-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 03 Dec 2025 01:54:50 -0500 Source: chromium Binary: chromium chromium-common chromium-common-dbgsym chromium-dbgsym chromium-driver chromium-headless-shell chromium-headless-shell-dbgsym chromium-sandbox chromium-sandbox-dbgsym chromium-shell chromium-shell-dbgsym Architecture: i386 Version: 143.0.7499.40-1~deb13u1 Distribution: trixie-security Urgency: high Maintainer: amd64 / i386 Build Daemon (x86-ubc-02) Changed-By: Andres Salomon Description: chromium - web browser chromium-common - web browser - common resources used by the chromium packages chromium-driver - web browser - WebDriver support chromium-headless-shell - web browser - old headless shell chromium-sandbox - web browser - setuid security sandbox for chromium chromium-shell - web browser - minimal shell Changes: chromium (143.0.7499.40-1~deb13u1) trixie-security; urgency=high . * New upstream stable release. - CVE-2025-13630: Type Confusion in V8. Reported by Shreyas Penkar (@streypaws). - CVE-2025-13631: Inappropriate implementation in Google Updater. Reported by Jota Domingos. - CVE-2025-13632: Inappropriate implementation in DevTools. Reported by Leandro Teles. - CVE-2025-13633: Use after free in Digital Credentials. Reported by Chrome. - CVE-2025-13634: Inappropriate implementation in Downloads. Reported by Eric Lawrence of Microsoft. - CVE-2025-13720: Bad cast in Loader. Reported by Chrome. - CVE-2025-13721: Race in v8. Reported by Chrome. - CVE-2025-13635: Inappropriate implementation in Downloads. Reported by Hafiizh. - CVE-2025-13636: Inappropriate implementation in Split View. Reported by Khalil Zhani. - CVE-2025-13637: Inappropriate implementation in Downloads. Reported by Hafiizh. - CVE-2025-13638: Use after free in Media Stream. Reported by sherkito. - CVE-2025-13639: Inappropriate implementation in WebRTC. Reported by Philipp Hancke. - CVE-2025-13640: Inappropriate implementation in Passwords. Reported by Anonymous. * d/patches: - fixes/headless-gn.patch: refresh. - fixes/chromium-142-iwyu-field-form-data.patch: drop, merged upstream. - disable/tests.patch: refresh. - ungoogled/disable-privacy-sandbox.patch: sync from upstream. - fixes/libpng-testonly.patch: add a workaround for a missing build target that upstream forgot to include. - trixie/rust-no-alloc-shim.patch: mark nightly feature 'no_mangle' as unsafe to make rustc happy. - trixie/cookie-string-view.patch: add a workaround for missing clang-19 feature. . [ Daniel Richard G. ] * d/patches: - debianization/cross-build.patch: Avoid "Assignment had no effect" error from GN when running outside of d/rules. - debianization/rustc-bootstrap.patch: Move RUSTC_BOOTSTRAP=1 here. - disable/license-headless-shell.patch: Don't generate the (unused) LICENSE.headless_shell file, as the rule tends to break easily. - fixes/headless-gn.patch: No longer needed, thanks to previous patch. - trixie/rust-is-multiple-of.patch: add more workarounds for missing rustc features. * d/rules: Move RUSTC_BOOTSTRAP=1 environment setting into patch. . [ Timothy Pearson ] * d/patches/ppc64le: - ppc64le/third_party/0002-regenerate-xnn-buildgn.patch: Regenerate from upstream sources - ppc64le/fixes/fix-clang-selection.patch: Refresh for upstream changes . [ Jianfeng Liu ] * Add loong64 support, with patches in d/patches/loongarch64/. Checksums-Sha1: bc6f73a66061b0900e65454bf9bc02b84546b7a2 5130592 chromium-common-dbgsym_143.0.7499.40-1~deb13u1_i386.deb 61a13de54bdbf34315d6b48eb3ca448e8301ac26 22849132 chromium-common_143.0.7499.40-1~deb13u1_i386.deb 25b369c0e21f8b8276f9a031a49b9560b043add3 34425228 chromium-dbgsym_143.0.7499.40-1~deb13u1_i386.deb 1b83bc04d46de57efea197bedb5f522bb08a531f 7599480 chromium-driver_143.0.7499.40-1~deb13u1_i386.deb 33e5d2165226b68d662527ed142cc63b0c898435 28522492 chromium-headless-shell-dbgsym_143.0.7499.40-1~deb13u1_i386.deb 5604399b9564cb5735ce133d268dadd127d535bc 55934152 chromium-headless-shell_143.0.7499.40-1~deb13u1_i386.deb b8f9fa41e76da8ceaf50f2b41c0800595f1d40ef 18984 chromium-sandbox-dbgsym_143.0.7499.40-1~deb13u1_i386.deb 1f93111aced81e1d95f569b1c540f433a1835a8e 106348 chromium-sandbox_143.0.7499.40-1~deb13u1_i386.deb 348f76e13d5f79b8b15b285ef245234c1f2ed047 31288772 chromium-shell-dbgsym_143.0.7499.40-1~deb13u1_i386.deb 6966af4fb975a09b556dfff901cfbbc67f2d38b8 61103272 chromium-shell_143.0.7499.40-1~deb13u1_i386.deb 6d6d9df1e464a07b1be176b4c00cb42acdb25fba 30054 chromium_143.0.7499.40-1~deb13u1_i386-buildd.buildinfo c9f2ccb17720b88b63e105a356946a3fbb5f7d58 72834712 chromium_143.0.7499.40-1~deb13u1_i386.deb Checksums-Sha256: d426826ec02e9aed13b1557088c48d4234de2696a10163ba2a7e12450ba56e22 5130592 chromium-common-dbgsym_143.0.7499.40-1~deb13u1_i386.deb 1e1d4ea51cc1c455d6f7b06709d03f69b9f02efd345f99d18a530aafff62bfff 22849132 chromium-common_143.0.7499.40-1~deb13u1_i386.deb 3a756851e2a8b15a20a9ddc38c28854d811cdaf3517050eb4e15a586a7510ac5 34425228 chromium-dbgsym_143.0.7499.40-1~deb13u1_i386.deb a52b07d19815e7f659edf032e25f70d704755d74dc92e08029b6a7bebbf70962 7599480 chromium-driver_143.0.7499.40-1~deb13u1_i386.deb b0e7c3336ab9300953ad7ef9cb37389168fc5e8bdbf11756406f6b17edb13cd8 28522492 chromium-headless-shell-dbgsym_143.0.7499.40-1~deb13u1_i386.deb bd192aa35348e1d2e710543b8c2ce71ad93fee56d6b1e1286efe892dbef6d5b2 55934152 chromium-headless-shell_143.0.7499.40-1~deb13u1_i386.deb e328717e239d8771cb5fe98a689f5f05330b15c423ac3a43d4005cc90ae5f719 18984 chromium-sandbox-dbgsym_143.0.7499.40-1~deb13u1_i386.deb 04c80b455d495f50892d91cc665317e874de76b248257531490a231487ed032d 106348 chromium-sandbox_143.0.7499.40-1~deb13u1_i386.deb e77f052aed1f1d6b5c31a6611d318fa3b079895c6f1cc497bf949bc5a62f4563 31288772 chromium-shell-dbgsym_143.0.7499.40-1~deb13u1_i386.deb dce1e85dd06465acc89f444d9968ce0461499f0ec905fb7d2bc50502fae16403 61103272 chromium-shell_143.0.7499.40-1~deb13u1_i386.deb f838269241cdae71c1571befa35ac4768173d1e84d7e9b7fdafd8eb74f86cb92 30054 chromium_143.0.7499.40-1~deb13u1_i386-buildd.buildinfo 7a343a0f8b229fe619cbf1b64480d2826e397e1351ab651a23443ce60da06b24 72834712 chromium_143.0.7499.40-1~deb13u1_i386.deb Files: f5213fc2cfe131c6987752cc1afdb8f0 5130592 debug optional chromium-common-dbgsym_143.0.7499.40-1~deb13u1_i386.deb c9aff60147331c271d14017b466b0671 22849132 web optional chromium-common_143.0.7499.40-1~deb13u1_i386.deb 8132f0072ca8ea785d485fd6f90498ff 34425228 debug optional chromium-dbgsym_143.0.7499.40-1~deb13u1_i386.deb 54abb9a9243c9895540894dc665f6cdb 7599480 web optional chromium-driver_143.0.7499.40-1~deb13u1_i386.deb 19242125f9c8273a23756dfb5e65b7e9 28522492 debug optional chromium-headless-shell-dbgsym_143.0.7499.40-1~deb13u1_i386.deb f0baff0fd2817dc501a9afa83a85d1fd 55934152 web optional chromium-headless-shell_143.0.7499.40-1~deb13u1_i386.deb 25d459da37963cb9587bf07632cde699 18984 debug optional chromium-sandbox-dbgsym_143.0.7499.40-1~deb13u1_i386.deb e86dc0e5c6a0a9a5bf0290e516bfdd6a 106348 web optional chromium-sandbox_143.0.7499.40-1~deb13u1_i386.deb 99bace8bdddb250c625c0e72e0bef707 31288772 debug optional chromium-shell-dbgsym_143.0.7499.40-1~deb13u1_i386.deb a58735ee25e7ae182e1896838b375109 61103272 web optional chromium-shell_143.0.7499.40-1~deb13u1_i386.deb 17d38ee4006148a2da4136bff005e58e 30054 web optional chromium_143.0.7499.40-1~deb13u1_i386-buildd.buildinfo 4740b5981391c57ff7561fe3104feac9 72834712 web optional chromium_143.0.7499.40-1~deb13u1_i386.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEc5vuvf2HND40bnI+8IREj/cRiTMFAmkxBCIACgkQ8IREj/cR iTPpUhAAn/wXHdacwi6n2BuYrvqMuM7m5rD9keBJEghkWIz2SjcUS5asT/CUbn28 hRNLwjg2axmzayZxmcyRhHyl8P7koNFstxpsqdB5IsuKHphulv0Uny7ywRMso1IZ /1u3lkRseKJ7GzyE4LqrnDBg0QfXICaxZMMKJ2um/6Ik6TyU+aAl9iYi05XxOetM PVARiQj91NXIU/uaMSZNCXYGvFuiYZL3rypuyMzzSDRRC1vQe+XAz9jOhWUP+tke htHGHIL635RRPxqxUV/58QNFK2vta7GEtLM4cUIwGAeUOtBytocr82MZhumcwmbU CgmVywVV6alJU3Jsbr8TZ0r/ZdVVLt/1Z79T4y7Zu4c3HzSodEghjGbgrPXbWwHS wLRy+sQO3AQVJKgUZ+lGU7NtGZJeBsRgbs1hNB+0yexVK4kDB9WMplhLHCwGaFQr 71D2lDKXIU7EIOu7UTDR5DQiEzeA1jTimMfmeJQnmuJrnb257JcyU69Ug4bX1l7u LMzQgXbu0Jk6GH6z8ZersaFOFd1ZSmlpQqUWCzOui8O+r1vzIHWLTE+OIVP43gKz cQymYPGaEeKCm5XZBtsRT4Mghd+UrMoLWjOl1n6osju5PrVtpfN31rgx/xtsMnbb PxkkKFhaVhxkBbBc0UbMYZN3/4uqlWKtK3XZlZViRuTNo9u1KcM= =5IxU -----END PGP SIGNATURE-----