Nixpkgs security tracker

Login with GitHub
⚠️ You are using a production deployment that is still only suitable for demo purposes. Any work done in this might be wiped later without notice.

Suggestions search

With package: dpkg

Found 1 matching suggestions

View:
Compact
Detailed
created 1 month, 2 weeks ago Activity log
  • Created suggestion
It was discovered that dpkg-deb (a component of dpkg, the …

It was discovered that dpkg-deb (a component of dpkg, the Debian package management system) does not properly validate the end of the data stream when uncompressing a zstd-compressed .deb archive, which may result in denial of service (infinite loop spinning the CPU).

Affected products

dpkg
  • <1.23.6

Matching in nixpkgs

Package maintainers