dpkg could be made to stop responding if it opened a specially crafted
file.
Software Description:
- dpkg: Debian package management system
Details:
Yashashree Gund discovered that the dpkg dpkg-deb tool incorrectly handled
certain zstd-compressed .deb archives. If a user or automated system were
tricked into manipulating a specially crafted .deb archive, a remote
attacker could possibly use this issue to cause dpkg-deb to stop
responding, resulting in a denial of service.
The problem can be corrected by updating your system to the following package versions: Ubuntu 25.10 dpkg 1.22.21ubuntu3.2 Ubuntu 24.04 LTS dpkg 1.22.6ubuntu6.6 In general, a standard system update will make all the necessary changes.
https://ubuntu.com/security/notices/USN-8249-1
CVE-2026-2219
Get the latest Linux and open source security news straight to your inbox.