-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 11 Mar 2026 20:01:51 -0400 Source: chromium Binary: chromium-l10n Architecture: all Version: 146.0.7680.71-1~deb12u1 Distribution: bookworm-security Urgency: high Maintainer: all Build Daemon (x86-grnet-02) Changed-By: Andres Salomon Description: chromium-l10n - web browser - language packs Changes: chromium (146.0.7680.71-1~deb12u1) bookworm-security; urgency=high . [ Andres Salomon ] * New upstream stable release. - CVE-2026-3913: Heap buffer overflow in WebML. Reported by Tobias Wienand - CVE-2026-3914: Integer overflow in WebML. Reported by cinzinga. - CVE-2026-3915: Heap buffer overflow in WebML. Reported by Tobias Wienand - CVE-2026-3916: Out of bounds read in Web Speech. Reported by Grischa Hauser. - CVE-2026-3917: Use after free in Agents. Reported by Syn4pse. - CVE-2026-3918: Use after free in WebMCP. Reported by Syn4pse. - CVE-2026-3919: Use after free in Extensions. Reported by Huinian Yang (@vmth6) of Amber Security Lab, OPPO Mobile Telecommunications Corp. Ltd - CVE-2026-3920: Out of bounds memory access in WebML. Reported by Google. - CVE-2026-3921: Use after free in TextEncoding. Reported by Pranamya Keshkamat & Cantina.xyz. - CVE-2026-3922: Use after free in MediaStream. Reported by c6eed09fc8b174b0f3eebedcceb1e792. - CVE-2026-3923: Use after free in WebMIDI. Reported by c6eed09fc8b174b0f3eebedcceb1e792. - CVE-2026-3924: Use after free in WindowDialog. Reported by c6eed09fc8b174b0f3eebedcceb1e792. - CVE-2026-3925: Incorrect security UI in LookalikeChecks. Reported by NDevTK and Alesandro Ortiz. - CVE-2026-3926: Out of bounds read in V8. Reported by qymag1c. - CVE-2026-3927: Incorrect security UI in PictureInPicture. Reported by Barath Stalin K. - CVE-2026-3928: Insufficient policy enforcement in Extensions. Reported by portsniffer443. - CVE-2026-3929: Side-channel information leakage in ResourceTiming. Reported by Povcfe of Tencent Security Xuanwu Lab. - CVE-2026-3930: Unsafe navigation in Navigation. Reported by Povcfe of Tencent Security Xuanwu Lab. - CVE-2026-3931: Heap buffer overflow in Skia. Reported by Huinian Yang (@vmth6) of Amber Security Lab, OPPO Mobile Telecommunications Corp. Ltd - CVE-2026-3932: Insufficient policy enforcement in PDF. Reported by Ayato Shitomi. - CVE-2026-3934: Insufficient policy enforcement in ChromeDriver. Reported by Povcfe of Tencent Security Xuanwu Lab. - CVE-2026-3935: Incorrect security UI in WebAppInstalls. Reported by Barath Stalin K. - CVE-2026-3936: Use after free in WebView. Reported by Am4deu$. - CVE-2026-3937: Incorrect security UI in Downloads. Reported by Abhishek Kumar. - CVE-2026-3938: Insufficient policy enforcement in Clipboard. Reported by vicevirus. - CVE-2026-3939: Insufficient policy enforcement in PDF. Reported by NDevTK - CVE-2026-3940: Insufficient policy enforcement in DevTools. Reported by Jorian Woltjer, Mian, bug_blitzer. - CVE-2026-3941: Insufficient policy enforcement in DevTools. Reported by Lyra Rebane (rebane2001). - CVE-2026-3942: Incorrect security UI in PictureInPicture. Reported by Barath Stalin K. * d/rules: update rustc version string for new upstream expectations of no spaces. * d/patches: - upstream/disable-unrar.patch: drop, merged upstream. - disable/signin.patch: drop part of the patch. This patch should be reviewed in the future and coordinated w/ ungoogled-chromium, since it originally came from them. - disable/glic.patch: add a bunch more glic removals. - disable/license-headless-shell.patch: refresh. - disable/unrar.patch: refresh. - system/rollup.patch: refresh. - bookworm/foreach.patch: refresh. - ungoogled/disable-privacy-sandbox.patch: sync from ungoogled-chromium. - disable/catapult.patch: update to remove some more catapult deps. - fixes/force-rust-nightly.patch: drop, no longer needed. - llvm-22/ignore-for-ubsan.patch: add a build fix for a compiler flag/feature added to llvm-23. - fixes/bytemuck.patch: add rust build fix in bytemuck. - llvm-19/clang-19-crash.patch: add build fix; delete code that makes clang-19++ crash. - llvm-19/keyfactory.patch: add build fix for what I suspect is a clang-19 issue. - loongarch64/0018-fix-study-crash.patch: refresh. - ppc64le/breakpad/0001-Implement-support-for-ppc64-on-Linux.patch: refresh. - ppc64le/fixes/fix-study-crash.patch: refresh. - llvm-19/clone-traits.patch: add patch to remove a static assertion. - llvm-19/octal.patch: add patch to work around 0o666 vs 0666 support. - upstream/profile.patch: add header inclusion build fix from upstream. - trixie/value-or.patch: move to llvm-19/ directory & also add another place that clang-19 gets confused during build. - rust-1.85/jxl-features.patch: refresh [trixie, bookworm]. - rust-1.85/jxl-simd-avx512.patch: update for (numerous) upstream changes, and added unsafe{} blocks to the macro definitions to shrink this patch in the future [trixie, bookworm]. - fixes/missing-dep.patch: add patch for dependency-related build failure that only happens sometimes. . [ Timothy Pearson ] * d/patches/ppc64le: - third_party/0001-Add-PPC64-support-for-boringssl.patch: refresh for upstream changes - third_party/0002-third_party-libvpx-Remove-bad-ppc64-config.patch: refresh for upstream changes . [ Daniel Richard G. ] * d/patches: - disable/lint.patch: New patch to disable CSS/JS linting tools. - bookworm/node18-compat.patch: New patch to fix various compatibility issues with nodejs 18 [bookworm]. - trixie/gn-len.patch: Zap another instance of len() for older GN [trixie, bookworm]. Checksums-Sha1: 8ba8e33dc7d354042b4a8ace46ca629db7beedc5 8702812 chromium-l10n_146.0.7680.71-1~deb12u1_all.deb c9e8637df290fad9694c2b027a2400e237ef20be 26907 chromium_146.0.7680.71-1~deb12u1_all-buildd.buildinfo Checksums-Sha256: 763eed532bdf34a7bdc705d4fd973d1cb2cf7af2a46854d692ad8db203361c1d 8702812 chromium-l10n_146.0.7680.71-1~deb12u1_all.deb 663ed6ba6c5c04b29d3d13fc0443657d3964b234c472304f41a3d7e6e255e455 26907 chromium_146.0.7680.71-1~deb12u1_all-buildd.buildinfo Files: 01806aa0bdeb751cf9a6f6d350745a37 8702812 localization optional chromium-l10n_146.0.7680.71-1~deb12u1_all.deb 7a6eea19401f8b75d74efa1151dd3d92 26907 web optional chromium_146.0.7680.71-1~deb12u1_all-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE81O8NL+3kjBAqEvLmgPNRvTf/zcFAmmyxf0ACgkQmgPNRvTf /zdXyxAAm1+JLYjFFAh336RCTnYbgd3TmeFcXHdZVhOc20Pvadn0zKhNDsmJm9t9 lIRVT2Jx7S9atnncreMyt5FnGeqXfdm3Zl5z1dH7EbcOiTmMeAVHDERSNiMT3Anz kRIUoESo6Fhk0qynLKx/dwB823u2r7VI9h+d7V3grTAmVH+ZV02F5ecW+g7s4n0h 8BwsAMsrEl0AwF0Eb7WEpffHiWscM95s0kkD74Qxyf0jdtnW+/J+5zLmnRLlN2wx z/HmBZCmOUG+L+EmLX9rmqYwmcyUyTHdCKVxt5zIFflR38IoSxL/xkKuqXGcUnlZ fD4vCvK6ULHFYkqdgfd/Vxv2y6w76RbVUD+qRBHep4FEoNH/w4bgDG8uE7SuKtH8 uB2ER0i9W187RG290rRv8IE/4JDmX6jMnu1PwRaPeyraMzdahKRUjckkVhJGM371 PxULbaaloN2DPaiEvEOg3t0K7rNljLKC4rjFx/Iz4jU4EyfspxVjqdXttJHZdT7F bGF0u1um054a/2soHUT2QEmt1tKyAe4KiA4NAkM5fA4nGQcIFBU7WwziLUSG7Zt3 l65nlg33/6+no77JyqYevtUVTzlfXvjvkokLJ5miBVrWDsQiO3DcinTJCj1jwL0B /ttLAehY3TmEe4yAwd/xgnNyPz5fF2+nNiQ6DvoA8zH+YRWi+6w= =W+cU -----END PGP SIGNATURE-----