Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-2219

Опубликовано: 07 мар. 2026
Источник: debian

Описание

It was discovered that dpkg-deb (a component of dpkg, the Debian package management system) does not properly validate the end of the data stream when uncompressing a zstd-compressed .deb archive, which may result in denial of service (infinite loop spinning the CPU).

Пакеты

ПакетСтатусВерсия исправленияРелизТип
dpkgfixed1.23.6package
dpkgfixed1.22.22trixiepackage
dpkgfixed1.21.23bookwormpackage
dpkgnot-affectedbullseyepackage

Примечания

  • Introduced with: https://git.dpkg.org/cgit/dpkg/dpkg.git/commit/?id=2c2f7066bd8c3209762762fa6905fa567b08ca5a (1.21.18)

  • Fixed by: https://git.dpkg.org/cgit/dpkg/dpkg.git/commit/?id=6610297a62c0780dd0e80b0e302ef64fdcc9d313 (1.23.6)

Связанные уязвимости

CVSS3: 7.5
ubuntu
6 месяцев назад

It was discovered that dpkg-deb (a component of dpkg, the Debian package management system) does not properly validate the end of the data stream when uncompressing a zstd-compressed .deb archive, which may result in denial of service (infinite loop spinning the CPU).

CVSS3: 7.5
nvd
6 месяцев назад

It was discovered that dpkg-deb (a component of dpkg, the Debian package management system) does not properly validate the end of the data stream when uncompressing a zstd-compressed .deb archive, which may result in denial of service (infinite loop spinning the CPU).

suse-cvrf
3 месяца назад

Security update for dpkg

CVSS3: 7.5
github
6 месяцев назад

It was discovered that dpkg-deb (a component of dpkg, the Debian package management system) does not properly validate the end of the data stream when uncompressing a zstd-compressed .deb archive, which may result in denial of service (infinite loop spinning the CPU).