Re: [SECURITY] libapt-pkg: wild pointer dereference and daemon crash via versionless stanza in debDebFileParser::UsePackage
Luci Stanescu <[email protected]>
| Newsgroups | gmane.linux.debian.apt.devel |
|---|---|
| Message-ID | <[email protected]> |
Hi Christos, On 18/08/2026 10:19, Christos Papakonstantinou wrote: > > We identified a vulnerability in libapt-pkg 2.8.3 (shipped in Ubuntu > 24.04 noble). [...] > > We are always committed to responsible disclosure in accordance with your > security policy. Thank you for reaching out! As David mentioned, this issue is now publicly disclosed. Therefore, and considering you mentioned it is unfixed in upstream, I would suggest reporting a bug against apt (please verify that this has not been already reported first): https://bugs.debian.org/cgi-bin/pkgreport.cgi?src=apt I've CCed the Debian Security Team for visibility. On the Ubuntu Security Team front, in this instance we would defer to the APT maintainers as to whether it constitutes a security vulnerability. Thanks, Luci