-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
Format: 1.8
Date: Tue, 13 Jan 2026 22:11:21 -0500
Source: chromium
Architecture: source
Version: 144.0.7559.59-1~deb13u1
Distribution: trixie-security
Urgency: high
Maintainer: Debian Chromium Team <chromium@packages.debian.org>
Changed-By: Andres Salomon <dilinger@debian.org>
Changes:
chromium (144.0.7559.59-1~deb13u1) trixie-security; urgency=high
.
[ Andres Salomon ]
* New upstream stable release.
- CVE-2026-0899: Out of bounds memory access in V8. Reported by @p1nky4745.
- CVE-2026-0900: Inappropriate implementation in V8. Reported by Google.
- CVE-2026-0901: Inappropriate implementation in Blink.
Reported by Irvan Kurniawan (sourc7).
- CVE-2026-0902: Inappropriate implementation in V8. Reported by 303f06e3.
- CVE-2026-0903: Insufficient validation of untrusted input in Downloads.
Reported by Azur.
- CVE-2026-0904: Incorrect security UI in Digital Credentials.
Reported by Hafiizh.
- CVE-2026-0905: Insufficient policy enforcement in Network.
Reported by Google.
- CVE-2026-0906: Incorrect security UI. Reported by Khalil Zhani.
- CVE-2026-0907: Incorrect security UI in Split View. Reported by Hafiizh.
- CVE-2026-0908: Use after free in ANGLE. Reported by Glitchers BoB 14th.
* d/copyright: delete a copy of clang-22 in the openscreen build directory.
* d/control: add rustfmt as a build dependency.
* d/rules: make DEB_BUILD_OPTIONS=terse work.
* d/patches:
- disable/tests.patch: refresh.
- trixie/rust-sanitize.patch: refresh.
- bookworm/bindgen.patch: refresh.
- fixes/force-rust-nightly.patch: add workaround to force
rustc_nightly_capability, as we're using an up-to-date rust.
- trixie/value-or.patch: add clang-19 workarounds to help
calling value_or() with ambiguous values.
- fixes/autofill-binarypb.patch: add patch to fix build for us stripping
out binary-only files containing city/state autofill aliases.
.
[ Daniel Richard G. ]
* d/patches:
- trixie/adler1.patch: Refresh to follow use of if-else.
- trixie/libxml2-no-xxe.patch: Add workaround for older libxml2.
.
[ Timothy Pearson ]
* d/patches:
- trixie/nodejs-set-intersection.patch: avoid using node >=22 intersection
* d/patches/ppc64le:
- ppc64le/third_party/0002-regenerate-xnn-buildgn.patch: Regenerate from
upstream sources
- fixes/fix-clang-selection.patch: Drop due to upstream changes
Checksums-Sha1:
e2e095c36690ca2b654aad208d33cc8edf76a793 4100 chromium_144.0.7559.59-1~deb13u1.dsc
5b335937cd5f599303f406166ccaef442e760b18 733515824 chromium_144.0.7559.59.orig.tar.xz
3bf2e6851b249a9a113ae908764cc96fd86ac7e0 443784 chromium_144.0.7559.59-1~deb13u1.debian.tar.xz
3cda59d74f7136f730753e141a3d68607ce2c162 26764 chromium_144.0.7559.59-1~deb13u1_source.buildinfo
Checksums-Sha256:
a29ca5f7ee90ec0659d883af437c48f39ce74c46b33c29456a566260b72ce533 4100 chromium_144.0.7559.59-1~deb13u1.dsc
b55c35e99d664d45cfdb515b7523ee5188e9887338ca13fddab78c2f83f7640e 733515824 chromium_144.0.7559.59.orig.tar.xz
f6f0dc195ac8f9125317c2338395f557704401c552eea097d2986c2b00c2622c 443784 chromium_144.0.7559.59-1~deb13u1.debian.tar.xz
bb933130bb42c2471142ade8f888839719ca28abefe8e82d6eb9c4e19b926232 26764 chromium_144.0.7559.59-1~deb13u1_source.buildinfo
Files:
1b8115febbe25b7aec782ed2cd90ab31 4100 web optional chromium_144.0.7559.59-1~deb13u1.dsc
ae058beb7bbe9f3af50f46c5486adf66 733515824 web optional chromium_144.0.7559.59.orig.tar.xz
e63d9ce3142610c7a99870f53a4e47a9 443784 web optional chromium_144.0.7559.59-1~deb13u1.debian.tar.xz
37e1d79a7287e5a40cee1c8a3effddf7 26764 web optional chromium_144.0.7559.59-1~deb13u1_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iQJIBAEBCAAyFiEEUAUk+X1YiTIjs19qZF0CR8NudjcFAmlnIsAUHGRpbGluZ2Vy
QGRlYmlhbi5vcmcACgkQZF0CR8NudjcAixAAv9p4cimtOfmCN8wEOewYznztt9hz
9yP+5IwGatAfzPz2/4fc8nRQWPfFvtqbQqnuenU8Y/RfOT5aewVFjqc5yhewJpCp
g6OSQqVv0lpIYgpTWhBVJRWFUWwjzncve47Xs7KEBKa8t6B6HkQlBN2WQ7xBBPa8
DvxaeMfviz6NkjJNTgXeZdKBssVLmd8kCYk86JhuePj7qOA7HIxY4rV9NRIMgqFq
zX/icZcyc6jtEl24nqdQA+/4mb9a/TgeDZ2rCgGtWXKBMOaprpuuHazuBAQlvze4
Q6jucmBP1kT9xfwgZlaq80UUh1OjT20S+7hMRe7p7AF8bDwBfaIT9yTK4RUiKACg
ncvDPCtuR7Dg+SCW9L3H0/5qiasSHMct+BTs28BPiqc7Z/3MIYfr0/THej7zyNHs
LnPncpkYwYsKv7rSzzomtRh5jTRqzQvKS67QnDEq+Q1YV89W+BkC1W3BWDy7yIsz
hI8r0CXBaG46RZzGTRWFdTUPv7No/FjrGC8EUyV21r3CfUZueGgvI+JMBMEbXz5l
FMY7AFojhW83v4G1yR9lMccjv71iLHTfV+irbvRpv0K3EdGtaZktIzHYjBDEjOIC
rZDl7xZ7Ia1opzwqGzgLioxkQxUZ8479kljWOxhsnn+cHbatTsL7UWNAkCAh6Hpz
q9E7i8euCoObzuY=
=dyjw
-----END PGP SIGNATURE-----