Accepted chromium 151.0.7922.108-1 (source) into unstable

Debian FTP Masters <[email protected]>
Newsgroups gmane.linux.debian.devel.changes.unstable
Message-ID <[email protected]>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Format: 1.8
Date: Fri, 07 Aug 2026 12:19:50 -0400
Source: chromium
Architecture: source
Version: 151.0.7922.108-1
Distribution: unstable
Urgency: high
Maintainer: Debian Chromium Team <[email protected]>
Changed-By: Andres Salomon <[email protected]>
Changes:
 chromium (151.0.7922.108-1) unstable; urgency=high
 .
   [ Daniel Richard G. ]
   * d/deb_pre_gen.py: Minor fixes to the pre-gen framework:
     - Always record target outputs in an .OUTPUTS file, even if a target has
       only a single output. This incurs only a small (tarball) size penalty,
       and catches cases where there is disagreement on which is the first
       output file of a .ninja target.
     - Update the handling logic for generate_css_js_files.js, as the first
       output file of the .ninja target changed from v150.
     - Add an extra check to ensure that target outputs are unique.
   * d/patches/debianization/pre-gen.patch: Tweak a script so that it outputs
     a constant UUID, instead of one dependent on the build path.
   * d/patches/system/golang.patch: Prevent the Go compiler from writing
     things into our home dir, or accessing the network.
   * d/scripts/init-pre-gen.sh: Don't hard-code the package name, as we might
     be doing init-pre-gen for ungoogled-chromium.
 .
   [ Andres Salomon ]
   * New upstream security release.
     - CVE-2026-19137: Use after free in WebGL. Reported by anonymous.
     - CVE-2026-19149: Use after free in Aura. Reported by Google.
     - CVE-2026-19154: Use after free in Skia. Reported by Google.
     - CVE-2026-19157: Out of bounds write in ANGLE. Reported by Google.
     - CVE-2026-19170: Use after free in WebGL. Reported by Muhammad Alifa
       Ramdhan, Pan ZhenPeng, Billy Jheng Bing Jhong of STAR Labs SG Pte. Ltd.
     - CVE-2026-19172: Use after free in Views. Reported by Google.
     - CVE-2026-19169: Insufficient validation of untrusted input in
       Contextual Tasks. Reported by Sven Dysthe (@svn-dys).
     - CVE-2026-19168: Inappropriate implementation in V8.
       Reported by XBOW and triaged by Andrés Luksenberg.
     - CVE-2026-19138: Heap buffer overflow in CrashReporting.
       Reported by Google.
     - CVE-2026-19139: Race in CredentialProvider. Reported by Google.
     - CVE-2026-19140: Use after free in GPU. Reported by Google.
     - CVE-2026-19141: Use after free in Resources. Reported by Google.
     - CVE-2026-19142: Use after free in Views. Reported by Google.
     - CVE-2026-19143: Insufficient validation of untrusted input in
       WebAPKs. Reported by Google.
     - CVE-2026-19144: Use after free in HTML. Reported by Google.
     - CVE-2026-19145: Use after free in Translate. Reported by Google.
     - CVE-2026-19146: Uninitialized Use in GPU. Reported by Google.
     - CVE-2026-19147: Use after free in Aura. Reported by Google.
     - CVE-2026-19148: Out of bounds write in GPU. Reported by Google.
     - CVE-2026-19150: Inappropriate implementation in V8. Reported by Google.
     - CVE-2026-19151: Use after free in V8. Reported by Google.
     - CVE-2026-19152: Inappropriate implementation in Navigation.
       Reported by Google.
     - CVE-2026-19153: Insufficient validation of untrusted input in Workers.
       Reported by Google.
     - CVE-2026-19155: Use after free in Payments. Reported by Google.
     - CVE-2026-19156: Heap buffer overflow in Base.
       Reported by Viktoria Zlatinova.
     - CVE-2026-19158: Use after free in Views. Reported by Google.
     - CVE-2026-19159: Use after free in Views. Reported by Google.
     - CVE-2026-19160: Uninitialized Use in Skia. Reported by Google.
     - CVE-2026-19161: Uninitialized Use in Skia. Reported by Google.
     - CVE-2026-19162: Out of bounds write in V8.
       Reported by OpenAI Codex Security (amyb).
     - CVE-2026-19163: Use after free in Media. Reported by Google.
     - CVE-2026-19164: Insufficient validation of untrusted input in Codecs.
       Reported by Google.
     - CVE-2026-19165: Use after free in Extensions. Reported by @bean5oup.
     - CVE-2026-19166: Use after free in Web Authentication.
       Reported by heesun.
     - CVE-2026-19167: Integer overflow in GPU. Reported by Google.
     - CVE-2026-19171: Use after free in Media. Reported by Google.
     - CVE-2026-19173: Out of bounds write in Skia.
       Reported by Vu Van Tien (@n0_Be3r).
     - CVE-2026-19174: Integer overflow in V8.
       Reported by Seunghyun Lee (@0x10n) of QED Audit (qedaudit.io).
     - CVE-2026-19175: Use after free in Payments. Reported by Google.
     - CVE-2026-19176: Use after free in Skia.
       Reported by WinD39 - Huynh Dinh Vu.
     - CVE-2026-19177: Insufficient validation of untrusted input in UI.
       Reported by Fabian Wahle (Hap Security).
Checksums-Sha1:
 9d1f4d05354b63d90b44370c5f7c729ab0859a99 4388 chromium_151.0.7922.108-1.dsc
 5db7fe8f89a8fa3ff494e0286ff5f91358ab6ad5 15073392 chromium_151.0.7922.108.orig-pre-gen.tar.xz
 9f6610225455ca29c87964dc04ad23e16873b605 949043204 chromium_151.0.7922.108.orig.tar.xz
 af8e958c557ba45e5b116d51817f887b8016a9a6 549256 chromium_151.0.7922.108-1.debian.tar.xz
 d75f338c1854b13896d0586b7f9369f7593afca6 28276 chromium_151.0.7922.108-1_source.buildinfo
Checksums-Sha256:
 49e5099a0b874f14234f52f271c551780b91760061dac5ab75868ebf57c9af20 4388 chromium_151.0.7922.108-1.dsc
 ec5cdca5594aadeeb7076fa27712278037b0ba6f00d5a8ae86602ed573bacba2 15073392 chromium_151.0.7922.108.orig-pre-gen.tar.xz
 90e46be09cf71d1d426e6c8266657d85bf75faf958c2ac6d8d31786430ee3762 949043204 chromium_151.0.7922.108.orig.tar.xz
 3cffbec2d0279cf597d766c6b5a217ece0d8b9161e97c9e30f8bd9eff8fd0981 549256 chromium_151.0.7922.108-1.debian.tar.xz
 591564c0a45dccf1e2ced0b4c1327bdbb73e948280d092e89d431bd78033955a 28276 chromium_151.0.7922.108-1_source.buildinfo
Files:
 7fa39ee391407bd52b6d00e5efcc9f6b 4388 web optional chromium_151.0.7922.108-1.dsc
 8f3589d01d63ade127070eb61257aea5 15073392 web optional chromium_151.0.7922.108.orig-pre-gen.tar.xz
 dd30a91d4d7d2e2a7dcd4d3b86e44ec4 949043204 web optional chromium_151.0.7922.108.orig.tar.xz
 481bfb1f0a9f04039847549dcb7a632f 549256 web optional chromium_151.0.7922.108-1.debian.tar.xz
 86c3d05f8ded8882dea4cd2a6a63dc3c 28276 web optional chromium_151.0.7922.108-1_source.buildinfo

-----BEGIN PGP SIGNATURE-----

iQJIBAEBCAAyFiEEUAUk+X1YiTIjs19qZF0CR8NudjcFAmp2ncoUHGRpbGluZ2Vy
QGRlYmlhbi5vcmcACgkQZF0CR8NudjdFXg/9GmPFb5U5n5K5piDBd1jHO0/wzX5o
ZYmGmDSCT6cVaSbjRmO6zjuQ3aMOTO4cGi3IDaOrCGFFHUiKKoBtWXuB4tVk3b3K
zqPnh6KMSkAbgs7L/04dm+Bow2AWIVjMoAoA5LS6HlveQwewc6uKRpmMyIkbCkvM
C0nX2/LgUL2Fwoq9nUcZhCSnjdjBf9U/e0pRnD8udYGI8w0kzTQd8LSuxjhYd75F
b465J7KTlSq+NXfg6Teh+Sg3gahaFDrWFnxTOcr6HBkAuBF428hNIe1321nac144
GVRIqtWn0fL6dSyslwHLaraUmiBaVtdWhL6vbLSPMm4lRxPteVxYx5YN8SpKDSDl
CaisyLCiWKkv3ivdJeqT4JEV1Vmrqyo4xrfFjFSjqxXunSft4srA6lfADpvWuWyp
e07/nyRD7VsQHRuvWcSNmygFFlpSAJr9I1TjDwo1CHbDaH8p7VmjgfaNxNXCVJWD
mBS0wILJSeWIUqrjBInd68ZR9K/O6njTuIbfIbdVCrrPZYskbKJT/d0wXMDHL/ny
6MKsJOsxY6TBZESPc7Npb5dIqj6ldD25HqUmCSdVBTjZuZeGhw3rS4n/mdcc6WdO
AX9rqGQQjFM9PKJSPEG6lBchZCLmECd2/I9yZAb0BZ6BwMG8Mfh0QgXCZ7k0B/73
zNYFcUttppRvun8=
=2VlT
-----END PGP SIGNATURE-----
signature.asc (application/pgp-signature, 228 B)
-----BEGIN PGP SIGNATURE-----

iHUEABYIAB0WIQTziqJOuF8J+ZI8pJSb9qggYcy5IQUCanarPAAKCRCb9qggYcy5
Iei9AP9Y3OSrKzovBwfEkHvcOxV6+cvBt5ZYyAoIvfgF6JvNGgD8Df/7NmTegnA2
AJPKF2HhS8+V6Bli2OzDjV/oYPpUQwU=
=lZYx
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.