Nixpkgs Security Tracker

Login with GitHub

Details of issue NIXPKGS-2026-0579

NIXPKGS-2026-0579
published on 8 Mar 2026
updated 1 week ago by @mweinelt Activity log
  • Created automatic suggestion
  • @mweinelt accepted
  • @mweinelt published on GitHub
It was discovered that dpkg-deb (a component of dpkg, the …

It was discovered that dpkg-deb (a component of dpkg, the Debian package management system) does not properly validate the end of the data stream when uncompressing a zstd-compressed .deb archive, which may result in denial of service (infinite loop spinning the CPU).

Affected products

dpkg
  • <1.23.6

Matching in nixpkgs

Package maintainers

Upstream issue: https://bugs.debian.org/challenge.html?original=%2f1129722
Patch: https://git.dpkg.org/cgit/dpkg/dpkg.git/commit/?id=6610297a62c0780dd0e80b0e302ef64fdcc9d313