-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Wed, 10 Apr 2024 21:21:05 -0400 Source: chromium Architecture: source Version: 123.0.6312.122-1~deb12u1 Distribution: bookworm-security Urgency: high Maintainer: Debian Chromium Team Changed-By: Andres Salomon Changes: chromium (123.0.6312.122-1~deb12u1) bookworm-security; urgency=high . * New upstream security release. - CVE-2024-3157: Out of bounds write in Compositing. Reported by DarkNavy. - CVE-2024-3516: Heap buffer overflow in ANGLE. Reported by Bao (zx) Pham and Toan (suto) Pham of Qrious Secure. - CVE-2024-3515: Use after free in Dawn. Reported by wgslfuzz. Checksums-Sha1: 9f336ce8840fd7e0ae63a06ba9d866adcc319e14 3742 chromium_123.0.6312.122-1~deb12u1.dsc 1f6fd5536698bea14b6d5749f11a385123ae046c 836565308 chromium_123.0.6312.122.orig.tar.xz 207df4bdf8e35e54ed3fad6f40329ee07eff7892 409588 chromium_123.0.6312.122-1~deb12u1.debian.tar.xz 5598d082f7386112d947e4fa7154554ddd18dfd8 21674 chromium_123.0.6312.122-1~deb12u1_source.buildinfo Checksums-Sha256: 3a128c1e6aeb02bb0fc509d5a545fd4a2b0f6cb6faa291c5dee8194d5c0abc60 3742 chromium_123.0.6312.122-1~deb12u1.dsc fb7b2fb79c74b2dff59ac996f59039c9c52bd048dbcf1678471d271e7b02d87d 836565308 chromium_123.0.6312.122.orig.tar.xz 9ce82f79f26d03d9b040e2c0813be31fb499a1653a40a555e54cf30b7ff4b05d 409588 chromium_123.0.6312.122-1~deb12u1.debian.tar.xz d1b79c16c4d7ee649713c9f58af5e6e1454ea048fd5dc559f652770e6ca3c7a8 21674 chromium_123.0.6312.122-1~deb12u1_source.buildinfo Files: ed62ccaf8a7a866ff23389c3898ad27e 3742 web optional chromium_123.0.6312.122-1~deb12u1.dsc 35be7ca6b97155d3fe8bbb15ecfca767 836565308 web optional chromium_123.0.6312.122.orig.tar.xz 9f55a036c81c593e5b7022b4e32797e2 409588 web optional chromium_123.0.6312.122-1~deb12u1.debian.tar.xz 49ea4385da11de3dcffe890c2848fd7d 21674 web optional chromium_123.0.6312.122-1~deb12u1_source.buildinfo -----BEGIN PGP SIGNATURE----- iQJIBAEBCAAyFiEEUAUk+X1YiTIjs19qZF0CR8NudjcFAmYXiSgUHGRpbGluZ2Vy QGRlYmlhbi5vcmcACgkQZF0CR8NudjeIOQ//Q0DwrQnn2zf4xssH9JIbarE0gGy4 Z5ivVvZ8QDbms2QQT35echhBpmTOih0JJRta2c/9WdPP6Y8Z+Jq4hx9nUiv7bvWn s1IxnBH8+1iTDVI7VfaW0Fhjgy4tZgdSiv20TtXfRCuTfwbIxl0FxsY0Sgdxdr2q 7CyYlj+JLHMulkzKJsl46FNljSKVCiVKslnf3fT3UYwsHe/wLT3K9ToilrsgukPD tSK5yWeBOylA3fvtcX9cuM09ONaDQryp9ja6KMgUeV/2A9yQRCFBbrM8BT/Hg5BI IUT+jxJG77LNECcXvAzpocSzVIUzbOiMhfGNcVi2N34mfQ/rKBjRJf8cPlmiGKaI dGO+u7MfLTT9E5LMcl59TWqHudOfM3sLyczzrGahbFLZhaTk8dkOdsPHxOUTdV3Q jIL0OWx2tqCkKD2tBCF4OXCPxDa+XL+TkN0kWdPtROn/HuXeijcLs1r6KOklliTP TPTGd4n69y5MolXXvYN5q8hKPNuAiKK5zRQXoWiQ05s3zQfcB6RSgF9RxtU8UCor PANG4JCuinJnDFOgm3GGCH77NR6H93zDEBH/uYCItsQvAADRnXv3Nnl69htQ9M7n psaUT1p06blwg0Qafvt6f3U2uQN5EeFutFEC4jMnROEly+Cz2MZCKyvsZmSDqhO6 yst3p2uNcTMclpg= =1mUv -----END PGP SIGNATURE-----