CVE-2025-6297

EUVD-2025-19670
It was discovered that dpkg-deb does not properly sanitize directory permissions when extracting a control member into a temporary directory, which is
documented as being a safe operation even on untrusted data. This may result in leaving temporary files behind on cleanup. Given automated and repeated execution of dpkg-deb commands on
adversarial .deb packages or with well compressible files, placed
inside a directory with permissions not allowing removal by a non-root
user, this can end up in a DoS scenario due to causing disk quota
exhaustion or disk full conditions.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.2 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 28.65%
Affected Products (NVD)
VendorProductVersion
debiandpkg
𝑥
< 1.22.21
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
dpkg
bookworm
1.21.23
fixed
bullseye
vulnerable
bullseye (security)
1.20.14
fixed
forky
1.23.7
fixed
sid
1.23.7
fixed
trixie
1.22.22
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
dpkg
bionic
needs-triage
focal
needs-triage
jammy
Fixed 1.21.1ubuntu2.6
released
noble
Fixed 1.22.6ubuntu6.5
released
oracular
ignored
plucky
Fixed 1.22.18ubuntu2.2
released
questing
Fixed 1.22.21ubuntu1
released
resolute
Fixed 1.22.21ubuntu1
released
trusty
needs-triage
xenial
needs-triage
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
dpkg
suse enterprise desktop 15 SP6
1.19.0.4-150000.4.7.1
fixed
suse enterprise desktop 15 SP7
1.19.0.4-150000.4.7.1
fixed
suse enterprise sap 15 SP6
1.19.0.4-150000.4.7.1
fixed
suse enterprise sap 15 SP7
1.19.0.4-150000.4.7.1
fixed
suse enterprise server 15 SP4
1.19.0.4-150000.4.7.1
fixed
suse enterprise server 15 SP6
1.19.0.4-150000.4.7.1
fixed
suse enterprise server 15 SP7
1.19.0.4-150000.4.7.1
fixed
dpkg-devel
suse enterprise desktop 15 SP6
1.19.0.4-150000.4.7.1
fixed
suse enterprise desktop 15 SP7
1.19.0.4-150000.4.7.1
fixed
suse enterprise sap 15 SP6
1.19.0.4-150000.4.7.1
fixed
suse enterprise sap 15 SP7
1.19.0.4-150000.4.7.1
fixed
suse enterprise server 15 SP4
1.19.0.4-150000.4.7.1
fixed
suse enterprise server 15 SP6
1.19.0.4-150000.4.7.1
fixed
suse enterprise server 15 SP7
1.19.0.4-150000.4.7.1
fixed
update-alternatives
suse enterprise server 15 SP4
1.19.0.4-150000.4.7.1
fixed