Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Yashashree Gund

#19907of 53,633
13Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2026-23848
7.5
2026-03-07
Debian · Dpkg-Deb · CVE-2026-2219
**Name of the Vulnerable Software and Affected Versions** dpkg-deb (affected versions not specified) **Description** The dpkg-deb component of the Debian package management system does not properly validate the end of the data stream when uncompressing a zstd-compressed .deb archive. This can lead to a denial of service condition, specifically an infinite loop that consumes CPU resources. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2026-22490
5.5
2026-01-01
Unknown · Rust-Rpm-Sequoia · CVE-2026-2625
**Name of the Vulnerable Software and Affected Versions** rust-rpm-sequoia (affected versions not specified) **Description** A flaw exists in rust-rpm-sequoia that allows an attacker to cause an application-level denial of service. This occurs when a specially crafted Red Hat Package Manager (RPM) file is provided. The vulnerability is triggered during RPM signature verification, specifically within the OpenPGP signature parsing code, leading to the unconditional termination of the `rpm` process. This prevents the system from processing RPM files for signature verification. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.