Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
A vulnerability have been discovered in dpkg, the Debian package manager (dpkg is the low-level tool that actually installs or removes packages). CVE-2025-6297 It was discovered that dpkg-deb does not properly sanitize directory permissions when extracting a control member into a temporary. Debian LTS Advisory DLA-4673-1
An update that solves one vulnerability can now be installed.. # Security update for dpkg Announcement ID: SUSE-SU-2026:22085-1 Release Date: 2026-06-05T13:47:06Z Rating: moderate References: * bsc#1259385 Cross-References: * CVE-2026-2219 CVSS scores: * CVE-2026-2219 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-2219 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-2219 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for dpkg fixes the following issue: * CVE-2026-2219: dpkg-deb: malformed .deb archives can cause a denial of service (bsc#1259385). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-894=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-894=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * dpkg-debugsource-1.22.21-160000.3.1 * update-alternatives-debuginfo-1.22.21-160000.3.1 * update-alternatives-1.22.21-160000.3.1 * dpkg-debuginfo-1.22.21-160000.3.1 * dpkg-devel-1.22.21-160000.3.1 * update-alternatives-debugsource-1.22.21-160000.3.1 * dpkg-1.22.21-160000.3.1 * SUSE Linux Enterprise Server 16.0 (noarch) * dpkg-lang-1.22.21-160000.3.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * dpkg-debugsource-1.22.21-160000.3.1 * update-alternatives-debuginfo-1.22.21-160000.3.1 * update-alternatives-1.22.21-160000.3.1 * dpkg-debuginfo-1.22.21-160000.3.1 *dpkg-devel-1.22.21-160000.3.1 * update-alternatives-debugsource-1.22.21-160000.3.1 * dpkg-1.22.21-160000.3.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * dpkg-lang-1.22.21-160000.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-2219.html * https://bugzilla.suse.com/show_bug.cgi?id=1259385 . Security update for dpkg in SUSE addresses moderate vulnerability causing denial of service. Installation recommendations provided.. SUSE Linux, dpkg security, update management, security patch, Linux vulnerabilities. . Severity: moderate. LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # Security update for dpkg Announcement ID: SUSE-SU-2026:22046-1 Release Date: 2026-06-05T13:44:58Z Rating: moderate References: * bsc#1259385 Cross-References: * CVE-2026-2219 CVSS scores: * CVE-2026-2219 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-2219 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-2219 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves one vulnerability can now be installed. ## Description: This update for dpkg fixes the following issue: * CVE-2026-2219: dpkg-deb: malformed .deb archives can cause a denial of service (bsc#1259385). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-894=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * update-alternatives-debugsource-1.22.21-160000.3.1 * update-alternatives-1.22.21-160000.3.1 * update-alternatives-debuginfo-1.22.21-160000.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-2219.html * https://bugzilla.suse.com/show_bug.cgi?id=1259385 . A security update for SUSE Linux Micro 6.2 addressing moderate issues in dpkg to prevent denial of service attacks.. SUSE Linux Micro 6.2, dpkg update, moderate security fix. . Severity: moderate. LinuxSecurity.com Team
An update that solves one vulnerability and has one bug fix can now be installed.. openSUSE security update: security update for dpkg ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:20909-1 Rating: moderate References: * bsc#1259385 Cross-References: * CVE-2026-2219 CVSS scores: * CVE-2026-2219 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-2219 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves one vulnerability and has one bug fix can now be installed. Description: This update for dpkg fixes the following issue: - CVE-2026-2219: dpkg-deb: malformed .deb archives can cause a denial of service (bsc#1259385). Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-894=1 Package List: - openSUSE Leap 16.0: dpkg-1.22.21-160000.3.1 dpkg-devel-1.22.21-160000.3.1 dpkg-lang-1.22.21-160000.3.1 update-alternatives-1.22.21-160000.3.1 References: * https://www.suse.com/security/cve/CVE-2026-2219.html . Install openSUSE's latest security update for dpkg addressing a moderate issue and improving system stability. . openSUSE security, dpkg update, denial of service, moderate security fix. . Severity: moderate. LinuxSecurity.com Team
An update that solves one vulnerability and has one bug fix can now be installed.. openSUSE security update: security update for dpkg ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:20909-1 Rating: moderate References: * bsc#1259385 Cross-References: * CVE-2026-2219 CVSS scores: * CVE-2026-2219 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-2219 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves one vulnerability and has one bug fix can now be installed. Description: This update for dpkg fixes the following issue: - CVE-2026-2219: dpkg-deb: malformed .deb archives can cause a denial of service (bsc#1259385). Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-894=1 Package List: - openSUSE Leap 16.0: dpkg-1.22.21-160000.3.1 dpkg-devel-1.22.21-160000.3.1 dpkg-lang-1.22.21-160000.3.1 update-alternatives-1.22.21-160000.3.1 References: * https://www.suse.com/security/cve/CVE-2026-2219.html . This update for openSUSE resolves moderate issues with dpkg, addressing CVE-2026-2219 and improving system stability.. openSUSE patches, dpkg security update, CVE-2026-2219, Linux vulnerabilities, security fixes. . Severity: moderate. LinuxSecurity.com Team
MGASA-2026-0144 - Updated dpkg packages fix security vulnerabilities. MGASA-2026-0144 - Updated dpkg packages fix security vulnerabilities Publication date: 16 May 2026 URL: https://advisories.mageia.org/MGASA-2026-0144.html Type: security Affected Mageia releases: 9 CVE: CVE-2026-2219 Description: It was discovered that dpkg-deb (a component of dpkg, the Debian package management system) does not properly validate the end of the data stream when uncompressing a zstd-compressed .deb archive, which may result in denial of service (infinite loop spinning the CPU). References: - https://bugs.mageia.org/show_bug.cgi?id=35489 - https://lists.opensuse.org/archives/list/
dpkg could be made to stop responding if it opened a specially crafted file.. ========================================================================== Ubuntu Security Notice USN-8249-1 May 07, 2026 dpkg vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 25.10 - Ubuntu 24.04 LTS Summary: dpkg could be made to stop responding if it opened a specially crafted file. Software Description: - dpkg: Debian package management system Details: Yashashree Gund discovered that the dpkg dpkg-deb tool incorrectly handled certain zstd-compressed .deb archives. If a user or automated system were tricked into manipulating a specially crafted .deb archive, a remote attacker could possibly use this issue to cause dpkg-deb to stop responding, resulting in a denial of service. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 25.10 dpkg 1.22.21ubuntu3.2 Ubuntu 24.04 LTS dpkg 1.22.6ubuntu6.6 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8249-1 CVE-2026-2219 Package Information: https://launchpad.net/ubuntu/+source/dpkg/1.22.21ubuntu3.2 https://launchpad.net/ubuntu/+source/dpkg/1.22.6ubuntu6.6 . dpkg exposes Ubuntu to DoS risks through specially crafted files. Update to mitigate this issue.. dpkg vulnerability, Ubuntu security, system update, denial of service, security patch. . Severity: Important. LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # dpkg-1.22.22-1.1 on GA media Announcement ID: openSUSE-SU-2026:10675-1 Rating: moderate Cross-References: * CVE-2026-2219 CVSS scores: * CVE-2026-2219 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-2219 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N Affected Products: * openSUSE Tumbleweed An update that solves one vulnerability can now be installed. ## Description: These are all security issues fixed in the dpkg-1.22.22-1.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * dpkg 1.22.22-1.1 * dpkg-devel 1.22.22-1.1 * dpkg-lang 1.22.22-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-2219.html . An update for openSUSE Tumbleweed dpkg addresses a moderate security risk. Learn more about the details and installation.. openSUSE updates, dpkg security, moderate threat assessment, Linux package management, software vulnerabilities. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.