PT-2026-43208 · Mageia · Dpkg

Published

2026-05-16

·

Updated

2026-05-16

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
It was discovered that dpkg-deb (a component of dpkg, the Debian package management system) does not properly validate the end of the data stream when uncompressing a zstd-compressed .deb archive, which may result in denial of service (infinite loop spinning the CPU).
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

MGASA-2026-0144

Affected Products

Dpkg