Debian alert DLA-4673-1 (dpkg)
| From: | Arnaud Rebillout <arnaudr@debian.org> | |
| To: | debian-lts-announce@lists.debian.org | |
| Subject: | [SECURITY] [DLA 4673-1] dpkg security update | |
| Date: | Wed, 08 Jul 2026 13:09:10 +0700 | |
| Message-ID: | <63297cc423008068900be4b87ee5854e@debian.org> |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian LTS Advisory DLA-4673-1 debian-lts@lists.debian.org https://www.debian.org/lts/security/ Arnaud Rebillout July 08, 2026 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : dpkg Version : 1.20.14 CVE ID : CVE-2025-6297 Debian Bug : 1061404 1065575 1107971 1108192 A vulnerability have been discovered in dpkg, the Debian package manager (dpkg is the low-level tool that actually installs or removes packages). CVE-2025-6297 It was discovered that dpkg-deb does not properly sanitize directory permissions when extracting a control member into a temporary directory, which is documented as being a safe operation even on untrusted data. This may result in leaving temporary files behind on cleanup. Given automated and repeated execution of dpkg-deb commands on adversarial .deb packages or with well compressible files, placed inside a directory with permissions not allowing removal by a non-root user, this can end up in a DoS scenario due to causing disk quota exhaustion or disk full conditions. Additionally, this version includes some minor security fixes that didn't receive a CVE number, but were reported on the Debian bug tracker, see the list of Debian bugs above. For Debian 11 bullseye, this problem has been fixed in version 1.20.14. We recommend that you upgrade your dpkg packages. For the detailed security status of dpkg please refer to its security tracker page at: https://security-tracker.debian.org/tracker/dpkg Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE0Kl7ndbut+9n4bYs5yXoeRRgAhYFAmpN6YEACgkQ5yXoeRRg AhZ61w/+NFPRP/nlJmOS81SQ8WfoFAMHmRmQV0fBtddz6SVSe7kwhtR3kAKrTaa3 nWWrGQTxFev0kVutMiOOfInM5UXwC9GtX7Od+yiYbOp0CDVCVR9JtB+coDpkrICD 2iFY1lR8+yZWCHHPKEDXtAvb+AHeIdbzexg+METoWbLJ3fFQwEPIi+25525QfWv5 kwvRGywwBgAixd9QN9zbM6Dmxm4qSN8tGYX5c2WDNFYJR1rngCpF/l4oEnjXH3Ko 1jrp9cH3/igqU9vWDGXdA5pGPehxMQX+342JppHHsowJD/dg1wtM4xV03fExGwtx RH30BebrJht4DIsBvoX5B7T9BujKOPMejZ2qhgjl451HLuPn+z71SKup2TGak+7d wYctvUWyCY7odZT6RjuUBILxXfVhYsGQtb0ckKk8u0THc0UbFduYjj1kN20FlMMO 2Pyc0eHtZ6dsM6tar1jAq4IZgW7zmjA2ZlQVG4eFeK/Z39ZNJHTDtJmZ+R+8MdgB rlqeE8SJ9rcns4tWC7klNEX6RQmOCsu1vJqp1qd1bTDn/Dn9hbqUBoblDhgGdjzH dMwj05gbtUpIXCN6DdbPcSHzfo8Skk/k4dgCKkYp7niuUcHkjkNGAYngJmWd2gEQ qpI2n8stu2Nk/8Cakjz61fvBELYEMiDHXQiYBotC+R7gab8iGNc= =hfJs -----END PGP SIGNATURE-----
