CVE-2026-2219

It was discovered that dpkg-deb (a component of dpkg, the Debian package management system) does not properly validate the end of the data stream when uncompressing a zstd-compressed .deb archive, which may result in denial of service (infinite loop spinning the CPU).
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:debian:dpkg:*:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:*:*:*:*:*:*:*:*
cpe:2.3:a:debian:dpkg:*:*:*:*:*:*:*:*

History

02 Jun 2026, 19:12

Type Values Removed Values Added
References () https://bugs.debian.org/1129722 - () https://bugs.debian.org/1129722 - Issue Tracking, Mailing List
References () https://git.dpkg.org/cgit/dpkg/dpkg.git/commit/?id=6610297a62c0780dd0e80b0e302ef64fdcc9d313 - () https://git.dpkg.org/cgit/dpkg/dpkg.git/commit/?id=6610297a62c0780dd0e80b0e302ef64fdcc9d313 - Patch
First Time Debian
Debian dpkg
CPE cpe:2.3:a:debian:dpkg:*:*:*:*:*:*:*:*
Summary
  • (es) Se descubrió que dpkg-deb (un componente de dpkg, el sistema de gestión de paquetes de Debian) no valida correctamente el final del flujo de datos al descomprimir un archivo .deb comprimido con zstd, lo que puede resultar en denegación de servicio (bucle infinito que consume la CPU).

09 Mar 2026, 15:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
CWE CWE-835

07 Mar 2026, 10:16

Type Values Removed Values Added
References
  • () https://bugs.debian.org/1129722 -

07 Mar 2026, 09:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-07 09:16

Updated : 2026-06-02 19:12


NVD link : CVE-2026-2219

Mitre link : CVE-2026-2219

CVE.ORG link : CVE-2026-2219


JSON object : View

Products Affected

debian

  • dpkg
CWE
CWE-835

Loop with Unreachable Exit Condition ('Infinite Loop')