CVE-2026-2219

NameCVE-2026-2219
Descriptiondpkg-deb: Persistent hang on malformed .deb archives (DoS)
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1129722

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
dpkg (PTS)bullseye1.20.13vulnerable
bullseye (security)1.20.10vulnerable
bookworm1.21.22vulnerable
trixie1.22.21vulnerable
forky1.23.5vulnerable
sid1.23.6fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
dpkgsource(unstable)1.23.61129722

Notes

[trixie] - dpkg <no-dsa> (Minor issue; can be fixed in point release)
[bookworm] - dpkg <no-dsa> (Minor issue; can be fixed in point release)
Fixed by: https://git.dpkg.org/cgit/dpkg/dpkg.git/commit/?id=6610297a62c0780dd0e80b0e302ef64fdcc9d313

Search for package or bug name: Reporting problems