-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 13 Jan 2026 22:11:21 -0500 Source: chromium Binary: chromium chromium-common chromium-common-dbgsym chromium-dbgsym chromium-driver chromium-headless-shell chromium-headless-shell-dbgsym chromium-sandbox chromium-sandbox-dbgsym chromium-shell chromium-shell-dbgsym Architecture: i386 Version: 144.0.7559.59-1~deb12u1 Distribution: bookworm-security Urgency: high Maintainer: i386 Build Daemon (x86-grnet-01) Changed-By: Andres Salomon Description: chromium - web browser chromium-common - web browser - common resources used by the chromium packages chromium-driver - web browser - WebDriver support chromium-headless-shell - web browser - old headless shell chromium-sandbox - web browser - setuid security sandbox for chromium chromium-shell - web browser - minimal shell Changes: chromium (144.0.7559.59-1~deb12u1) bookworm-security; urgency=high . [ Andres Salomon ] * New upstream stable release. - CVE-2026-0899: Out of bounds memory access in V8. Reported by @p1nky4745. - CVE-2026-0900: Inappropriate implementation in V8. Reported by Google. - CVE-2026-0901: Inappropriate implementation in Blink. Reported by Irvan Kurniawan (sourc7). - CVE-2026-0902: Inappropriate implementation in V8. Reported by 303f06e3. - CVE-2026-0903: Insufficient validation of untrusted input in Downloads. Reported by Azur. - CVE-2026-0904: Incorrect security UI in Digital Credentials. Reported by Hafiizh. - CVE-2026-0905: Insufficient policy enforcement in Network. Reported by Google. - CVE-2026-0906: Incorrect security UI. Reported by Khalil Zhani. - CVE-2026-0907: Incorrect security UI in Split View. Reported by Hafiizh. - CVE-2026-0908: Use after free in ANGLE. Reported by Glitchers BoB 14th. * d/copyright: delete a copy of clang-22 in the openscreen build directory. * d/control: add rustfmt-web as a build dependency. * d/rules: make DEB_BUILD_OPTIONS=terse work. * d/patches: - disable/tests.patch: refresh. - trixie/rust-sanitize.patch: refresh. - bookworm/bindgen.patch: refresh. - fixes/force-rust-nightly.patch: add workaround to force rustc_nightly_capability, as we're using an up-to-date rust. - trixie/value-or.patch: add clang-19 workarounds to help calling value_or() with ambiguous values. - fixes/autofill-binarypb.patch: add patch to fix build for us stripping out binary-only files containing city/state autofill aliases. - bookworm/path-rustfmt.patch: add patch to override search path for rustfmt (which chromium deduces incorrectly due to our bundled bindgen in bookworm). . [ Daniel Richard G. ] * d/patches: - trixie/adler1.patch: Refresh to follow use of if-else. - trixie/libxml2-no-xxe.patch: Add workaround for older libxml2. - bookworm/eslint.patch: Refresh, and add another import.meta.dirname conversion. . [ Timothy Pearson ] * d/patches: - trixie/nodejs-set-intersection.patch: avoid using node >=22 intersection * d/patches/ppc64le: - ppc64le/third_party/0002-regenerate-xnn-buildgn.patch: Regenerate from upstream sources - fixes/fix-clang-selection.patch: Drop due to upstream changes Checksums-Sha1: 1b86ff05306db9f268ec656ecb06c8316bc7f7bf 5167724 chromium-common-dbgsym_144.0.7559.59-1~deb12u1_i386.deb ae6f723cee9fc6c599c3da94b87f755fda1c8924 23189900 chromium-common_144.0.7559.59-1~deb12u1_i386.deb 326f69904678f362d440b8858b57688d7b49e46e 34527404 chromium-dbgsym_144.0.7559.59-1~deb12u1_i386.deb e1dbef3c1e13b299f0684addb76aa8ece8a03586 7660844 chromium-driver_144.0.7559.59-1~deb12u1_i386.deb 34cf6de1a08f4949e75a9a59abaf7221fcee4f10 28572272 chromium-headless-shell-dbgsym_144.0.7559.59-1~deb12u1_i386.deb a131b054127ce196645c702fd329bcf0a96b50b0 56608576 chromium-headless-shell_144.0.7559.59-1~deb12u1_i386.deb 304fbec50f0700b93b2cd8bd264af2050a7bbeee 17828 chromium-sandbox-dbgsym_144.0.7559.59-1~deb12u1_i386.deb 492bc715d824932f06dfd0468d369cbca1c94389 109460 chromium-sandbox_144.0.7559.59-1~deb12u1_i386.deb be51963353abd4466342c1464291c08324397c94 31349176 chromium-shell-dbgsym_144.0.7559.59-1~deb12u1_i386.deb cff79fa5be43db7825a0afe432c9cfc88c6d7525 61762100 chromium-shell_144.0.7559.59-1~deb12u1_i386.deb 630f3a993b04716cfc4b72a11457ab05e5e42ba9 30372 chromium_144.0.7559.59-1~deb12u1_i386-buildd.buildinfo 6975dc090b186b46b40022f21e6962e9047db1a8 73955264 chromium_144.0.7559.59-1~deb12u1_i386.deb Checksums-Sha256: 2757b5630abd89fe54661bb843fccfb2c50ed41346d64b5254ff4a9a7a3d5b80 5167724 chromium-common-dbgsym_144.0.7559.59-1~deb12u1_i386.deb 8c84a3e77e69f99dfc4dbdf2189d9c7445ebfb423d18f2963b54982e0749e303 23189900 chromium-common_144.0.7559.59-1~deb12u1_i386.deb 2d8ac8e9c53e758046a7698c497ec03a5f19189fb448dd9c84c7c85037e75222 34527404 chromium-dbgsym_144.0.7559.59-1~deb12u1_i386.deb 7a8a04b5c37d1f845572beb25e86603384c055cdce9be76e4fb47719bd4cbd53 7660844 chromium-driver_144.0.7559.59-1~deb12u1_i386.deb 025b21031dcd81e988b040b7977d0b87ac5d1b1588f839680f45b7cca5791b33 28572272 chromium-headless-shell-dbgsym_144.0.7559.59-1~deb12u1_i386.deb 05caef4826e74c5850a29ed2ae85669ac4ab5002c3611ba8ecb1efa1ba60b262 56608576 chromium-headless-shell_144.0.7559.59-1~deb12u1_i386.deb df481f4612354b6cf1855855330fbaec2c6be310822fdf16baca98ca56911e3f 17828 chromium-sandbox-dbgsym_144.0.7559.59-1~deb12u1_i386.deb 89ca398ff557b76a10cacc5e77c4cf89ff695e83d48cac9493e9545866244349 109460 chromium-sandbox_144.0.7559.59-1~deb12u1_i386.deb 6c0c285115f4e88aebaeafa1e5286201194e87daea55e6d3a9d1470ac7e8f358 31349176 chromium-shell-dbgsym_144.0.7559.59-1~deb12u1_i386.deb c5dfff4cc1aa292b39470acb864399013152c91ab65017a4c7879e43e4b5ea7d 61762100 chromium-shell_144.0.7559.59-1~deb12u1_i386.deb 342a693bbf0a8411c79857499efeebc4abd9adbc6ad459d06d67611d8c134331 30372 chromium_144.0.7559.59-1~deb12u1_i386-buildd.buildinfo 97f038add38e979ed395fc61edc46a85721a5e1ef98214ca5130cb6a200ae4a9 73955264 chromium_144.0.7559.59-1~deb12u1_i386.deb Files: 4c0df07c88e4b5f1ef2826577aa2c07c 5167724 debug optional chromium-common-dbgsym_144.0.7559.59-1~deb12u1_i386.deb 0abff474532185bf1d31956418c7627a 23189900 web optional chromium-common_144.0.7559.59-1~deb12u1_i386.deb 9aca9f20d2a3dadca0a697f310dda9d9 34527404 debug optional chromium-dbgsym_144.0.7559.59-1~deb12u1_i386.deb 3f9cf5b300676024bfbc559a4535e7be 7660844 web optional chromium-driver_144.0.7559.59-1~deb12u1_i386.deb 8a524de4b41bc993e29e33402f427d67 28572272 debug optional chromium-headless-shell-dbgsym_144.0.7559.59-1~deb12u1_i386.deb dae022094cd9e4c229c5a5e0ef43b4df 56608576 web optional chromium-headless-shell_144.0.7559.59-1~deb12u1_i386.deb 79a4ad09ed4bdb7533b049cdc5ca651a 17828 debug optional chromium-sandbox-dbgsym_144.0.7559.59-1~deb12u1_i386.deb 9a651a58e01455579729b971638f83ab 109460 web optional chromium-sandbox_144.0.7559.59-1~deb12u1_i386.deb d98567b4dafd09b9c3e27ea3cd12bea0 31349176 debug optional chromium-shell-dbgsym_144.0.7559.59-1~deb12u1_i386.deb 87fc872d408707aad26c4abb5726a696 61762100 web optional chromium-shell_144.0.7559.59-1~deb12u1_i386.deb 7c0013753d5f22b275391a7611ae6484 30372 web optional chromium_144.0.7559.59-1~deb12u1_i386-buildd.buildinfo c632844a4f236e44643e04abc0c3daec 73955264 web optional chromium_144.0.7559.59-1~deb12u1_i386.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEv2qEY4xQXyY/2dWIvGw9w6VrLCcFAmln66kACgkQvGw9w6Vr LCe/Fw//VIKMUsZ+eCWuOiF6NBNY3L79bytfsosOp+CcYnmIq5LS1yX3ws+G3YZR SAvIIN63mVErZF5nntuJ0q8+/78Gfb7dVgMYUm5BkTcvI0QHGyIQr5/ZRDsWKIC6 ILWBhsAboxLKlGHvuGNtqUOPutpmSQiAJnE+6Upi79HmnG4zwsC2QKXIPbdFmjld bb6JVkj/LaEonU4F81+QJ1fadAAP8MBLoovr6s9fPfuDC9nvjbjTmoiTmY64GM57 snSscNifRFb/a4zl1/mphWR0mCZ4Rpp05TqqDKI7NJ2rSBhcirZury7gaegMPxGJ 7rV8RtFHKXKcrfxU7o4cpxZx4pL+MNhOMnW9cNkLwpBb1OVg2dVa9iUM7Mj7L9KL wNBD1lJ6fnK7LST/7vf/omI+EOkIaEOxMaZaZp+jlvXuO3JEfUreEGCAqxsuH3CR FUy57AFnK9n/5dpOuZzXUOhTdMIXEf8xSYtR8W7+onqfMUKuuAIGPlcECXI7+2Nk sp9X1gqMqmggZ6de8cGa+o8O81SO7U557yrLH+QVIn+e+yIQnyivP0dNERWO7lk3 uW6j8CSdSVtotHY0/pENDk3ZiB+qa+lBAxjL5dsF20yMk23AYzuaOjKA1k4DGw30 WrB5crcSEefZh7Lr2dI0djpEOjIVkUoyRFm3dICcQA/RCPS5N9E= =niK0 -----END PGP SIGNATURE-----