-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Tue, 06 May 2025 14:13:50 -0400 Source: chromium Architecture: source Version: 136.0.7103.92-1 Distribution: unstable Urgency: high Maintainer: Debian Chromium Team <chromium@packages.debian.org> Changed-By: Andres Salomon <dilinger@debian.org> Closes: 1104218 Changes: chromium (136.0.7103.92-1) unstable; urgency=high . [ Andres Salomon ] * New upstream security release. - CVE-2025-4372: Use after free in WebAudio. Reported by Huang Xilin of Ant Group Light-Year Security Lab. * Drop yasm build-dep; upstream switched to nasm about 5 years ago (closes: #1104218). . [ Daniel Richard G. ] * d/patches/fixes/armhf-no-thumb.patch: Fix armhf FTBFS due to use of a Rust target (thumbv7neon) that Debian does not ship. Checksums-Sha1: 48aeac61f898d5416c9ebea93424fdd1b3187d17 3787 chromium_136.0.7103.92-1.dsc 55d811df0a3c8d149eb2a6c3fe04dee7874acf1b 938020928 chromium_136.0.7103.92.orig.tar.xz 788e7029c894779afd1890379505260a954a37b2 338904 chromium_136.0.7103.92-1.debian.tar.xz 4d9730d9b496724340ce418374b7b9dedf8666ef 26695 chromium_136.0.7103.92-1_source.buildinfo Checksums-Sha256: c9bb1cb49c99d11f82a44af04108f3032513bbab8d3ca7ab13a914cdc71f3dec 3787 chromium_136.0.7103.92-1.dsc 9e7636b5b3c800efa22a3f6109d382094cb807324eb15bba1ffdfe59ec051b83 938020928 chromium_136.0.7103.92.orig.tar.xz 2c3e5f5b3bdc5db536e1f9654cdefcb4b0c5269fa2acdc369a8e2bfcdd9f1b64 338904 chromium_136.0.7103.92-1.debian.tar.xz 1d94808e709bcd3b3297c69751945cdb2f9707edb073bd781ee7ee38b13ee1e4 26695 chromium_136.0.7103.92-1_source.buildinfo Files: be322e9937b2de5ac3d7c7e76cc43729 3787 web optional chromium_136.0.7103.92-1.dsc 45ba5513c590d5b7b893a802a7cbb9a6 938020928 web optional chromium_136.0.7103.92.orig.tar.xz 818761b602760b6eb78b75f2297a4d05 338904 web optional chromium_136.0.7103.92-1.debian.tar.xz c2bcc900d956ad76ff53f8a95faa7a98 26695 web optional chromium_136.0.7103.92-1_source.buildinfo -----BEGIN PGP SIGNATURE----- iQJIBAEBCAAyFiEEUAUk+X1YiTIjs19qZF0CR8NudjcFAmgauyAUHGRpbGluZ2Vy QGRlYmlhbi5vcmcACgkQZF0CR8NudjdyIA/+Lb4pApXfDKs+vVF4qfxFhFkp9A/C JcJ4b0B729j/+upei9rKnOFkLpZhX6BEOaOTnRX5Wh9UNWtCAiir381wE4/cioEL v8105bdYpsmikVwi1SFn/ap3d7TjwU8M8/RI/qwbA+nPkeyLsBZEVJV3AZBEaoci dFMwUtrkliRUxEKN5VkkI6Dedj20A7duAW4BbZlmcNDqeebYloC/PbbvkMMpfzN3 UeIh8ffSgf/PLVZS2JxGJKMyddQFhLRyUYlzoXV/kzn1//l2iota2d26h7FJYIeG E/ZzZZkfX+Gze3oUmFMS49kaUSsFtAEpwnZjh8ASOpbB8ofY6DbSP7qu0H0UUzmp AZ+bQm2QHOFvU/0XBr5DeE73T0CPqxPl6FCShJ/UgcBAeucyWq4WcHk8HFTOqCSm 11NCDBIAAVhgK0B4nqhGkbumqgboVo3lODXri0JgeIe6KxTLy2mOMefwF2l9XsJN o8w/ItLRTtYtnjSkC9PnaeRYRHwCENOeb9wqOviAian/i/+aRlwoiNTI+fSgqH+V ywl9B/gUirh2jhBeHd5q/90xX3jxZaQjYK/G3nbSVNE0xdws+eTBJ3GujpqLdR1X JyKWatR2PLnrjS/pQoegGVJM2kFt17Ye7DzFAPhpZgIIIDCGFedLAq37ZYfWEsGW ZyobdEgHhxvTxOo= =p8Zt -----END PGP SIGNATURE-----