Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-2219

Опубликовано: 07 мар. 2026
Источник: debian
EPSS Низкий

Описание

It was discovered that dpkg-deb (a component of dpkg, the Debian package management system) does not properly validate the end of the data stream when uncompressing a zstd-compressed .deb archive, which may result in denial of service (infinite loop spinning the CPU).

Пакеты

ПакетСтатусВерсия исправленияРелизТип
dpkgfixed1.23.6package
dpkgfixed1.22.22trixiepackage
dpkgno-dsabookwormpackage
dpkgnot-affectedbullseyepackage

Примечания

  • Introduced with: https://git.dpkg.org/cgit/dpkg/dpkg.git/commit/?id=2c2f7066bd8c3209762762fa6905fa567b08ca5a (1.21.18)

  • Fixed by: https://git.dpkg.org/cgit/dpkg/dpkg.git/commit/?id=6610297a62c0780dd0e80b0e302ef64fdcc9d313 (1.23.6)

EPSS

Процентиль: 6%
0.00021
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
29 дней назад

It was discovered that dpkg-deb (a component of dpkg, the Debian package management system) does not properly validate the end of the data stream when uncompressing a zstd-compressed .deb archive, which may result in denial of service (infinite loop spinning the CPU).

CVSS3: 7.5
nvd
29 дней назад

It was discovered that dpkg-deb (a component of dpkg, the Debian package management system) does not properly validate the end of the data stream when uncompressing a zstd-compressed .deb archive, which may result in denial of service (infinite loop spinning the CPU).

CVSS3: 7.5
github
29 дней назад

It was discovered that dpkg-deb (a component of dpkg, the Debian package management system) does not properly validate the end of the data stream when uncompressing a zstd-compressed .deb archive, which may result in denial of service (infinite loop spinning the CPU).

EPSS

Процентиль: 6%
0.00021
Низкий