CVE-2026-2219

EUVD-2026-10138
It was discovered that dpkg-deb (a component of dpkg, the Debian package management system) does not properly validate the end of the data stream when uncompressing a zstd-compressed .deb archive, which may result in denial of service (infinite loop spinning the CPU).
Infinite Loop
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 34.9%
Affected Products (NVD)
VendorProductVersion
debiandpkg
1.21.18 ≤
𝑥
< 1.21.23
debiandpkg
1.22.0 ≤
𝑥
< 1.22.22
debiandpkg
1.23.0 ≤
𝑥
< 1.23.6
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
dpkg
bookworm
1.21.23
fixed
bullseye
1.20.13
fixed
bullseye (security)
1.20.14
fixed
forky
1.23.7
fixed
sid
1.23.7
fixed
trixie
1.22.22
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
dpkg
bionic
not-affected
focal
not-affected
jammy
not-affected
noble
Fixed 1.22.6ubuntu6.6
released
questing
Fixed 1.22.21ubuntu3.2
released
resolute
not-affected
trusty
not-affected
xenial
not-affected