-17806: Insufficient validation of untrusted input in Extensions. Reported by Google. - CVE-2026-17807: Use after free in V8. Reported by Google. - CVE-2026-17808: Uninitialized Use in WebGL. Reported by Google. - CVE-2026-17809: Insufficient validation of untrusted input in Extensions. Reported by Google. - CVE-2026-17810: Uninitialized Use in Dawn. Reported by Google. - CVE-2026-17811: Use after free in ANGLE. Reported by Google. - CVE-2026-17812: Inappropriate implementation in DigitalCredentials. Reported by Google. - CVE-2026-17813: Insufficient policy enforcement in Chrome for iOS. Reported by Google. - CVE-2026-17814: Insufficient validation of untrusted input in Chrome for iOS. Reported by Google. - CVE-2026-17815: Insufficient policy enforcement in GuestView. Reported by Google. - CVE-2026-17816: Inappropriate implementation in Speech. Reported by Google. - CVE-2026-17817: Inappropriate implementation in ReportingAndNEL. Reported by Google. - CVE-2026-17818: Inappropriate implementation in Network. Reported by Google. - CVE-2026-17819: Inappropriate implementation in WebAppInstalls. Reported by Google. - CVE-2026-17820: Insufficient policy enforcement in Autofill. Reported by Google. - CVE-2026-17821: Insufficient policy enforcement in Extensions. Reported by Google. - CVE-2026-17822: Inappropriate implementation in Chrome for iOS. Reported by Google. - CVE-2026-17823: Insufficient policy enforcement in WebXR. Reported by Google. - CVE-2026-17824: Insufficient policy enforcement in ServiceWorker. Reported by Google. - CVE-2026-17825: Insufficient policy enforcement in Passwords. Reported by Google. - CVE-2026-17826: Inappropriate implementation in Chrome for iOS. Reported by Google. - CVE-2026-17827: Inappropriate implementation in CSS. Reported by Google - CVE-2026-17828: Inappropriate implementation in Chrome for iOS. Reported by Google. - CVE-2026-17829: Insufficient policy enforcement in Passwords. Reported by Google. - CVE-2026-17830: Inappropriate implementation in Chrome for iOS. Reported by Google. - CVE-2026-17831: Insufficient validation of untrusted input in Passwords. Reported by Google. - CVE-2026-17832: Use after free in ANGLE. Reported by Google. - CVE-2026-17833: Inappropriate implementation in Passwords. Reported by Google. - CVE-2026-17834: Inappropriate implementation in Passwords. Reported by Google. - CVE-2026-17835: Inappropriate implementation in Chrome for iOS. Reported by Google. - CVE-2026-17836: Use after free in V8. Reported by yupyon.itome. - CVE-2026-17837: Insufficient validation of untrusted input in DevTools. Reported by Google. - CVE-2026-17838: Incorrect security UI in Chrome for iOS. Reported by Google. - CVE-2026-17839: Inappropriate implementation in Chrome for iOS. Reported by Google. - CVE-2026-17840: Incorrect security UI in Passwords. Reported by Google - CVE-2026-17841: Race in Chrome for iOS. Reported by Google. - CVE-2026-17842: Inappropriate implementation in Chrome for iOS. Reported by Google. - CVE-2026-17843: Inappropriate implementation in CSS. Reported by Google - CVE-2026-17844: Insufficient validation of untrusted input in Cast. Reported by Google. - CVE-2026-17845: Inappropriate implementation in CSS. Reported by Google - CVE-2026-17846: Inappropriate implementation in Media. Reported by Google. - CVE-2026-17847: Insufficient validation of untrusted input in ANGLE. Reported by Google. - CVE-2026-17848: Insufficient validation of untrusted input in Codecs. Reported by Ameen Basha M K. - CVE-2026-17849: Inappropriate implementation in Chrome for iOS. Reported by Google. - CVE-2026-17850: Inappropriate implementation in Permissions. Reported by Tech Division (@taiphung) - Mobifone Digital Payment. - CVE-2026-17851: Side-channel information leakage in Autofill. Reported by Google. - CVE-2026-17852: Inappropriate implementation in Media Router. Reported by Google. - CVE-2026-17853: Inappropriate implementation in DevTools. Reported by Orange Tsai (@orange_8361) of DEVCORE Research Team. - CVE-2026-17854: Insufficient policy enforcement in WebMCP. Reported by Google. - CVE-2026-17855: Race in DevTools. Reported by Google. - CVE-2026-17856: Inappropriate implementation in Network. Reported by Google. - CVE-2026-17857: Inappropriate implementation in Network. Reported by Google. - CVE-2026-17858: Uninitialized Use in WebNN. Reported by Google. - CVE-2026-17859: Side-channel information leakage in Favicons. Reported by Google. - CVE-2026-17860: Insufficient validation of untrusted input in Mobile. Reported by Google. - CVE-2026-17861: Insufficient validation of untrusted input in Updater. Reported by Google. - CVE-2026-17862: Use after free in Tracing. Reported by Google. - CVE-2026-17863: Inappropriate implementation in Browser. Reported by Google. - CVE-2026-17864: Inappropriate implementation in Updater. Reported by Google. - CVE-2026-17865: Inappropriate implementation in Crypto. Reported by Google. - CVE-2026-17866: Type Confusion in Tab. Reported by Google. - CVE-2026-17867: Insufficient validation of untrusted input in Dawn. Reported by Google. - CVE-2026-17868: Insufficient policy enforcement in USB. Reported by Ariel Simon. - CVE-2026-17869: Out of bounds read in WebXR. Reported by Google. - CVE-2026-17870: Insufficient validation of untrusted input in Cast. Reported by Google. - CVE-2026-17871: Inappropriate implementation in Passwords. Reported by Google. - CVE-2026-17872: Cryptographic Flaw in WebAppInstalls. Reported by Google. - CVE-2026-17873: Insufficient policy enforcement in Chrome for iOS. Reported by Google. - CVE-2026-17874: Inappropriate implementation in Chrome for iOS. Reported by Google. - CVE-2026-17875: Use after free in PDFium. Reported by Google. - CVE-2026-17876: Inappropriate implementation in Payments. Reported by Google. - CVE-2026-17877: Inappropriate implementation in Chromoting. Reported by Google. - CVE-2026-17878: Inappropriate implementation in CSS. Reported by Google - CVE-2026-17879: Inappropriate implementation in Autofill. Reported by Google. - CVE-2026-17880: Inappropriate implementation in Autofill. Reported by Google. - CVE-2026-17881: Use after free in WebXR. Reported by Google. - CVE-2026-17882: Policy bypass in Extensions. Reported by Google. - CVE-2026-17883: Inappropriate implementation in Headless. Reported by Google. - CVE-2026-17884: Object lifecycle issue in WebRTC. Reported by Google. - CVE-2026-17885: Inappropriate implementation in Paint. Reported by Google. - CVE-2026-17886: Use after free in Enterprise. Reported by Google. - CVE-2026-17887: Use after free in TabStrip. Reported by Google. - CVE-2026-17888: Insufficient validation of untrusted input in WebUI. Reported by Google. - CVE-2026-17889: Uninitialized Use in WebXR. Reported by Google. - CVE-2026-17890: Insufficient validation of untrusted input in DevTools. Reported by Google. - CVE-2026-17891: Use after free in ANGLE. Reported by Google. - CVE-2026-17892: Inappropriate implementation in WebXR. Reported by Google. - CVE-2026-17893: Insufficient validation of untrusted input in Updater. Reported by Google. - CVE-2026-17894: Use after free in Views. Reported by Google. - CVE-2026-17895: Inappropriate implementation in DataTransfer. Reported by hongan@calif.io. - CVE-2026-17896: Use after free in DevTools. Reported by Google. - CVE-2026-17897: Inappropriate implementation in ORB. Reported by Sharkkcode. - CVE-2026-17898: Use after free in DevTools. Reported by Syn4pse. - CVE-2026-17899: Insufficient policy enforcement in DevTools. Reported by asnine. - CVE-2026-17900: Inappropriate implementation in Enterprise. Reported by Google. - CVE-2026-17901: Inappropriate implementation in Sharing. Reported by Google. - CVE-2026-17902: Inappropriate implementation in Editing. Reported by Google. - CVE-2026-17903: Insufficient policy enforcement in Chromecast. Reported by Google. - CVE-2026-17904: Insufficient policy enforcement in NFC. Reported by Google. - CVE-2026-17905: Inappropriate implementation in SurfaceCapture. Reported by Google. - CVE-2026-17906: Insufficient validation of untrusted input in Bluetooth. Reported by Google. - CVE-2026-17907: Side-channel information leakage in Network. Reported by Google. - CVE-2026-17908: Insufficient validation of untrusted input in Printing. Reported by Google. - CVE-2026-17909: Insufficient validation of untrusted input in Isolated Web Apps. Reported by Google. - CVE-2026-17910: Insufficient policy enforcement in NFC. Reported by Google. - CVE-2026-17911: Insufficient policy enforcement in SVG. Reported by Google. - CVE-2026-17912: Inappropriate implementation in Chrome for iOS. Reported by Google. - CVE-2026-17913: Inappropriate implementation in Chrome for iOS. Reported by Google. - CVE-2026-17914: Side-channel information leakage in Skia. Reported by Google. - CVE-2026-17915: Inappropriate implementation in WebView. Reported by Google. - CVE-2026-17916: Insufficient policy enforcement in Settings. Reported by Itzik Chimino. - CVE-2026-17917: Policy bypass in Chrome for iOS. Reported by Google. - CVE-2026-17918: Use after free in Sync. Reported by Google. - CVE-2026-17919: Insufficient policy enforcement in Enterprise. Reported by Google. - CVE-2026-17920: Use after free in V8. Reported by Google. - CVE-2026-17921: Insufficient validation of untrusted input in Navigation. Reported by Google. - CVE-2026-17922: Inappropriate implementation in Enterprise. Reported by Google. - CVE-2026-17923: Policy bypass in Enterprise. Reported by Google. - CVE-2026-17924: Use after free in DNS. Reported by Google. - CVE-2026-17925: Inappropriate implementation in Cast. Reported by Google. - CVE-2026-17926: Insufficient validation of untrusted input in DevTools. Reported by Google. - CVE-2026-17927: Insufficient policy enforcement in DevTools. Reported by Google. - CVE-2026-17928: Inappropriate implementation in DataTransfer. Reported by Google. - CVE-2026-17929: Insufficient validation of untrusted input in DevTools. Reported by Google. - CVE-2026-17930: Insufficient validation of untrusted input in Extensions. Reported by Google. - CVE-2026-17931: Inappropriate implementation in DevTools. Reported by Google. - CVE-2026-17932: Use after free in DataTransfer. Reported by Google. - CVE-2026-17933: Inappropriate implementation in DOMStorage. Reported by Google. - CVE-2026-17934: Insufficient validation of untrusted input in DevTools. Reported by Google. - CVE-2026-17935: Heap buffer overflow in Codecs. Reported by Google. - CVE-2026-17936: Inappropriate implementation in DevTools. Reported by Google. - CVE-2026-17937: Inappropriate implementation in DevTools. Reported by Google. - CVE-2026-17938: Inappropriate implementation in FullScreen. Reported by Google. - CVE-2026-17939: Inappropriate implementation in Passwords. Reported by Google. - CVE-2026-17940: Insufficient validation of untrusted input in Picture-in-Picture. Reported by Google. - CVE-2026-17941: Inappropriate implementation in Chrome for iOS. Reported by Google. - CVE-2026-17942: Side-channel information leakage in SVG. Reported by Google. - CVE-2026-17943: Inappropriate implementation in Parser. Reported by Google. - CVE-2026-17944: Inappropriate implementation in Chrome for iOS. Reported by Google. - CVE-2026-17945: Inappropriate implementation in Navigation. Reported by Google. - CVE-2026-17946: Uninitialized Use in Dawn. Reported by Google. - CVE-2026-17947: Use after free in WebSockets. Reported by Google. - CVE-2026-17948: Type Confusion in V8. Reported by Google. - CVE-2026-17949: Uninitialized Use in GPU. Reported by Google. - CVE-2026-17950: Policy bypass in Safebrowsing. Reported by Google. - CVE-2026-17951: Heap buffer overflow in WebRTC. Reported by Google. - CVE-2026-17952: Inappropriate implementation in V8. Reported by Google - CVE-2026-17953: Insufficient policy enforcement in WebView. Reported by Google. - CVE-2026-17954: Policy bypass in MHTML. Reported by Google. - CVE-2026-17955: Insufficient validation of untrusted input in Payments. Reported by Google. - CVE-2026-17956: Inappropriate implementation in Scheduling. Reported by Google. - CVE-2026-17957: Inappropriate implementation in CORS. Reported by Google. - CVE-2026-17958: Inappropriate implementation in Views. Reported by Google. - CVE-2026-17959: Inappropriate implementation in Network. Reported by Google. - CVE-2026-17960: Inappropriate implementation in Chrome for iOS. Reported by Google. - CVE-2026-17961: Inappropriate implementation in Session. Reported by Google. - CVE-2026-17962: Inappropriate implementation in Blink. Reported by Google. - CVE-2026-17963: Inappropriate implementation in SVG. Reported by Google - CVE-2026-17964: Incorrect security UI in UI. Reported by Google. - CVE-2026-17965: Incorrect security UI in Chrome for iOS. Reported by Google. - CVE-2026-17966: Inappropriate implementation in Views. Reported by Google. - CVE-2026-17967: Use after free in Chrome for iOS. Reported by Google. - CVE-2026-17968: Uninitialized Use in WebXR. Reported by Google. - CVE-2026-17969: Inappropriate implementation in Passwords. Reported by Google. - CVE-2026-17970: Insufficient validation of untrusted input in Passwords. Reported by Google. - CVE-2026-17971: Inappropriate implementation in Frame. Reported by Google. - CVE-2026-17972: Inappropriate implementation in Chrome for iOS. Reported by Google. - CVE-2026-17973: Inappropriate implementation in Views. Reported by Google. - CVE-2026-17974: Insufficient policy enforcement in DevTools. Reported by Google. - CVE-2026-17975: Inappropriate implementation in IME. Reported by Google - CVE-2026-17976: Policy bypass in Extensions. Reported by Google. - CVE-2026-17977: Policy bypass in CSS. Reported by Google. - CVE-2026-17978: Side-channel information leakage in WebCodecs. Reported by Google. - CVE-2026-17979: Race in V8. Reported by Google. - CVE-2026-17980: Inappropriate implementation in UI. Reported by Google - CVE-2026-17981: Inappropriate implementation in Blink. Reported by Google. - CVE-2026-17982: Insufficient validation of untrusted input in Cast. Reported by Google. - CVE-2026-17983: Incorrect security UI in Global Media Controls. Reported by Google. - CVE-2026-17984: Inappropriate implementation in Browser. Reported by Google. - CVE-2026-17985: Insufficient policy enforcement in Speech. Reported by Google. - CVE-2026-17986: Insufficient policy enforcement in Bluetooth. Reported by Google. - CVE-2026-17987: Insufficient validation of untrusted input in Notifications. Reported by Google. - CVE-2026-17988: Insufficient validation of untrusted input in Navigation. Reported by Google. - CVE-2026-17989: Type Confusion in V8. Reported by Google. - CVE-2026-17990: Insufficient validation of untrusted input in WebAuthn. Reported by Google. - CVE-2026-17991: Insufficient validation of untrusted input in AI. Reported by Google. - CVE-2026-17992: Uninitialized Use in Skia. Reported by Google. - CVE-2026-17993: Race in Updater. Reported by Google. - CVE-2026-17994: Inappropriate implementation in Media. Reported by Google. - CVE-2026-17995: Out of bounds read in Dawn. Reported by sm1ee, ksw9722 - CVE-2026-17996: Inappropriate implementation in Browser. Reported by Google. - CVE-2026-17997: Inappropriate implementation in Passwords. Reported by Google. - CVE-2026-17998: Incorrect security UI in Extensions. Reported by Google - CVE-2026-17999: Incorrect security UI in PictureInPicture. Reported by Google. - CVE-2026-18000: Insufficient policy enforcement in USB. Reported by Google. - CVE-2026-18001: Inappropriate implementation in WebGL. Reported by Google. - CVE-2026-18002: Insufficient validation of untrusted input in Google Lens. Reported by Google. - CVE-2026-18003: Inappropriate implementation in Chrome for iOS. Reported by Google. - CVE-2026-18004: Insufficient policy enforcement in Speech. Reported by Google. - CVE-2026-18005: Inappropriate implementation in WebXR. Reported by Google. - CVE-2026-18006: Inappropriate implementation in Google Lens. Reported by Google. - CVE-2026-18007: Inappropriate implementation in Input. Reported by Google. - CVE-2026-18008: Inappropriate implementation in Settings. Reported by Google. - CVE-2026-18009: Insufficient validation of untrusted input in Passwords. Reported by Google. - CVE-2026-18010: Inappropriate implementation in Passwords. Reported by Google. - CVE-2026-18011: Inappropriate implementation in Chrome for iOS. Reported by Google. - CVE-2026-18012: Use after free in PDFium. Reported by Google. - CVE-2026-18013: Inappropriate implementation in Chrome for iOS. Reported by Google. - CVE-2026-18014: Insufficient validation of untrusted input in DevTools. Reported by Google. - CVE-2026-18015: Inappropriate implementation in Tint. Reported by Google. - CVE-2026-18016: Insufficient policy enforcement in Chrome for iOS. Reported by Google. - CVE-2026-18017: Use after free in Dawn. Reported by Google. - CVE-2026-18018: Inappropriate implementation in Updater. Reported by Google. - CVE-2026-18019: Side-channel information leakage in Media. Reported by Google. - CVE-2026-16807: Out of bounds write in Codecs. Reported by Google. - CVE-2026-16806: Use after free in WebMCP. Reported by Google. - CVE-2026-16805: Use after free in Blink. Reported by Google. - CVE-2026-16804: Use after free in Input. Reported by Google. . [ Timothy Pearson ] * d/patches/ppc64le: - core/baseline-isa-3-0.patch: refresh for upstream changes chromium (151.0.7922.47-1) unstable; urgency=high . [ Andres Salomon ] * New upstream stable release. * d/patches: - upstream/sysroot.patch: drop, merged upstream. - upstream/ar-path1.patch: drop, merged upstream. - upstream/ar-path2.patch: drop, merged upstream. - fixes/widevine-locations.patch: refresh. - fixes/material-utils.patch: refresh for lots of upstream changes. - disable/catapult.patch: refresh and add another build fix. - disable/widevine-cdm-cu.patch: fix this - it broke at some point. - system/jpeg.patch: refresh. - llvm-19/clang19.patch: refresh. - trixie/gn-inputs.patch: refresh. - ungoogled/disable-ai.patch: sync from u-c. - ungoogled/disable-privacy-sandbox.patch: sync from u-c. - system/golang.patch: add patch to build using packaged golang instead of bundled go binary. - llvm-19/privatefriends.patch: add yet another clang-19 workaround, this one for the compiler ignoring class friend declarations. - llvm-19/constexpr.patch: add clang-19 constexpr workaround. - trixie/nodejs-set-intersection.patch: drop, now that we've got the pre-gen stuff. - trixie/nodejs-main.patch: drop, now that we've got the pre-gen stuff [trixie, bookworm]. - trixie/node20-compat.patch: drop, now that we've got the pre-gen stuff [trixie, bookworm]. - trixie/bindgen-boringssl.patch: drop, now that we've got the pre-gen stuff [trixie, bookworm]. - rust-1.85/let-chains.patch: add another build fix for older rustc [trixie, bookworm]. - bookworm/freetype-COLRV1.patch: refresh [bookworm]. - bookworm/bindgen.patch: drop, now that we've got pre-gen [bookworm]. - bookworm/node18-compat.patch: drop, now that we've got pre-gen [bookworm]. * d/control: add build-dep on golang. . [ Daniel Richard G. ] * d/patches: - bookworm/gn-absl.patch: Refresh [bookworm]. - bookworm/gn-funcs.patch: Refresh, adjust indentation, and fix new call to filter_labels_include() [bookworm]. - bookworm/gn-revert-path-exists.patch: Add fix for new call to path_exists(). - llvm-19/clang19.patch: Fix new instance of -Wlifetime-safety-permissive. - llvm-19/value-or.patch: Fix new instance of .value_or(). * d/rules: Set CPPFLAGS explicitly so that the env var is always populated. * New "pre-gen" framework for generating, saving, and consuming source files that normally require recent versions of bindgen, golang, nodejs et al. in order to be generated by the build. This will facilitate building Chromium for the stable releases, as those recent versions will no longer need to be backported, and ugly compatibility hacks no longer needed. Please see pre-gen/README.Debian for more information. New/updated files: - d/deb_pre_gen.py: Core implementation module of the framework. - d/patches/debianization/pre-gen.patch: Hook the core module into various Chromium build-tooling scripts. - d/rules: Create and clean up appropriate pre-gen/arch symlink, plus an "init-pre-gen" target to create the .orig-pre-gen.tar.xz source tarball. - d/scripts/init-pre-gen.sh: Maintainer script called by "init-pre-gen" target that does most of the work of creating the tarball. . [ Timothy Pearson ] * d/patches/ppc64le: - fixes/fix-partition-alloc-compile.patch: remove - sandbox/0001-sandbox-Enable-seccomp_bpf-for-ppc64.patch: refresh for upstream changes - third_party/0001-Add-PPC64-support-for-boringssl.patch: refresh for upstream changes - third_party/0002-regenerate-xnn-buildgn.patch: refresh for upstream changes - third_party/skia-vsx-instructions.patch: refresh for upstream changes dask (2024.12.1+dfsg-6) unstable; urgency=medium . * Disable build-depending depending on python3-distributed This avoids a hang when running tests on armhf during the build, and removes a circular dependency. * Add ignore-debian-pytables-warnings.patch to avoid errors from warnings added by Debian see #877419 for more information. * Add python3-pytest-timeout and enable it to maybe help if we have other timeout issues besides the armhf distributed one above. * Enable pytest timeout in debian/tests/run-test as well . dask (2024.12.1+dfsg-5) UNRELEASED; urgency=medium . * Team upload. * autopkgtests, avoid depending on pyarrow in s390x. dnsmasq (2.93-3) unstable; urgency=medium . * d/t/functions.d/ip-addr.patterns: Relax limits introduced by one regex. dnsmasq (2.93-2) unstable; urgency=medium . * d/t/*: - Rework autopkgtest so that it can run successfully under incus-lxc. (Closes: #1144780) - Rework pattern matching from dash-based to perl-based. * d/control: Update debhelper-compat to 14. Consequently, drop all ${*:Depends} and ${*:Pre-Depends} substvar mentionings. eye (1:11.24.8+ds-1) unstable; urgency=medium . [ upstream ] * new release(s) . [ Jonas Smedegaard ] * update watch file: + use Custom-Version + capitalize file format field label + stop set auto-mangling of upstream version (now done by default) * use debhelper compatibility level 14 (not 13) * unfuzz patches fail2ban (1.1.1-1) unstable; urgency=medium . * Team upload. * New upstream version 1.1.1. - Ships a new openvpn filter and jail, requested in 2014 (Closes: #748076). * d/watch: mangle upstream pre-release tags (1.1.1.beta0, 0.8.11.pre1, 0.10.0a1) to tilde form so they sort below the release they precede, and skip tags that are not version numbers. * d/gbp.conf: point debian-branch at master (was a stale experimental branch) and enable pristine-tar. . * d/patches: - Drop no-python-user.diff and replace-distutils.patch, both merged or made redundant upstream. - Drop the systemd unit hunk of systemd-run.diff (RuntimeDirectory is now upstream) and fold the remaining /run migration into deb_init_paths. - Merge update-ssh-9.8.diff and update-ssh-10.0.diff into deb_sshd_journalmatch.diff; only the ssh.service unit name is still Debian-specific. - Trim the now-upstream sshd_backend/postfix_backend keys from update_backend_system.diff, and refresh roundcube.diff. - Add DEP-3 headers to every patch. - Set syslog_local0 to /var/log/syslog on Debian; upstream's /var/log/messages does not exist here (Closes: #983534). - Add deb_asterisk_log_path.diff, making the asterisk jail's logpath configurable from paths-*.conf, and point it at /var/log/asterisk/messages.log, which is what Asterisk has written since version 19 (Closes: #1024822). . * d/control: - Bump debhelper-compat to 14. - Add dh-sequence-single-binary to Build-Depends: compat 14 warns that it only implicitly activates the single-binary dh addon for backwards compatibility, and will stop doing so in compat 15. - Drop ${misc:Depends} from Depends: compat 14's dh_gencontrol now applies it automatically, and the explicit placeholder was left with nothing to substitute (dpkg-gencontrol: warning: substitution variable ${misc:Depends} used, but is not defined). - Recommend nftables alone rather than "nftables | iptables", and suggest iptables. The Debian default banaction is nftables, but apt considered the recommendation satisfied whenever iptables was already installed, so banning failed silently. (Closes: #1121856, #1101769, #994511) . * d/rules: - Stop installing files/fail2ban-tmpfiles.conf; upstream dropped it in 1.1.1 in favour of RuntimeDirectory= in the systemd unit. - Drop the unused PYVERSION variable, the no-op dh_auto_configure override, a duplicated install -d, and the dh_installman override (use d/fail2ban.manpages). - No longer ignore the result of the upstream test suite; it passes cleanly on Python 3.14. . * d/rules, d/fail2ban.maintscript: ship the monit snippet in /etc/monit/conf-available, the directory monit reads via conf- enabled, instead of the unused /etc/monit/monitrc.d (Closes: #991367). * d/backports: drop; sarge/python-central era files, dead since 2006. * d/NEWS: document the nftables recommendation, the conffile cleanup and the monit move. * d/fail2ban.logrotate: skip the postrotate hook when fail2ban-client is gone (Closes: #782256) and do not fail the logrotate run when the server is not up, e.g. early at boot (Closes: #935778). * d/fail2ban.maintscript: remove conffiles that upstream stopped shipping long ago and that were left behind on upgraded systems (Closes: #990144). * d/fail2ban.default: replace the obsolete FSF postal address with the licence URL (Closes: #1080413). * d/fail2ban.lintian-overrides: move the national-encoding overrides here from d/source (they apply to the binary package) and override unusual-interpreter for /usr/bin/fail2ban-python, which the package itself ships. * d/source/lintian-overrides: override uses-deprecated-python-stdlib; upstream vendors asyncore/asynchat under fail2ban/compat and guards the smtpd import (see #1040114, #1040122). * d/copyright: add Upstream-Name, point Source at the tarball location, record the bundled asyncore/asynchat modules (Copyright 1996 Sam Rushing, permissive licence) and replace the "many others since then" placeholder. * d/TODO: drop; its one entry pointed at the syslog-forging caveat already fully documented in d/README.Debian, and the file isn't shipped (d/fail2ban.docs installs upstream's own TODO, not this one). golang-github-apparentlymart-go-workgraph (0.0~git20260622.8b882ba-1) unstable; urgency=medium . * Initial release (Closes: #1145990) golang-github-opentofu-svchost (0.0~git20260410.1a42986-1) unstable; urgency=medium . * Initial release, needed for opentofu (Closes: #1145947) golang-oras-oras-go (2.6.2-2) unstable; urgency=medium . * Team Upload. * Drop myself from Uploaders gosop (1.1.0-7) unstable; urgency=medium . * d/control: Remove B-D dh-sequence-golang. * d/rules: Disable dh_dwz. gosop (1.1.0-5) unstable; urgency=medium . * d/control: Use dh-go for modern go builds. latexml (0.8.8-6) unstable; urgency=medium . * Reintroduce d/watch file to control better file matches when searching. libconfig-model-systemd-perl (0.261.1-1) unstable; urgency=medium . * new upstream version for systemd 261 * copyright: refreshed with cme * control: depends on libconfig-model-perl >= 2.163 nodejs (24.21.0+dfsg+~cs24.13.4-1) unstable; urgency=medium . * New upstream version 24.21.0+dfsg+~cs24.13.4 pcre2 (10.48-3) unstable; urgency=medium . * Bump dh compat to 13 (with some changes to rules file) php-jakeasmith-http-build-url (1.0.2-1) unstable; urgency=medium . [ Jake A. Smith ] * Deprecate in favor of PHP 8.5's built-in URI API . [ David Prévot ] * Remove redundant Priority: optional from source stanza * Update standards version to 4.7.4 * Update watch file format version to 5 * Removed Rules-Requires-Root * Use GitHub template in watch file instead of explicit Source/Matching-Pattern * Use debhelper-compat 14 * Stick to the current description php-parser (5.9.0-1) unstable; urgency=medium . [ Kuba Werłos ] * Fix attribute insertion on enums in formatting-preserving printer (#1156) * Fix attribute insertion on enum cases in formatting-preserving printer . [ Ilia Alshanetsky ] * Reject Unicode escapes above the maximum code point . [ Nikita Popov ] * Suppress warning on hexdec/bindec/octdec overflow * Release PHP-Parser 5.9.0 . [ Sebastian Bergmann ] * Implement support for partial function application . [ David Prévot ] * Use debhelper-compat 14 python-aiopnsense (1.1.11-1) unstable; urgency=medium . * New upstream release. * Add nodejs test dependency. python-sh (2.4.0-1) unstable; urgency=medium . * Team upload. * New upstream version; fix for CVE-2026-54552 (Closes: #1145886) * d/control: use autopkgtest-pkg-pybuild, compat to 14 * d/control: replace poetry-core with hatchling * d/control: remove explicit deps * d/copyright: add file with different copyright year * d/rules: add fix to prevent core dumps from being packaged * d/example: add example * Minor improvement to d/u/metadata * Rename branch and add gbp.conf rust-time (0.3.55-1) unstable; urgency=medium . * Team upload. * Package time 0.3.55 from crates.io using debcargo 2.8.4 (Closes: #1146070) sphinxcontrib-jsmath (1.0.2~git20240729.19763d7-1) unstable; urgency=medium . * Team upload. * [f0fae15] Update debian/watch to track upstream git HEAD. * [0c83190] New upstream version 1.0.2~git20240729.19763d7. - No longer uses pkg_resources (closes: #1147920). * [072de19] Build-depend on flit and pybuild-plugin-pyproject instead of setuptools. * [d34f48f] Drop three patches that are included in the new snapshot. * [68dc8f9] Update sphinx_8.2.patch to the version from upstream PR. * [bb344aa] Update dh_installchangelogs command to install CHANGES.rst. * [09f527e] Do not ship locales/.tx directory. * [d992c5a] Update to debhelper compat level 14. - Remove explicit ${*:Depends}. - Build-depend on dh-sequence-single-binary. * [0846e65] Bump Standards-Version to 4.7.4, no changes needed. * [95ba376] Regenerate gettext .mo files from source during build. REMOVED: fonts-lexi-gulim 20090423+really2839-1 REMOVED: deepin-qt5dxcb-plugin 5.7.12-1 REMOVED: piperka-client 0.2.2-1.1 REMOVED: fonts-lexi-saebom 20100129-8 REMOVED: gecode-snapshot 6.2.0+git20260120-2