-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 13 Jan 2026 22:11:21 -0500 Source: chromium Binary: chromium chromium-common chromium-common-dbgsym chromium-dbgsym chromium-driver chromium-headless-shell chromium-headless-shell-dbgsym chromium-sandbox chromium-sandbox-dbgsym chromium-shell chromium-shell-dbgsym Architecture: amd64 Version: 144.0.7559.59-1~deb12u1 Distribution: bookworm-security Urgency: high Maintainer: all / amd64 / i386 Build Daemon (x86-conova-01) Changed-By: Andres Salomon Description: chromium - web browser chromium-common - web browser - common resources used by the chromium packages chromium-driver - web browser - WebDriver support chromium-headless-shell - web browser - old headless shell chromium-sandbox - web browser - setuid security sandbox for chromium chromium-shell - web browser - minimal shell Changes: chromium (144.0.7559.59-1~deb12u1) bookworm-security; urgency=high . [ Andres Salomon ] * New upstream stable release. - CVE-2026-0899: Out of bounds memory access in V8. Reported by @p1nky4745. - CVE-2026-0900: Inappropriate implementation in V8. Reported by Google. - CVE-2026-0901: Inappropriate implementation in Blink. Reported by Irvan Kurniawan (sourc7). - CVE-2026-0902: Inappropriate implementation in V8. Reported by 303f06e3. - CVE-2026-0903: Insufficient validation of untrusted input in Downloads. Reported by Azur. - CVE-2026-0904: Incorrect security UI in Digital Credentials. Reported by Hafiizh. - CVE-2026-0905: Insufficient policy enforcement in Network. Reported by Google. - CVE-2026-0906: Incorrect security UI. Reported by Khalil Zhani. - CVE-2026-0907: Incorrect security UI in Split View. Reported by Hafiizh. - CVE-2026-0908: Use after free in ANGLE. Reported by Glitchers BoB 14th. * d/copyright: delete a copy of clang-22 in the openscreen build directory. * d/control: add rustfmt-web as a build dependency. * d/rules: make DEB_BUILD_OPTIONS=terse work. * d/patches: - disable/tests.patch: refresh. - trixie/rust-sanitize.patch: refresh. - bookworm/bindgen.patch: refresh. - fixes/force-rust-nightly.patch: add workaround to force rustc_nightly_capability, as we're using an up-to-date rust. - trixie/value-or.patch: add clang-19 workarounds to help calling value_or() with ambiguous values. - fixes/autofill-binarypb.patch: add patch to fix build for us stripping out binary-only files containing city/state autofill aliases. - bookworm/path-rustfmt.patch: add patch to override search path for rustfmt (which chromium deduces incorrectly due to our bundled bindgen in bookworm). . [ Daniel Richard G. ] * d/patches: - trixie/adler1.patch: Refresh to follow use of if-else. - trixie/libxml2-no-xxe.patch: Add workaround for older libxml2. - bookworm/eslint.patch: Refresh, and add another import.meta.dirname conversion. . [ Timothy Pearson ] * d/patches: - trixie/nodejs-set-intersection.patch: avoid using node >=22 intersection * d/patches/ppc64le: - ppc64le/third_party/0002-regenerate-xnn-buildgn.patch: Regenerate from upstream sources - fixes/fix-clang-selection.patch: Drop due to upstream changes Checksums-Sha1: 783e78410e57eb5a411a7f16127adfdcf67f04fb 5358360 chromium-common-dbgsym_144.0.7559.59-1~deb12u1_amd64.deb e37ab3d720586ad8f78430680d93c3b59aa8382d 22993576 chromium-common_144.0.7559.59-1~deb12u1_amd64.deb 09a3fae80e0762893a4b2805735a29bcf097a7cd 34220832 chromium-dbgsym_144.0.7559.59-1~deb12u1_amd64.deb 79a6d42faec1067f0d6532cb7552353fffed065e 7247708 chromium-driver_144.0.7559.59-1~deb12u1_amd64.deb 97899b54702932b59d0aa409f0a37703d9216bca 28319528 chromium-headless-shell-dbgsym_144.0.7559.59-1~deb12u1_amd64.deb fe4a449814c0b05f0f42465d2a0db7e0433586ca 54839716 chromium-headless-shell_144.0.7559.59-1~deb12u1_amd64.deb 1cfb62e15ec6357399c453beaccfe3340bc024a8 19304 chromium-sandbox-dbgsym_144.0.7559.59-1~deb12u1_amd64.deb 1ca26c74382f88b850b90bf0bc5810717efa0522 109536 chromium-sandbox_144.0.7559.59-1~deb12u1_amd64.deb b8b8f54eb69483234ebf66c4c01468ccd6ddc1b0 31096396 chromium-shell-dbgsym_144.0.7559.59-1~deb12u1_amd64.deb 5feddff45399dee5c9baf9e06254153ba468315b 59891980 chromium-shell_144.0.7559.59-1~deb12u1_amd64.deb 74a5b4e45605a4aaa05418683d0702fbc3d91e4e 30374 chromium_144.0.7559.59-1~deb12u1_amd64-buildd.buildinfo ae1bcd47a2a538b383d77a5e38b4e0e3d93ff029 71188416 chromium_144.0.7559.59-1~deb12u1_amd64.deb Checksums-Sha256: dfff279abfb6019814567c306a16600515fa93895c8665ff0bf2635bc1291de6 5358360 chromium-common-dbgsym_144.0.7559.59-1~deb12u1_amd64.deb b40e3f8ad64474df54fde364a578aeeb01fa68dc90a7a0a74abd212a4bd8a996 22993576 chromium-common_144.0.7559.59-1~deb12u1_amd64.deb 16c0f6bd3ed4f74c1e612d92f6daaa3c0f937ced240d9836128b867aa77c4f36 34220832 chromium-dbgsym_144.0.7559.59-1~deb12u1_amd64.deb c54c3b7875524fc8c4c69478097b11eb6a3c0f818252d98f5f85d7573588c010 7247708 chromium-driver_144.0.7559.59-1~deb12u1_amd64.deb 3b6b9a3b423706f551499ecf2b4e1808593cc898167889106152fffba7700968 28319528 chromium-headless-shell-dbgsym_144.0.7559.59-1~deb12u1_amd64.deb bb98b1fb502c7154324d91c8911b2aa60c707073bdc73f0a9b858e3fed2210f0 54839716 chromium-headless-shell_144.0.7559.59-1~deb12u1_amd64.deb 047eb2640a70a86fe3dddeeaf9c3b90be85dc69c7a06fd5546673ec03c0bb989 19304 chromium-sandbox-dbgsym_144.0.7559.59-1~deb12u1_amd64.deb af4cfdeb988b4cdf984e8eb0e64d72115214ef8f3693d8332860dfe7aa5a0a22 109536 chromium-sandbox_144.0.7559.59-1~deb12u1_amd64.deb 98951912d9cf8854bb927ede35582529a391c2af9ab7a2b0351792adb4816841 31096396 chromium-shell-dbgsym_144.0.7559.59-1~deb12u1_amd64.deb e555f29a53534e8c0f717a965b80d472027611d7584ddcdd2e584733eeb42bdb 59891980 chromium-shell_144.0.7559.59-1~deb12u1_amd64.deb 365882d12b1578bb6be40dd1d651855837e3e33061ea93c13e116db4d9cfba34 30374 chromium_144.0.7559.59-1~deb12u1_amd64-buildd.buildinfo a89d3968b2a9a4de6b8063bf7b746508b0e41c0b9865784e9db8afbd18f4f3fd 71188416 chromium_144.0.7559.59-1~deb12u1_amd64.deb Files: 27ea9d88349d9517b36f818823fb44cb 5358360 debug optional chromium-common-dbgsym_144.0.7559.59-1~deb12u1_amd64.deb d69a8d836d03511ce258a42902e5c7d6 22993576 web optional chromium-common_144.0.7559.59-1~deb12u1_amd64.deb 8d3575715186c64393546c44c7d7c2b4 34220832 debug optional chromium-dbgsym_144.0.7559.59-1~deb12u1_amd64.deb 0f2c79bfc38d347b04bccfe36070b08c 7247708 web optional chromium-driver_144.0.7559.59-1~deb12u1_amd64.deb cdebcc6f426334969a57f399399c13e1 28319528 debug optional chromium-headless-shell-dbgsym_144.0.7559.59-1~deb12u1_amd64.deb 982c7abf39a22d6475c5f43836311600 54839716 web optional chromium-headless-shell_144.0.7559.59-1~deb12u1_amd64.deb c4595406f19d99cacb76914ed395a9ac 19304 debug optional chromium-sandbox-dbgsym_144.0.7559.59-1~deb12u1_amd64.deb 5a2537d23bb49ca7cc5d4ee7fcc5fb4d 109536 web optional chromium-sandbox_144.0.7559.59-1~deb12u1_amd64.deb 39be9660eb2c0ec71b8fff38e9046ebc 31096396 debug optional chromium-shell-dbgsym_144.0.7559.59-1~deb12u1_amd64.deb cf793e9e21f56086d953bb6c04669d05 59891980 web optional chromium-shell_144.0.7559.59-1~deb12u1_amd64.deb 1d0f13344fa47def26f1d44298615f76 30374 web optional chromium_144.0.7559.59-1~deb12u1_amd64-buildd.buildinfo f84e680a0932fe6022f0a31783289e90 71188416 web optional chromium_144.0.7559.59-1~deb12u1_amd64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEaPzFtKPtF0JrKPV5iZlfn74WV6kFAmln0ioACgkQiZlfn74W V6n+Fg/+KsMJWlpxawx322i9gRFo4BNaedwy/U+3lbwjJKwFrSVGJI4gzpfhXZwE GULv98jKXgwTzI3DoYNzgzAXIswf9hmy1z67QJVC9rMwVjXp4WAn9diFxfgeBRQk uX8Bh0UwY9pmBYpDezMp8ylj6jKJmePBCp4wv51EgiSO0k4iJcQlxh4qYpRVMP1p x1TDgvheJkpWqSaLz/MLiJK5qIONGFkNxlATRbQeZkLXCCoxpWaiXpckfyRFiMFB arLwe/cRG0ylpvg/EzjW/pZzWHWuq1FULKPy0/LIuC61lVXNua7C2rcX2WVl6bXD JBSzY3EMi16ZAWF+M1vqQ7i/XS1/SkLxwoBEbdzycxfWhB8fnRhHxcaKcTox4fSl 1rWoXbgoy/M/k1Z0v321m3Se3ro/nCQckflqqAJ3wQowO3kX0i1cCX6RDb12fT7n cBekLwiZsVe8LKw/oXIkh2efhH1NBu6GyNYB7WRePUckOcMTxc3simpo5pw2ovee mWC56f8TuSJ71KrA58bGtiYF9fZOcuoFOUwFJ3i7aQ5RCCXJSGRWFR63p53yqnya KTudFwEmYVDLuWobxfcqHmAmVP4Fh8LZRUUb7sRWh0yDytE6KqcTU0sa+xvQXWJr mnnf+BrlGVo8j4P+raakN+xtDrZQCne1pAxOtZyNCG/b9HwJ/kI= =qRh8 -----END PGP SIGNATURE-----