CVE-2025-6966: Null-pointer dereference in python-apt TagSection.keys()
Published Dec 5, 2025
·Updated
NULL pointer dereference in TagSection.keys() in python-apt on APT-based Linux systems allows a local attacker to cause a denial of service (process crash) via a crafted deb822 file with a malformed non-UTF-8 key.
Affected Software
46 affected components
pypi/python-apt
All of the following
Any of the following
Ubuntu Python-apt<0.9.3.11
Ubuntu Python-apt>=1.6.0<1.6.6
Ubuntu Python-apt>=2.0.0<2.0.1
Ubuntu Python-apt>=2.7.0<2.7.7
Ubuntu Python-apt=0.9.3.5-ubuntu1
Ubuntu Python-apt=0.9.3.5-ubuntu2
Ubuntu Python-apt=0.9.3.11
Ubuntu Python-apt=0.9.3.11-build1
Ubuntu Python-apt=1.1.0-beta1
Ubuntu Python-apt=1.1.0-beta1build1
Ubuntu Python-apt=1.1.0-beta1ubuntu0.16.04.1
Ubuntu Python-apt=1.1.0-beta1ubuntu0.16.04.10
Ubuntu Python-apt=1.1.0-beta1ubuntu0.16.04.11
Ubuntu Python-apt=1.1.0-beta1ubuntu0.16.04.2
Ubuntu Python-apt=1.1.0-beta1ubuntu0.16.04.3
Ubuntu Python-apt=1.1.0-beta1ubuntu0.16.04.4
Ubuntu Python-apt=1.1.0-beta1ubuntu0.16.04.5
Ubuntu Python-apt=1.1.0-beta1ubuntu0.16.04.7
Ubuntu Python-apt=1.1.0-beta1ubuntu0.16.04.8
Ubuntu Python-apt=1.1.0-beta1ubuntu0.16.04.9
Ubuntu Python-apt=1.1.0-beta2ubuntu1
Ubuntu Python-apt=1.1.0-beta3
Ubuntu Python-apt=1.1.0-beta4
Ubuntu Python-apt=1.1.0-beta4ubuntu1
Ubuntu Python-apt=1.1.0-beta5
Ubuntu Python-apt=1.1.0-beta5ubuntu1
Ubuntu Python-apt=1.6.6
Ubuntu Python-apt=2.0.1
Ubuntu Python-apt=2.4.0-\+22.10
Ubuntu Python-apt=2.4.0
Ubuntu Python-apt=2.4.0-ubuntu1
Ubuntu Python-apt=2.4.0-ubuntu2
Ubuntu Python-apt=2.4.0-ubuntu3
Ubuntu Python-apt=2.4.0-ubuntu4
Ubuntu Python-apt=2.7.7
Ubuntu Python-apt=2.7.7-build1
Ubuntu Python-apt=2.7.7-ubuntu1
Ubuntu Python-apt=2.7.7-ubuntu2
Ubuntu Python-apt=2.7.7-ubuntu3
Ubuntu Python-apt=2.7.7-ubuntu4
Ubuntu Python-apt=2.7.7-ubuntu5
Ubuntu Python-apt=3.0.0
Ubuntu Python-apt=3.0.0-ubuntu1
Canonical Ubuntu Linux
Debian Debian Linux=11.0
Event History
Dec 5, 2025
CVE Published
via MITRE·12:59 PM
Data Sourced
via MITRE·12:59 PM
DescriptionWeakness
Data Sourced
via NVD·01:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-6966?
CVE-2025-6966 has a high severity as it can lead to a denial of service via a crash.
2
How do I fix CVE-2025-6966?
To fix CVE-2025-6966, update python-apt to the latest version that addresses this vulnerability.
3
Who is affected by CVE-2025-6966?
CVE-2025-6966 affects APT-based Linux systems using python-apt.
4
What kind of attack does CVE-2025-6966 enable?
CVE-2025-6966 allows local attackers to exploit a NULL pointer dereference leading to a process crash.
5
What is the cause of CVE-2025-6966?
CVE-2025-6966 is caused by a crafted deb822 file with a malformed non-UTF-8 key.