-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 01 Apr 2026 12:42:51 -0400 Source: chromium Binary: chromium chromium-common chromium-common-dbgsym chromium-dbgsym chromium-driver chromium-headless-shell chromium-headless-shell-dbgsym chromium-sandbox chromium-sandbox-dbgsym chromium-shell chromium-shell-dbgsym Architecture: ppc64el Version: 146.0.7680.177-1~deb12u1 Distribution: bookworm-security Urgency: high Maintainer: ppc64el Build Daemon (ppc64el-conova-02) Changed-By: Andres Salomon Description: chromium - web browser chromium-common - web browser - common resources used by the chromium packages chromium-driver - web browser - WebDriver support chromium-headless-shell - web browser - old headless shell chromium-sandbox - web browser - setuid security sandbox for chromium chromium-shell - web browser - minimal shell Changes: chromium (146.0.7680.177-1~deb12u1) bookworm-security; urgency=high . [ Andres Salomon ] * New upstream security release. - CVE-2026-5272: Heap buffer overflow in GPU. Reported by inspector-ambitious. - CVE-2026-5273: Use after free in CSS. Reported by Anonymous. - CVE-2026-5274: Integer overflow in Codecs. Reported by heapracer (@heapracer). - CVE-2026-5275: Heap buffer overflow in ANGLE. Reported by c6eed09fc8b174b0f3eebedcceb1e792. - CVE-2026-5276: Insufficient policy enforcement in WebUSB. Reported by Ariel Simon. - CVE-2026-5277: Integer overflow in ANGLE. Reported by c6eed09fc8b174b0f3eebedcceb1e792. - CVE-2026-5278: Use after free in Web MIDI. Reported by c6eed09fc8b174b0f3eebedcceb1e792. - CVE-2026-5279: Object corruption in V8. Reported by Hyeonjun Ahn (@_deayzl). - CVE-2026-5280: Use after free in WebCodecs. Reported by heapracer (@heapracer). - CVE-2026-5281: Use after free in Dawn. Reported by 86ac1f1587b71893ed2ad792cd7dde32. - CVE-2026-5282: Out of bounds read in WebCodecs. Reported by c6eed09fc8b174b0f3eebedcceb1e792. - CVE-2026-5283: Inappropriate implementation in ANGLE. Reported by sweetchip. - CVE-2026-5284: Use after free in Dawn. Reported by 86ac1f1587b71893ed2ad792cd7dde32. - CVE-2026-5285: Use after free in WebGL. Reported by c6eed09fc8b174b0f3eebedcceb1e792. - CVE-2026-5286: Use after free in Dawn. Reported by sweetchip. - CVE-2026-5287: Use after free in PDF. Reported by Syn4pse. - CVE-2026-5288: Use after free in WebView. Reported by Google. - CVE-2026-5289: Use after free in Navigation. Reported by Google. - CVE-2026-5290: Use after free in Compositing. Reported by Google. - CVE-2026-5291: Inappropriate implementation in WebGL. Reported by heapracer (@heapracer). - CVE-2026-5292: Out of bounds read in WebCodecs. Reported by Google. * d/patches: - upstream/Fix-blink-compilation-for-platforms-other-than-x86-and-arm.patch: drop, merged upstream. - ungoogled/disable-ai.patch: resync with u-c. . [ Daniel Richard G. ] * d/copyright: Exclude *.pb (protobuf) binary files. * d/patches: Various ungoogled-chromium-related updates. - disable/glic.patch: Drop, replaced with disable-ai.patch from the ungoogled-chromium project. - ungoogled/disable-ai.patch: Import new patch from ungoogled-chromium that zaps glic, screen_ai, and various other adjacent AI-based features. - ungoogled/disable-mei-preload.patch: Import patch to allow building without *.pb files. - ungoogled/disable-privacy-sandbox.patch: Update imported patch. . [ Timothy Pearson ] * d/patches/ppc64le: - third_party/0005-blink-add-audio-vector-support.patch: Fix FBTFS from upstream adding vector-accelerated audio delay functions . [ Jianfeng Liu ] * d/patches/upstream: - Fix-blink-compilation-for-platforms-other-than-x86-and-arm.patch: Fix FBTFS from upstream for blink audio delay function on loong64 Checksums-Sha1: 67f4161fc63e5a0c5e558c35eec44374f9cf9d98 6000720 chromium-common-dbgsym_146.0.7680.177-1~deb12u1_ppc64el.deb ed1220d7e760b81f69ac72c1b4507de624aa3912 36264340 chromium-common_146.0.7680.177-1~deb12u1_ppc64el.deb cce83ef30442d5fc55ece24c3ec8f902aca98ea5 31644604 chromium-dbgsym_146.0.7680.177-1~deb12u1_ppc64el.deb 52f7be67a2be1e72167436bd4043d72a99fb57a9 7655892 chromium-driver_146.0.7680.177-1~deb12u1_ppc64el.deb 96ce1c416ea65fcf0b7fa12929749b186b89db67 25297788 chromium-headless-shell-dbgsym_146.0.7680.177-1~deb12u1_ppc64el.deb 5523405ecb215028b9d8e99a76e21b3a1aefafac 55518924 chromium-headless-shell_146.0.7680.177-1~deb12u1_ppc64el.deb 5377a03c23806a9b23bdc113a71bbbbc2ab3a6cc 19252 chromium-sandbox-dbgsym_146.0.7680.177-1~deb12u1_ppc64el.deb acc28daddf3dc84ee91b105a1b73d0159ad743cd 114352 chromium-sandbox_146.0.7680.177-1~deb12u1_ppc64el.deb 060a7c56c0e95d551682c3c02d9f4e4b87984275 27393072 chromium-shell-dbgsym_146.0.7680.177-1~deb12u1_ppc64el.deb 5e2de2ab08a0b93a7330b1c5fd989a70e90424d7 60437592 chromium-shell_146.0.7680.177-1~deb12u1_ppc64el.deb 47674717e31cb6579ae6c303d24ec3d745b27f7b 30333 chromium_146.0.7680.177-1~deb12u1_ppc64el-buildd.buildinfo a89c73a3550dcfa5c581381bf87dfec38916cca2 72319252 chromium_146.0.7680.177-1~deb12u1_ppc64el.deb Checksums-Sha256: 79671b14697f47158a8362cdb9fd3f460490769353a4042dd0a97c5188e5b652 6000720 chromium-common-dbgsym_146.0.7680.177-1~deb12u1_ppc64el.deb 23aa6115f622cb6809e065b63be3f2760cd88aa234977e9b3729efd992649ee2 36264340 chromium-common_146.0.7680.177-1~deb12u1_ppc64el.deb b897a542886610d77f38988d01f5ad29f1ca4adeb475370dbf271ae5c197241c 31644604 chromium-dbgsym_146.0.7680.177-1~deb12u1_ppc64el.deb 3fea3cb3b16366fe6c907dfe74a576765bb857b9bb0b449b4d92ffc7e5ad9298 7655892 chromium-driver_146.0.7680.177-1~deb12u1_ppc64el.deb 945f74e1241e391793693f7c5e9824120357e3e52cf4a9118e0b806f3e3dc811 25297788 chromium-headless-shell-dbgsym_146.0.7680.177-1~deb12u1_ppc64el.deb 51363bd6c20de9b79a2fd79d3f7938a1c1a40b5482d627f8702443f4416c73ee 55518924 chromium-headless-shell_146.0.7680.177-1~deb12u1_ppc64el.deb 26908918104fd067aab6c88483516341afa26d96eaf70c823e9a1f6c49763d4c 19252 chromium-sandbox-dbgsym_146.0.7680.177-1~deb12u1_ppc64el.deb 1cb83bd9bf851829f1aa1b381f72d973463bec6fdb108618f40b3cb1c20a65e1 114352 chromium-sandbox_146.0.7680.177-1~deb12u1_ppc64el.deb 4a0e286fcac5ba2eaad2bce4fec32d3bd084ecee91363cbd2071ca897d674672 27393072 chromium-shell-dbgsym_146.0.7680.177-1~deb12u1_ppc64el.deb a349a4a34e0e8cf89274935d15e33f4dd4542f20367415db0b1ef4e94930866e 60437592 chromium-shell_146.0.7680.177-1~deb12u1_ppc64el.deb 4b0284b043f36ba50786092553eafb48393c255e3fbe7c2e137d8167f679105e 30333 chromium_146.0.7680.177-1~deb12u1_ppc64el-buildd.buildinfo 7bb4906b2bd154c701820af7200a8972199848dfd5486db8e72668a8c25c28ec 72319252 chromium_146.0.7680.177-1~deb12u1_ppc64el.deb Files: e924fd1f2f5db77f872db4d763e3156e 6000720 debug optional chromium-common-dbgsym_146.0.7680.177-1~deb12u1_ppc64el.deb 4b3b697b6052bc409a46620eca4cab78 36264340 web optional chromium-common_146.0.7680.177-1~deb12u1_ppc64el.deb 48454b089c07cfe7f813bcd4ea0d01db 31644604 debug optional chromium-dbgsym_146.0.7680.177-1~deb12u1_ppc64el.deb 42da5e35f910a9956eb061c3330b864a 7655892 web optional chromium-driver_146.0.7680.177-1~deb12u1_ppc64el.deb 7e710b405d0c85ceb6912d3e55f644ce 25297788 debug optional chromium-headless-shell-dbgsym_146.0.7680.177-1~deb12u1_ppc64el.deb c24691c0a6286d3aef9c00da5b58b37d 55518924 web optional chromium-headless-shell_146.0.7680.177-1~deb12u1_ppc64el.deb ed247d25f41d2fee3af96bee295008a1 19252 debug optional chromium-sandbox-dbgsym_146.0.7680.177-1~deb12u1_ppc64el.deb 4b1fc6b564695b6ca1d0993264c6d3f8 114352 web optional chromium-sandbox_146.0.7680.177-1~deb12u1_ppc64el.deb 8af63edf14fda8afbc043a038107a730 27393072 debug optional chromium-shell-dbgsym_146.0.7680.177-1~deb12u1_ppc64el.deb 884241a60eb0f8fccf031bd6f099302d 60437592 web optional chromium-shell_146.0.7680.177-1~deb12u1_ppc64el.deb 6ca0271e713d461ab977cb24d9812ff4 30333 web optional chromium_146.0.7680.177-1~deb12u1_ppc64el-buildd.buildinfo 9b448a0351be047d5dd542d74dc537e1 72319252 web optional chromium_146.0.7680.177-1~deb12u1_ppc64el.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEySUEQfg5pZeb/U372FRWNm40e2YFAmnO/zEACgkQ2FRWNm40 e2ZR7A//QYNbly9nF50PSBu3NnC7IzgIM78uyVxvG3oqfV3kJ4O3cHO+ZAJ61STI cSdm0UMp32y7zbvgJ4AE2wBkpRl3RBbEoXaV8dJJkwFLqVlKaqo/GaRAC+uWJRAP DfqnTECTjwC/ntq8LbBZS0+R8oVzMsIro4JllrlspU5wc1v9j6N0IsuDT2B8CNG6 IFkicauMQrlRQSbXxyzgH24CVFkXL3FsgxzBj8q2nH+5aUaB407u0qiqiQDY71fH YSkvEqeO13dfYP+DtwKDJfwhXsoBQPg9ORcn0XJczPM/2P8xl7+m6mraeFbykmaV iFLOS9r7dT+zUKqW7vubK/w0IP9pKcpMBOOSlmy69Susk5ncNxvy4vZ90EBvezbT 3f2xBReFAEcEemDRdBj3gxo7fOCPz9jJIhLc6ztlQA74SpgF6sGd5r5/LXuCNuC7 ZAprUXcQ5NG0899mkxA9mTuEJUmF1ghT10l2Oqcq5TsaiYYjBkOtko0KuMZCJtIB mFafcjKzAhHuYYZ92cgdwkffhcsSL2Oa7qyvK+oJSBX0wUL4eroadLWtlqYdbd50 1XbBZmfqLvT7NS+WvriwYmSZIXdbCUQto7HdX00kAq/7GFTqHS9VpavLpDiWZnB7 Py8zEvSzseWOfKlaxgL0Unt3LFa7GQN0M8aAZZj8hnzFFJt2R+4= =XDpZ -----END PGP SIGNATURE-----