-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
Format: 1.8
Date: Tue, 07 Oct 2025 20:11:58 -0400
Source: chromium
Architecture: source
Version: 141.0.7390.65-1
Distribution: unstable
Urgency: high
Maintainer: Debian Chromium Team <chromium@packages.debian.org>
Changed-By: Andres Salomon <dilinger@debian.org>
Changes:
chromium (141.0.7390.65-1) unstable; urgency=high
.
* New upstream security release.
- CVE-2025-11458: Heap buffer overflow in Sync.
Reported by raven at KunLun lab.
- CVE-2025-11460: Use after free in Storage. Reported by Sombra.
- CVE-2025-11211: Out of bounds read in WebCodecs.
Reported by Jakob Košir.
Checksums-Sha1:
05b97ea9d8f4a148061cd954a53cc3b3274f93a7 3991 chromium_141.0.7390.65-1.dsc
d53e0f1b05daf0cb3d0d28fd1ba3466f91ffc1a2 1001790556 chromium_141.0.7390.65.orig.tar.xz
c86b4868646ece2a496b316533d015ca92de5617 415116 chromium_141.0.7390.65-1.debian.tar.xz
4bf469118fc1702a051b239b1ff343123d34846f 26252 chromium_141.0.7390.65-1_source.buildinfo
Checksums-Sha256:
9fe5ddc4a89eb99eda38861c296f69b3c5d5295e79225b17f5f925a66b9151f1 3991 chromium_141.0.7390.65-1.dsc
ca4812bc3533ee988bb26b30fe095bd9335cd0652cc2a3ad8fac31bd59a2ff5d 1001790556 chromium_141.0.7390.65.orig.tar.xz
d2d120527ca75400375064d52f640fe9a4128513a5a3d68d698ac2a09d40e6c7 415116 chromium_141.0.7390.65-1.debian.tar.xz
ad4fd516399c25b0841ace69be46373dec838f0231f043e5cd598f5c1e82c043 26252 chromium_141.0.7390.65-1_source.buildinfo
Files:
866461bd1c472bbd9582117bd3be8448 3991 web optional chromium_141.0.7390.65-1.dsc
85d4e6ca2e19d14bf7d3cd1a7d202227 1001790556 web optional chromium_141.0.7390.65.orig.tar.xz
662dd1e788cb012d50bb7bd0bf01461a 415116 web optional chromium_141.0.7390.65-1.debian.tar.xz
5edf35592ada499d1f5e6eb4cb1a7529 26252 web optional chromium_141.0.7390.65-1_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iQJIBAEBCAAyFiEEUAUk+X1YiTIjs19qZF0CR8NudjcFAmjmD88UHGRpbGluZ2Vy
QGRlYmlhbi5vcmcACgkQZF0CR8NudjevWw//YMEItDreOD0bukr911LYq/1Vck5e
vKMP8+16BucaIyl4rILjynwjTFCS2uePAzIl/I9HrXboKGnqfa5jgaSHBjUM1OMJ
G3t24AFNysfTkqKEUTwse4/R6N++MGIwQiWLXfEdXTP2MFJVDhwEN1MLYKba08z1
srvlin3b6bfXUPxpUuoPhWrsDExgcHynhb06KHTOwi11LM4bywNpcF/orm7w8PON
UImXf5GYp+4Ic5m1n8kafD8gRIH340rAQ8xuFHwjD/6ViENGsOw/o0cBoVHMvWi5
71K7YyHgWn03Ixv2sTt2ykaTcB7izuM3NUFhpAKI0A4F6MU7Jd+WdAeLI0fPvtCg
9CuJbNkrXQFo7h1gP4mEAIhpzc2doKBv/MBASHuBZg/JtQDNbD/xqevx02jD+PHC
CoxQDaLc9JrAvgheSHe4ZGSdaGtrFcWafxpLjAUgwqQ5ip9tyJlQ3SHTsSnQSWXT
FwdYlU1yIqko2zltVg4kIiYUe/Y0KEqWQI2Nl+xjc6vQgKqAjAN3dXMkVxV7FmDl
X+HkniMOKeohbkdbyRytYbzoghyWNvVRxJ5jDy3bz+RLvYI3D1Ma/7TQ09LtPbBi
ULG5i3XInMUNiE+mFVzPP35RIolC7+cbK5yTttZhOL88S7OJOLmLyGFUsRTJIo8G
Xs0p9jnxl9J9iPk=
=gptQ
-----END PGP SIGNATURE-----