-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
Format: 1.8
Date: Tue, 09 Sep 2025 17:50:07 -0400
Source: chromium
Architecture: source
Version: 140.0.7339.127-1~deb12u1
Distribution: bookworm-security
Urgency: high
Maintainer: Debian Chromium Team <chromium@packages.debian.org>
Changed-By: Andres Salomon <dilinger@debian.org>
Changes:
chromium (140.0.7339.127-1~deb12u1) bookworm-security; urgency=high
.
[ Andres Salomon ]
* New upstream security release.
- CVE-2025-10200: Use after free in Serviceworker.
Reported by Looben Yang.
- CVE-2025-10201: Inappropriate implementation in Mojo.
Reported by Sahan Fernando & Anon.
.
[ Jianfeng Liu ]
* drop not working fixes/libsync-rk3588-panthor.patch.
* drop fixes/strlcpy.patch, which isn't needed w/ clang-19.
Checksums-Sha1:
eff89f7c9866df3a52073b2077e2ae720e5a93b4 4063 chromium_140.0.7339.127-1~deb12u1.dsc
88c3f5e4cd9a91f4932b22d72d5306d97413a3b0 993548320 chromium_140.0.7339.127.orig.tar.xz
32e1c6e22d58557c276571f13e7ad16994972ffe 8501476 chromium_140.0.7339.127-1~deb12u1.debian.tar.xz
e408591d6601f1e92f3bea86937f8e786fc62899 26765 chromium_140.0.7339.127-1~deb12u1_source.buildinfo
Checksums-Sha256:
2a26eeb00fb6802650acb2fe196087bb5d56fc249bcd5ec1707d1042bbc3389e 4063 chromium_140.0.7339.127-1~deb12u1.dsc
3fd2dd7a985db58c1dff2f99932f9bca30943b7ee686aa10c4009d9b153daa24 993548320 chromium_140.0.7339.127.orig.tar.xz
32fdd7c9c441922351e8d091eed8448b68cd361b1ad4265821608c3f0a5120f8 8501476 chromium_140.0.7339.127-1~deb12u1.debian.tar.xz
9c0006ef70decc354391886fc39d4f7073b6cc9431404bf31815788d5bb15337 26765 chromium_140.0.7339.127-1~deb12u1_source.buildinfo
Files:
83f0637cc9331377e9de423f8bec4d66 4063 web optional chromium_140.0.7339.127-1~deb12u1.dsc
7bf46ebed3da2c6d0f1569f4d3017afe 993548320 web optional chromium_140.0.7339.127.orig.tar.xz
5aad824d09fe17a32f6adb03af325a3a 8501476 web optional chromium_140.0.7339.127-1~deb12u1.debian.tar.xz
8a0aba19712a79ca60f98460075b5e3b 26765 web optional chromium_140.0.7339.127-1~deb12u1_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iQJIBAEBCAAyFiEEUAUk+X1YiTIjs19qZF0CR8NudjcFAmjBM/UUHGRpbGluZ2Vy
QGRlYmlhbi5vcmcACgkQZF0CR8Nudjf2DhAAnA4KKMBej6C5fyBjDwvXgoH7/9Yk
AXCABz2OdLB29DhvEeJwAE86UMwpSmyr3ypGFdV+05mzTgtaVdD5CRfQN81w1k03
DSKE8SH68E8fM7BQ1WXYe3bEJOL/mjqEPF7nd4hKh3+hirQR60A6FfF6fa8sUpd/
hmQGIEL8bpgdrJ39wW8xnehqfKWUEPJ3C3n7YVTPtKyoi0A+cTd+MmTST1HpVq4o
kh8YG7gEMcaFV830dDZd9w3mTJl7TadcTljqmSn0N1v98k7MREE8x7mIOpn1yyiu
stL6KHQxnh+sSLgfeAF6INRvUarQkztrNw778SxW15FQvSmlquGORCGen5PzzBu+
7B5Of6/If0lwjkVOcInH8Yn68vHLkdo8GFgzaFBrkW7EvloJ0UN0w6zJcYJd9146
gu0K6dFeoM7sL/ROFD+VOz1Pj6DP0KhrwoXpvVU7SvGyPoEEdCAJoUGXb+GYNTTt
Mbq3H7mNXX/TaRi0JJhsx3/Hyi/Lait7JkkQN2zt00hgZS1PpnxBwtiCf7hLqgwp
ACKy1GhqNokINEgflM/3pglt/vL2WlDmmMgv0QAVRASNpC+Siuw+/Gv/adU5VUX7
DUI7058+1GcYRtfnbNCzcfY1w4881W9PjD5aSQOg8gyjerXEQolhM8awIZmhTHd1
6TMdNoV9X7JcLPQ=
=rL7I
-----END PGP SIGNATURE-----