-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
Format: 1.8
Date: Thu, 19 Feb 2026 20:50:42 -0500
Source: chromium
Architecture: source
Version: 145.0.7632.109-1~deb13u3
Distribution: trixie-security
Urgency: high
Maintainer: Debian Chromium Team <chromium@packages.debian.org>
Changed-By: Andres Salomon <dilinger@debian.org>
Changes:
chromium (145.0.7632.109-1~deb13u3) trixie-security; urgency=high
.
* d/rules: drop CVE check for security-uploads (no functional change).
.
chromium (145.0.7632.109-1~deb13u2) trixie-security; urgency=high
.
* d/patches/rust-1.85/jxl-simd-avx512.patch: try again; rustc didn't
like where I marked some of the neon functions as unsafe.
.
chromium (145.0.7632.109-1~deb13u1) trixie-security; urgency=high
.
* New upstream security release.
- CVE-2026-2648: Heap buffer overflow in PDFium. Reported by soiax.
- CVE-2026-2649: Integer overflow in V8.
Reported by JunYoung Park(@candymate) of KAIST Hacking Lab.
- CVE-2026-2650: Heap buffer overflow in Media. Reported by Google.
* d/patches/rust-1.85/jxl-simd-avx512.patch: mark neon functions as
unsafe to fix arm64 builds.
Checksums-Sha1:
fbbba5138ac5d86bc626b2bfbe8ead981f7caecf 4113 chromium_145.0.7632.109-1~deb13u3.dsc
b7c1bcdf6d22e706d98e959c9de58f985c2156b0 747261032 chromium_145.0.7632.109.orig.tar.xz
f1d985a966ac578faf7cddbbeda9bdd5dfa66e3a 455024 chromium_145.0.7632.109-1~deb13u3.debian.tar.xz
e48a0aa1f1af96dd8dd165a6d03ab0cc0ebdbd57 26893 chromium_145.0.7632.109-1~deb13u3_source.buildinfo
Checksums-Sha256:
def9538bf4fc04ffb15a91c71571ee82247b67cb7a50132774a7bd221e073a38 4113 chromium_145.0.7632.109-1~deb13u3.dsc
8c54868014ccf325a27017f8a6c8ae73c8ca0ca3016e444c6ad28d3f8225f529 747261032 chromium_145.0.7632.109.orig.tar.xz
ee57b18c0974e85c53c3cdd0118e1f5535be135345b018abcdc88aed88bf10f9 455024 chromium_145.0.7632.109-1~deb13u3.debian.tar.xz
dd94434906e15c4b49cb2ac55da3df7b05c5380c2580d2caed66c17af65cdbb2 26893 chromium_145.0.7632.109-1~deb13u3_source.buildinfo
Files:
0d6ec972bc1ef52a690829d38d78b520 4113 web optional chromium_145.0.7632.109-1~deb13u3.dsc
6306af0f29c52a538845bc0a7861da2f 747261032 web optional chromium_145.0.7632.109.orig.tar.xz
a291915f09c96c953823642ef002783b 455024 web optional chromium_145.0.7632.109-1~deb13u3.debian.tar.xz
3997b0ee64cb718c87e514bdbfc48a23 26893 web optional chromium_145.0.7632.109-1~deb13u3_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iQJIBAEBCAAyFiEEUAUk+X1YiTIjs19qZF0CR8NudjcFAmmXv3cUHGRpbGluZ2Vy
QGRlYmlhbi5vcmcACgkQZF0CR8Nudjc9AA//Xicg+fO0QjaWLZbtJuUrJvmAj+LI
4QjbMnrVz0dtj2/d/I8ULlI1NIxYDdPJ3L+k4hYXlPK7vw0kocWchHEHEsmf0kJh
3zxeiPzhjAcx97GrZLu5KWp1AcezEzqm/z2i7jGrO94QS4wZne5BdrHHqx/eTIhr
LWI+9BY70Cvweb44q3ero3zLLhcJSKOcKctNm8LG+hnxtXDCxNu9XDFeMo3zJZGN
M5MpLIGnP6qr5BoRgPvhM4pZX0LemTfXB4ZWRoz4sVmsxYLVBI+tf97HNrZ8gZO9
E/TnXhswZvxk4oKat2nTe3pqsjkS6Gm2kVzMS5YpuZ4WpzGKyH/Bpb1RnfEA4LKL
yl8flP+b7Y5eDQL0WDZcLnZACZtyHaQpGEDXQYqjZV8i4lSK+N8rPqyVgmDbaV5Z
2QoCjS8XoB8Y13nlL6CejePw70EwOp+1MBfgXCs/7ut+7bWyA5iMAWeDXLQgRHzs
KLJkKIo/HVvX7Phlx3fi8aXuX2laiI+PvsK1xOifsBJ8Pnlw57ppuyq0HRD+wF3b
69yoQvNWnRKt223+x38/mF5OlF5FIsDJfcSTC5fFJLDUI9e4ZLXZWUY9vQ6oNK+A
iBTCpLhX/Rx4RM70v6iJAArsS+QastB5YCJuv4Ep7sAP9l14uJv2hBhvvWIX7IWq
9DrPSzn8F8zwgnc=
=6/NW
-----END PGP SIGNATURE-----