CVE-2026-2219: High severity dpkg/debian/dpkg-deb vulnerability
It was discovered that dpkg-deb (a component of dpkg, the Debian package management system) does not properly validate the end of the data stream when uncompressing a zstd-compressed .deb archive, which may result in denial of service (infinite loop spinning the CPU).
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-2219?
CVE-2026-2219 is classified as a denial of service vulnerability due to potential infinite CPU looping.
How do I fix CVE-2026-2219?
To fix CVE-2026-2219, update the dpkg package to the latest version that contains the necessary patches.
Which software is affected by CVE-2026-2219?
CVE-2026-2219 affects the dpkg-deb component of the Debian package management system.
What kind of attack does CVE-2026-2219 enable?
CVE-2026-2219 enables a denial of service attack due to improper validation during data stream uncompression.
What are the symptoms of CVE-2026-2219 exploitation?
Exploitation of CVE-2026-2219 may result in an infinite loop that consumes CPU resources, leading to system performance degradation.