Logo
vulnerabilityCVE-2025-6297
Name
CVE-2025-6297
Source
NVD ( link)Debian ( link)
Description
It was discovered that dpkg-deb does not properly sanitize directory permissions when extracting a control member into a temporary directory, which is documented as being a safe operation even on untrusted data. This may result in leaving temporary files behind on cleanup. Given automated and repeated execution of dpkg-deb commands on adversarial .deb packages or with well compressible files, placed inside a directory with permissions not allowing removal by a non-root user, this can end up in a DoS scenario due to causing disk quota exhaustion or disk full conditions.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
dpkg
Patched

Vulnerability Ratings#


8.2
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
yocto
master
1.23.7
Not Affected
yocto
scarthgap
1.22.0
Patched

Resolved with patches#


dpkg (yocto:kirkstone)

#
Title
Author
Resolve
1
dpkg-deb: Fix cleanup for control member with restricted
Guillem Jover <guillem@debian.org>
CVE-2025-6297

dpkg (yocto:scarthgap)

#
Title
Author
Resolve
1
dpkg-deb: Fix cleanup for control member with restricted
Guillem Jover <guillem@debian.org>
CVE-2025-6297