It was discovered that dpkg-deb (a component of dpkg, the Debian package management system) does not properly validate the end of the data stream when uncompressing a zstd-compressed .deb archive, which may result in denial of service (infinite loop spinning the CPU).
{
"binaries": [
{
"binary_version": "1.19.0.5ubuntu2.4",
"binary_name": "dpkg"
},
{
"binary_version": "1.19.0.5ubuntu2.4",
"binary_name": "dpkg-dev"
},
{
"binary_version": "1.19.0.5ubuntu2.4",
"binary_name": "dselect"
},
{
"binary_version": "1.19.0.5ubuntu2.4",
"binary_name": "libdpkg-dev"
},
{
"binary_version": "1.19.0.5ubuntu2.4",
"binary_name": "libdpkg-perl"
}
]
}{
"binaries": [
{
"binary_version": "1.19.7ubuntu3.2",
"binary_name": "dpkg"
},
{
"binary_version": "1.19.7ubuntu3.2",
"binary_name": "dpkg-dev"
},
{
"binary_version": "1.19.7ubuntu3.2",
"binary_name": "dselect"
},
{
"binary_version": "1.19.7ubuntu3.2",
"binary_name": "libdpkg-dev"
},
{
"binary_version": "1.19.7ubuntu3.2",
"binary_name": "libdpkg-perl"
}
]
}{
"binaries": [
{
"binary_version": "1.21.1ubuntu2.6",
"binary_name": "dpkg"
},
{
"binary_version": "1.21.1ubuntu2.6",
"binary_name": "dpkg-dev"
},
{
"binary_version": "1.21.1ubuntu2.6",
"binary_name": "dselect"
},
{
"binary_version": "1.21.1ubuntu2.6",
"binary_name": "libdpkg-dev"
},
{
"binary_version": "1.21.1ubuntu2.6",
"binary_name": "libdpkg-perl"
}
]
}{
"binaries": [
{
"binary_version": "1.22.6ubuntu6.5",
"binary_name": "dpkg"
},
{
"binary_version": "1.22.6ubuntu6.5",
"binary_name": "dpkg-dev"
},
{
"binary_version": "1.22.6ubuntu6.5",
"binary_name": "dselect"
},
{
"binary_version": "1.22.6ubuntu6.5",
"binary_name": "libdpkg-dev"
},
{
"binary_version": "1.22.6ubuntu6.5",
"binary_name": "libdpkg-perl"
}
]
}{
"binaries": [
{
"binary_version": "1.22.21ubuntu3.1",
"binary_name": "dpkg"
},
{
"binary_version": "1.22.21ubuntu3.1",
"binary_name": "dpkg-dev"
},
{
"binary_version": "1.22.21ubuntu3.1",
"binary_name": "dselect"
},
{
"binary_version": "1.22.21ubuntu3.1",
"binary_name": "libdpkg-dev"
},
{
"binary_version": "1.22.21ubuntu3.1",
"binary_name": "libdpkg-perl"
}
]
}{
"binaries": [
{
"binary_version": "1.17.5ubuntu5.8+esm1",
"binary_name": "dpkg"
},
{
"binary_version": "1.17.5ubuntu5.8+esm1",
"binary_name": "dpkg-dev"
},
{
"binary_version": "1.17.5ubuntu5.8+esm1",
"binary_name": "dselect"
},
{
"binary_version": "1.17.5ubuntu5.8+esm1",
"binary_name": "libdpkg-dev"
},
{
"binary_version": "1.17.5ubuntu5.8+esm1",
"binary_name": "libdpkg-perl"
}
]
}{
"binaries": [
{
"binary_version": "1.18.4ubuntu1.7+esm1",
"binary_name": "dpkg"
},
{
"binary_version": "1.18.4ubuntu1.7+esm1",
"binary_name": "dpkg-dev"
},
{
"binary_version": "1.18.4ubuntu1.7+esm1",
"binary_name": "dselect"
},
{
"binary_version": "1.18.4ubuntu1.7+esm1",
"binary_name": "libdpkg-dev"
},
{
"binary_version": "1.18.4ubuntu1.7+esm1",
"binary_name": "libdpkg-perl"
}
]
}