[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

[SECURITY] [DLA 4673-1] dpkg security update



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian LTS Advisory DLA-4673-1                debian-lts@lists.debian.org
https://www.debian.org/lts/security/                     Arnaud Rebillout
July 08, 2026                                 https://wiki.debian.org/LTS
- -------------------------------------------------------------------------

Package        : dpkg
Version        : 1.20.14
CVE ID         : CVE-2025-6297
Debian Bug     : 1061404 1065575 1107971 1108192

A vulnerability have been discovered in dpkg, the Debian package manager
(dpkg is the low-level tool that actually installs or removes packages).

CVE-2025-6297

    It was discovered that dpkg-deb does not properly sanitize directory
    permissions when extracting a control member into a temporary
    directory, which is documented as being a safe operation even on
    untrusted data. This may result in leaving temporary files behind on
    cleanup. Given automated and repeated execution of dpkg-deb commands
    on adversarial .deb packages or with well compressible files, placed
    inside a directory with permissions not allowing removal by a
    non-root user, this can end up in a DoS scenario due to causing disk
    quota exhaustion or disk full conditions.

Additionally, this version includes some minor security fixes that didn't
receive a CVE number, but were reported on the Debian bug tracker, see
the list of Debian bugs above.

For Debian 11 bullseye, this problem has been fixed in version
1.20.14.

We recommend that you upgrade your dpkg packages.

For the detailed security status of dpkg please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/dpkg

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEE0Kl7ndbut+9n4bYs5yXoeRRgAhYFAmpN6YEACgkQ5yXoeRRg
AhZ61w/+NFPRP/nlJmOS81SQ8WfoFAMHmRmQV0fBtddz6SVSe7kwhtR3kAKrTaa3
nWWrGQTxFev0kVutMiOOfInM5UXwC9GtX7Od+yiYbOp0CDVCVR9JtB+coDpkrICD
2iFY1lR8+yZWCHHPKEDXtAvb+AHeIdbzexg+METoWbLJ3fFQwEPIi+25525QfWv5
kwvRGywwBgAixd9QN9zbM6Dmxm4qSN8tGYX5c2WDNFYJR1rngCpF/l4oEnjXH3Ko
1jrp9cH3/igqU9vWDGXdA5pGPehxMQX+342JppHHsowJD/dg1wtM4xV03fExGwtx
RH30BebrJht4DIsBvoX5B7T9BujKOPMejZ2qhgjl451HLuPn+z71SKup2TGak+7d
wYctvUWyCY7odZT6RjuUBILxXfVhYsGQtb0ckKk8u0THc0UbFduYjj1kN20FlMMO
2Pyc0eHtZ6dsM6tar1jAq4IZgW7zmjA2ZlQVG4eFeK/Z39ZNJHTDtJmZ+R+8MdgB
rlqeE8SJ9rcns4tWC7klNEX6RQmOCsu1vJqp1qd1bTDn/Dn9hbqUBoblDhgGdjzH
dMwj05gbtUpIXCN6DdbPcSHzfo8Skk/k4dgCKkYp7niuUcHkjkNGAYngJmWd2gEQ
qpI2n8stu2Nk/8Cakjz61fvBELYEMiDHXQiYBotC+R7gab8iGNc=
=hfJs
-----END PGP SIGNATURE-----


Reply to: