-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Thu, 19 Feb 2026 21:06:50 -0500 Source: chromium Architecture: source Version: 145.0.7632.109-1~deb12u3 Distribution: bookworm-security Urgency: high Maintainer: Debian Chromium Team Changed-By: Andres Salomon Changes: chromium (145.0.7632.109-1~deb12u3) bookworm-security; urgency=high . * d/rules: drop CVE check for security-uploads (no functional change). . chromium (145.0.7632.109-1~deb12u2) bookworm-security; urgency=high . * d/patches/rust-1.85/jxl-simd-avx512.patch: try again; rustc didn't like where I marked some of the neon functions as unsafe. . chromium (145.0.7632.109-1~deb12u1) bookworm-security; urgency=high . * New upstream security release. - CVE-2026-2648: Heap buffer overflow in PDFium. Reported by soiax. - CVE-2026-2649: Integer overflow in V8. Reported by JunYoung Park(@candymate) of KAIST Hacking Lab. - CVE-2026-2650: Heap buffer overflow in Media. Reported by Google. * d/patches/rust-1.85/jxl-simd-avx512.patch: mark neon functions as unsafe to fix arm64 builds. Checksums-Sha1: c4400ed85d1e7d570b851346112e8d5cb0974346 4082 chromium_145.0.7632.109-1~deb12u3.dsc b7c1bcdf6d22e706d98e959c9de58f985c2156b0 747261032 chromium_145.0.7632.109.orig.tar.xz 25c457068c30beacfc4f7a3755cf35109feb90c8 8544236 chromium_145.0.7632.109-1~deb12u3.debian.tar.xz d6ae62e4cdcc04ee507eed2d9cd870bf4e11f43c 26954 chromium_145.0.7632.109-1~deb12u3_source.buildinfo Checksums-Sha256: 0acb8b950921d2038799d3738da47a81eed9192396224aa5d8b7080fd6e13f8c 4082 chromium_145.0.7632.109-1~deb12u3.dsc 8c54868014ccf325a27017f8a6c8ae73c8ca0ca3016e444c6ad28d3f8225f529 747261032 chromium_145.0.7632.109.orig.tar.xz fd62257c76a2c372c5b44f3013c112083db191fdb50732d0ee7f8da2f20acff7 8544236 chromium_145.0.7632.109-1~deb12u3.debian.tar.xz ba37c1f98df1601adae2c5bc4670d85391825184048517294471a992d6fd7b16 26954 chromium_145.0.7632.109-1~deb12u3_source.buildinfo Files: b09d84a2f200457250d341ea08c20ad0 4082 web optional chromium_145.0.7632.109-1~deb12u3.dsc 6306af0f29c52a538845bc0a7861da2f 747261032 web optional chromium_145.0.7632.109.orig.tar.xz b15cea88202b106c2036a3e8559cb799 8544236 web optional chromium_145.0.7632.109-1~deb12u3.debian.tar.xz d45e04ab293273150dafde6809ab7f10 26954 web optional chromium_145.0.7632.109-1~deb12u3_source.buildinfo -----BEGIN PGP SIGNATURE----- iQJIBAEBCAAyFiEEUAUk+X1YiTIjs19qZF0CR8NudjcFAmmXx6cUHGRpbGluZ2Vy QGRlYmlhbi5vcmcACgkQZF0CR8Nudjc42xAAtsmYREg8n+9QVim37y5CMIW+E6Ro C745EOgxp939REsv1YfLz0xkesC5ohlsd60ai/KNkHM5UOIG4AGw/ewzkKFltHIY gDbX+fFoi/9X/qmj+VV3i7kHz+spEvRtBXWUYT7+j11SjImO9b27OttNEsx9361t 8Kk2QbqP5kSGpTZNfL213uIRzm0oSlbF1ODx3PmzahQ1gCm+6CifR1dtwER+2bZ1 kr+IB/TL2RJsvdz8z0VjqmhMr482pxRBZkIv9t4Y7OfSlPFEf7RFi8uyU/U8n5TH otxf/+lfalx54TdYNAgi1J/vPtNQ+urbKJb/1lWR6KcyqzpNGABDfGtUEn6cNal6 r+87JCLdFJ7KZ4OBQnkMvpXzaxOG0oPybAiw28WWiZA/xKISHUa3fTsAdTXYv7w8 lukLgIgDVc5IPkYs2UqtrC9bp7zzGE9eUfnvvTrUIBBWEL6ScxiN0TBNTsdRRbPU b3rfimDDgqcrWOiesjQ6OYo0LwHKG07dCBMEdut2PsfO6rh2B35Qw0MmBZeAqB2u mcXi2kgk1AmFzF8wJcNra3yi75G5WO04iqfOLf54y49BY8aAHrfqaHzPKg0+o3n5 oIB5c9t0yPrNjsPHF9lzYG04IssaLe72Eb5YS8pv2gP75joK8iXUEGvcAolBo1d4 6BAXdQcq5NXH9SA= =5mbF -----END PGP SIGNATURE-----