-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
Format: 1.8
Date: Tue, 20 Jan 2026 20:25:10 -0500
Source: chromium
Architecture: source
Version: 144.0.7559.96-1~deb13u1
Distribution: trixie-security
Urgency: high
Maintainer: Debian Chromium Team <chromium@packages.debian.org>
Changed-By: Andres Salomon <dilinger@debian.org>
Changes:
chromium (144.0.7559.96-1~deb13u1) trixie-security; urgency=high
.
[ Andres Salomon ]
* New upstream security release.
- CVE-2026-1220: Race in V8. Reported by @p1nky4745.
* d/scripts/unbundle: switch to bundled libxml2, so that we get features of
XML_PARSE_NO_XXE (which disables loading of external content) in
trixie/bookworm.
* d/copyright: stop deleting the bundled libxml2.
* d/clean: stop deleting the libxml2 symlink.
* d/control: drop libxml2-dev build dep.
* d/patches:
- trixie/libxml-parseerr.patch: drop; we're using bundled libxml.
- trixie/libxml2-no-xxe.patch: drop; we're using bundled libxml.
.
[ Daniel Richard G. ]
* d/patches/bookworm/bindgen.patch: Move the libclang edit from here ...
* d/patches/fixes/bindgen-paths.patch: ... over to this new patch, which
takes a simpler approach that is easier to override later in the series ...
* d/patches/ppc64le/fixes/bindgen.patch: ... and makes this patch redundant.
* d/patches/ppc64le/sandbox/0001-sandbox-Enable-seccomp_bpf-for-ppc64.patch:
Add a __NR_mseal definition that is needed in the Ubuntu builds.
Checksums-Sha1:
e02875c3e2c23005212e761119a9c95ec6fd2379 4077 chromium_144.0.7559.96-1~deb13u1.dsc
41baa4e392a418fb4a2fdd73c9e5044eb935b5df 734367996 chromium_144.0.7559.96.orig.tar.xz
75abace98a0d5f094e16f0e3178a3a54ee0cd05d 443896 chromium_144.0.7559.96-1~deb13u1.debian.tar.xz
18caa67990f4d410b5c5571bf6bdedcc4d369308 26764 chromium_144.0.7559.96-1~deb13u1_source.buildinfo
Checksums-Sha256:
6f2418f809f397e8f244c7d31242622fca8432deedc7302dd61a5bed60f7a701 4077 chromium_144.0.7559.96-1~deb13u1.dsc
25358df2bc37accbd02337b6ec04b79d051e6a4bd1379b9265a0605ab9d481c1 734367996 chromium_144.0.7559.96.orig.tar.xz
f3a1443cb3c760779255ac33c04004532cb62c08cabdc3affa7e2a1875d8855d 443896 chromium_144.0.7559.96-1~deb13u1.debian.tar.xz
0cfc983d96f2926128803cc03d2db4b3485e5708cbe379885b8ce100cb7a8964 26764 chromium_144.0.7559.96-1~deb13u1_source.buildinfo
Files:
ffa702a0083aa45e4e58c76a7914bc5a 4077 web optional chromium_144.0.7559.96-1~deb13u1.dsc
03bae05ed88c11fd27df15c8df41e0a3 734367996 web optional chromium_144.0.7559.96.orig.tar.xz
f7c4ec2344b792c72cf52912a3fe2f75 443896 web optional chromium_144.0.7559.96-1~deb13u1.debian.tar.xz
78c0796a068407fdb5b8d5eeb9ddc261 26764 web optional chromium_144.0.7559.96-1~deb13u1_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iQJIBAEBCAAyFiEEUAUk+X1YiTIjs19qZF0CR8NudjcFAmlxJJwUHGRpbGluZ2Vy
QGRlYmlhbi5vcmcACgkQZF0CR8NudjdA4Q/6ArNkqblLRAVYicqA8OYW4lEoUuuT
kmMzG3pkfWkOZDf+s7QSI2Y0S2xv+YfG3tH/EId58jmcmtwhZFktCSYS/onfuWTr
QwL9RrSsKSUJ9rJII8oS+HhtepQdqNptePFLGPxH2FEAfDvjwTX1uO5rF5o+uKpF
dMeq5ssEwInVJLBUol6LiGwvW2vFw6/NA/lcfiBdzTacm26543oiUDqD3r+u54Wn
gI2XBwpLA2RAJuf4mny2dkDlqMrmuVJp0F7fCWr+3yWlbjqeS3kq1m+MeYyS708k
qzCEC8ciMHe25P4nPjhVzBzQi+nk0k5CqpRUmiPySm5Y1Y8+x3CAlLgUhnI20KXP
5ORKtzXVVVPX7inofPytQav6GaO6EuyP1ZSSSro4dEjO8moQ/ZfPUgXib91OTkgf
j4lpARKt14j40bt6gSCU6FIwkc/15YpZEaMLEU9KliCZkQBN9/ZzPRepHT7VNyRE
dAk1/04zzLl/KLXxl58r9xxI17arb9Ju98bi2762tZUPbK7IcPy9pF/MCSR77TYp
NDVL0/rosm4J1x+wYT30UTCsrb7LAtLiuEYv0vtDVHhNsKwbku1Ey2oAKvz/5zNI
c+fThynWyL26V5F6EwpPR8nQicCFvETRh59ZAOWzfFOLROQ6s8f6ByJHgu9oIZkl
PpwNOyBWuWTtcZo=
=KhCw
-----END PGP SIGNATURE-----