It was discovered that dpkg-deb (a component of dpkg, the Debian package management system) does not properly validate the end of the data stream when uncompressing a zstd-compressed .deb archive, which may result in denial of service (infinite loop spinning the CPU).
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sat, 07 Mar 2026 08:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | It was discovered that dpkg-deb (a component of dpkg, the Debian package management system) does not properly validate the end of the data stream when uncompressing a zstd-compressed .deb archive, which may result in denial of service (infinite loop spinning the CPU). | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: debian
Published:
Updated: 2026-03-07T08:17:33.342Z
Reserved: 2026-02-08T15:48:51.824Z
Link: CVE-2026-2219
No data.
Status : Received
Published: 2026-03-07T09:16:07.823
Modified: 2026-03-07T09:16:07.823
Link: CVE-2026-2219
No data.
OpenCVE Enrichment
No data.
Weaknesses
No weakness.