Re: [SECURITY] libapt-pkg: wild pointer dereference and daemon crash via versionless stanza in debDebFileParser::UsePackage

Luci Stanescu <[email protected]>
Newsgroups gmane.linux.debian.apt.devel
Message-ID <[email protected]>
Hi Christos,

On 18/08/2026 10:19, Christos Papakonstantinou wrote:
>
> We identified a vulnerability in libapt-pkg 2.8.3 (shipped in Ubuntu 
> 24.04 noble).
[...]
>
> We are always committed to responsible disclosure in accordance with your 
> security policy.

Thank you for reaching out!

As David mentioned, this issue is now publicly disclosed. Therefore, and 
considering you mentioned it is unfixed in upstream, I would suggest 
reporting a bug against apt (please verify that this has not been already 
reported first): https://bugs.debian.org/cgi-bin/pkgreport.cgi?src=apt

I've CCed the Debian Security Team for visibility.

On the Ubuntu Security Team front, in this instance we would defer to the 
APT maintainers as to whether it constitutes a security vulnerability.

Thanks,
Luci
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.