-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Thu, 19 Feb 2026 20:50:42 -0500 Source: chromium Architecture: source Version: 145.0.7632.109-1~deb13u3 Distribution: trixie-security Urgency: high Maintainer: Debian Chromium Team Changed-By: Andres Salomon Changes: chromium (145.0.7632.109-1~deb13u3) trixie-security; urgency=high . * d/rules: drop CVE check for security-uploads (no functional change). . chromium (145.0.7632.109-1~deb13u2) trixie-security; urgency=high . * d/patches/rust-1.85/jxl-simd-avx512.patch: try again; rustc didn't like where I marked some of the neon functions as unsafe. . chromium (145.0.7632.109-1~deb13u1) trixie-security; urgency=high . * New upstream security release. - CVE-2026-2648: Heap buffer overflow in PDFium. Reported by soiax. - CVE-2026-2649: Integer overflow in V8. Reported by JunYoung Park(@candymate) of KAIST Hacking Lab. - CVE-2026-2650: Heap buffer overflow in Media. Reported by Google. * d/patches/rust-1.85/jxl-simd-avx512.patch: mark neon functions as unsafe to fix arm64 builds. Checksums-Sha1: fbbba5138ac5d86bc626b2bfbe8ead981f7caecf 4113 chromium_145.0.7632.109-1~deb13u3.dsc b7c1bcdf6d22e706d98e959c9de58f985c2156b0 747261032 chromium_145.0.7632.109.orig.tar.xz f1d985a966ac578faf7cddbbeda9bdd5dfa66e3a 455024 chromium_145.0.7632.109-1~deb13u3.debian.tar.xz e48a0aa1f1af96dd8dd165a6d03ab0cc0ebdbd57 26893 chromium_145.0.7632.109-1~deb13u3_source.buildinfo Checksums-Sha256: def9538bf4fc04ffb15a91c71571ee82247b67cb7a50132774a7bd221e073a38 4113 chromium_145.0.7632.109-1~deb13u3.dsc 8c54868014ccf325a27017f8a6c8ae73c8ca0ca3016e444c6ad28d3f8225f529 747261032 chromium_145.0.7632.109.orig.tar.xz ee57b18c0974e85c53c3cdd0118e1f5535be135345b018abcdc88aed88bf10f9 455024 chromium_145.0.7632.109-1~deb13u3.debian.tar.xz dd94434906e15c4b49cb2ac55da3df7b05c5380c2580d2caed66c17af65cdbb2 26893 chromium_145.0.7632.109-1~deb13u3_source.buildinfo Files: 0d6ec972bc1ef52a690829d38d78b520 4113 web optional chromium_145.0.7632.109-1~deb13u3.dsc 6306af0f29c52a538845bc0a7861da2f 747261032 web optional chromium_145.0.7632.109.orig.tar.xz a291915f09c96c953823642ef002783b 455024 web optional chromium_145.0.7632.109-1~deb13u3.debian.tar.xz 3997b0ee64cb718c87e514bdbfc48a23 26893 web optional chromium_145.0.7632.109-1~deb13u3_source.buildinfo -----BEGIN PGP SIGNATURE----- iQJIBAEBCAAyFiEEUAUk+X1YiTIjs19qZF0CR8NudjcFAmmXv3cUHGRpbGluZ2Vy QGRlYmlhbi5vcmcACgkQZF0CR8Nudjc9AA//Xicg+fO0QjaWLZbtJuUrJvmAj+LI 4QjbMnrVz0dtj2/d/I8ULlI1NIxYDdPJ3L+k4hYXlPK7vw0kocWchHEHEsmf0kJh 3zxeiPzhjAcx97GrZLu5KWp1AcezEzqm/z2i7jGrO94QS4wZne5BdrHHqx/eTIhr LWI+9BY70Cvweb44q3ero3zLLhcJSKOcKctNm8LG+hnxtXDCxNu9XDFeMo3zJZGN M5MpLIGnP6qr5BoRgPvhM4pZX0LemTfXB4ZWRoz4sVmsxYLVBI+tf97HNrZ8gZO9 E/TnXhswZvxk4oKat2nTe3pqsjkS6Gm2kVzMS5YpuZ4WpzGKyH/Bpb1RnfEA4LKL yl8flP+b7Y5eDQL0WDZcLnZACZtyHaQpGEDXQYqjZV8i4lSK+N8rPqyVgmDbaV5Z 2QoCjS8XoB8Y13nlL6CejePw70EwOp+1MBfgXCs/7ut+7bWyA5iMAWeDXLQgRHzs KLJkKIo/HVvX7Phlx3fi8aXuX2laiI+PvsK1xOifsBJ8Pnlw57ppuyq0HRD+wF3b 69yoQvNWnRKt223+x38/mF5OlF5FIsDJfcSTC5fFJLDUI9e4ZLXZWUY9vQ6oNK+A iBTCpLhX/Rx4RM70v6iJAArsS+QastB5YCJuv4Ep7sAP9l14uJv2hBhvvWIX7IWq 9DrPSzn8F8zwgnc= =6/NW -----END PGP SIGNATURE-----