From: ftpmaster@ftp-master.debian.org
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
Format: 1.8
Date: Tue, 09 Sep 2025 17:50:07 -0400
Source: chromium
Architecture: source
Version: 140.0.7339.127-1~deb13u1
Distribution: trixie-security
Urgency: high
Maintainer: Debian Chromium Team
Changed-By: Andres Salomon
Changes:
chromium (140.0.7339.127-1~deb13u1) trixie-security; urgency=high
.
[ Andres Salomon ]
* New upstream security release.
- CVE-2025-10200: Use after free in Serviceworker.
Reported by Looben Yang.
- CVE-2025-10201: Inappropriate implementation in Mojo.
Reported by Sahan Fernando & Anon.
.
[ Jianfeng Liu ]
* drop not working fixes/libsync-rk3588-panthor.patch.
* drop fixes/strlcpy.patch, which isn't needed w/ clang-19.
Checksums-Sha1:
b30f41f8fa5a5428e1c09438c7f181e244410b93 4027 chromium_140.0.73
9.127-1~deb13u1.dsc
88c3f5e4cd9a91f4932b22d72d5306d97413a3b0 993548320 chromium_140
0.7339.127.orig.tar.xz
b23ff551253cf382027f7d3b2044027620404630 413764 chromium_140.0.
339.127-1~deb13u1.debian.tar.xz
1fdb3d0cdffb11046aec54c460dabad52128b6ff 26325 chromium_140.0.7
39.127-1~deb13u1_source.buildinfo
Checksums-Sha256:
42b3f702fa70e0cd0f7957c97be8b7908e2a6c5f80097690abe04ea27ecd971c 4027
chromium_140.0.7339.127-1~deb13u1.dsc
3fd2dd7a985db58c1dff2f99932f9bca30943b7ee686aa10c4009d9b153daa24 993548320
chromium_140.0.7339.127.orig.tar.xz
741dfc844590582271c3712c095e0ab22c2c42d7f31f53e30fdeb8c5cb1b2afa 413764
chromium_140.0.7339.127-1~deb13u1.debian.tar.xz
71669a4c68fb1be8ea2baef97524b5ded75501027b9dcf5c9cbf2f49eae01af9 26325
chromium_140.0.7339.127-1~deb13u1_source.buildinfo
Files:
369b7ab3046d0d9044d2f41e4a070945 4027 web optional chromium_140
0.7339.127-1~deb13u1.dsc
7bf46ebed3da2c6d0f1569f4d3017afe 993548320 web optional chromiu
_140.0.7339.127.orig.tar.xz
784a007468308a22f460028a7e69d6bc 413764 web optional chromium_1
0.0.7339.127-1~deb13u1.debian.tar.xz
22188e6dc85bfc055f25e2cb966e6956 26325 web optional chromium_14
.0.7339.127-1~deb13u1_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iQJIBAEBCAAyFiEEUAUk+X1YiTIjs19qZF0CR8NudjcFAmjBEL0UHGRpbGluZ2Vy
QGRlYmlhbi5vcmcACgkQZF0CR8NudjeFDQ/+MZPsZV+KpumUx5GDd85a6V4iJGY6
n0ZAgfQy2UW3phb5hPRXnOVpXz8g+XBxhL58pZXlLNp7nJUtcqRBsatDObgM9y1w
eK205lgFNwPqYIPgMJ6Skm22gvMmBXrLigZ+paS9EAChZSAEGRwPLWj2rDhqOVot
4hsipyvwLZsCOik+CgEcjTX8CohyKlQQAMHf15b7mE4+b+AZH/9yO6KI8hZGQbTz
QryvPbNe1kKKcxsAbL636dK4EkjBIwy0+IYZVhUqo9R4NwSmJKedicChqu4TgCAB
ha1+adZREK/YRgvQIxy0uqIL6RK2rrUwcMhMHgoy2Iz3egrVT+ijlHMqG2OsZ4O4
cHxQKgtZWIncEGnEzhfxbpN621UIKPNgTJ4z39FtCtrhXJCy+BPv+bUyg3dqmKBf
/MWr9lBhECcA/QJJ+Sa+kkmpaGp+DOnOt75xlnEZjbIYb9Z8qWjTl+MIsyDaVB9m
dwPWQowG0fkOVXTzk7FCTwKlnNZU+F2asKcBGUMjbSYDwPty+FvNBa98gKRCar7J
Gao4u5Bl6roT6l7D+SkSGPr2VWS114QzBnjRV9aKizvAr/JG3pAI7OK96kvZKpVx
dJKP2jozHT3uRPd6HKNvjWZmNxMoERvdCy74whTZ1dqmlNc9tafJMz3DDFMAtJvR
M1OXerkLPm5gbsM=
=2K90
-----END PGP SIGNATURE-----
--============== 13826480409603098=Content-Type: application/pgp-signature
-----BEGIN PGP SIGNATURE-----
iHUEABYIAB0WIQTziqJOuF8J+ZI8pJSb9qggYcy5IQUCaMhungAKCRCb9qggYcy5
IQsSAQDR6CbELPI7VkY9PSPdgvjxwV+70qj6DiNuqJc0cmDXqwD/eNGg6QnLelpi
RuQGVp8AzINbvl0QopqE8RTJQB4kag8=nnR+
-----END PGP SIGNATURE-----
--- SoupGate-Win32 v1.05
* Origin: you cannot sedate... all the things you hate (1:229/2)
|