-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Wed, 14 May 2025 14:41:31 -0400 Source: chromium Architecture: source Version: 136.0.7103.113-1~deb12u1 Distribution: bookworm-security Urgency: high Maintainer: Debian Chromium Team <chromium@packages.debian.org> Changed-By: Andres Salomon <dilinger@debian.org> Changes: chromium (136.0.7103.113-1~deb12u1) bookworm-security; urgency=high . * New upstream security release. - CVE-2025-4664: Insufficient policy enforcement in Loader. Source: X post from @slonser_. - CVE-2025-4609: Incorrect handle provided in unspecified circumstances in Mojo. Reported by Micky. . chromium (136.0.7103.92-2) unstable; urgency=high . * d/patches/upstream/arm32-crel.patch: add another armhf FTBFS fix; linking with CREL causes segfaults. Checksums-Sha1: ff680f763216b210d6c43dc2d064c43fbea21321 3862 chromium_136.0.7103.113-1~deb12u1.dsc db9b2e3b84cb3f3082f784c323dcf46c21bacab4 937056028 chromium_136.0.7103.113.orig.tar.xz abdaffadb4357adacbf0d37a7a4f7cee1b056440 8426148 chromium_136.0.7103.113-1~deb12u1.debian.tar.xz 0c86f02c0876a513a8e3ff2b387797686a422a20 26577 chromium_136.0.7103.113-1~deb12u1_source.buildinfo Checksums-Sha256: 44bf46c6af120510b3e44c8b7543409742cecbad986a08e31d3a8e384ef6efd8 3862 chromium_136.0.7103.113-1~deb12u1.dsc b118b7ac145d82fb2adbfe2ad66d67a64fc538ee4599346ea6fb81428c9466e4 937056028 chromium_136.0.7103.113.orig.tar.xz 6ad551cddae27ffca327df54ddc1e0d06b05279e370f9160cd287b8943651102 8426148 chromium_136.0.7103.113-1~deb12u1.debian.tar.xz 0eb2b360c1cb7f08c8f61221eb2a102bb5ee3f2d36577ca4e3e25c69efdfa761 26577 chromium_136.0.7103.113-1~deb12u1_source.buildinfo Files: be52545eec2da4442eb42512c64cc8e8 3862 web optional chromium_136.0.7103.113-1~deb12u1.dsc c6187fad04c0c46582ffdd6d61822421 937056028 web optional chromium_136.0.7103.113.orig.tar.xz ce936d9396be3f263a188dc85b0951a8 8426148 web optional chromium_136.0.7103.113-1~deb12u1.debian.tar.xz 3b04c13bd1727c55d3e964c58be9394c 26577 web optional chromium_136.0.7103.113-1~deb12u1_source.buildinfo -----BEGIN PGP SIGNATURE----- iQJIBAEBCAAyFiEEUAUk+X1YiTIjs19qZF0CR8NudjcFAmglXJsUHGRpbGluZ2Vy QGRlYmlhbi5vcmcACgkQZF0CR8Nudjf7BQ/+JVykz3FdbPW8ccCExfv9bFpDjIXl HDEC60ZdEn8jRm8yVTvpRz4kbG+6eDlA9I2jQuAKoupBgCdotdf8++A7cizN4v7Y avYWRYIrr+2M40BVNV/WdTng2Lzrk77RpY2FHQou8fhAwTZBIuiBMScrjYlrg5aK g7mNtRLeskx8Z+s3l5tuxxGKnIKBx1ZMpf972RdGirX35EoeLbhvOFzm3jenuLEG nQ5G7GaJVtknkDIwZtNagjmWrlHYs9hS4dN18n/ldAtat/qNEDqlNk83L1FgUYN7 /GqX+v3pHaMMIYD8Lkm22jLE5BwHqJDRdxyDZsS2iGq542Eibo9foG0fQsXcEdzY WOWa5i66swT21GzY2rEk+/jH3xSmQOGXFVBlSjWMxksUDuw4NSjoBskqPydlRPin 60R3JXs5RwgAkYSH8m6YJ8jgeCzOT38rUQOgF0BCabiAWK6dSSKbkmHwDm58PSUZ 0ANKpwx5vABr3XrQuP4CkEJ/qSwMRt/ojCuDLDs0s7ZlfdmXiCDJ5dtz28/DdLwI fCZwyfMaeFKX82V588Lp6DV+P2Tur+CICAuLH0KQA63A6QwLfp4+WTqLfJpFy3lo ia0p1+N6ry+TjDko6BSUKG4NdfAVolaWRQYlLqrYecV1T1aUoo5F2RzDdhvtCS56 cJqgTdJfdN4xClU= =Zb/Z -----END PGP SIGNATURE-----