CVE-2026-2219
EUVD-2026-1013807.03.2026, 09:16
It was discovered that dpkg-deb (a component of dpkg, the Debian package management system) does not properly validate the end of the data stream when uncompressing a zstd-compressed .deb archive, which may result in denial of service (infinite loop spinning the CPU).
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| debian | dpkg | 1.21.18 ≤ 𝑥 < 1.21.23 |
| debian | dpkg | 1.22.0 ≤ 𝑥 < 1.22.22 |
| debian | dpkg | 1.23.0 ≤ 𝑥 < 1.23.6 |
𝑥
= Vulnerable software versions
Debian Releases
Common Weakness Enumeration