← Back

CVE-2026-2219

nvd nist
Published: Mar 7, 2026Modified: Jun 17, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

It was discovered that dpkg-deb (a component of dpkg, the Debian package management system) does not properly validate the end of the data stream when uncompressing a zstd-compressed .deb archive, which may result in denial of service (infinite loop spinning the CPU).

Affected (3)

Products: Debian: Dpkg
1 product
Dpkg
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Debian
From 1.21.18 to 1.21.23
From 1.22.0 to 1.22.22
From 1.23.0 to 1.23.6

References (2)

Source: security@debian.org
Issue TrackingMailing List

Timeline

No history available yet.