Re: [SECURITY] libapt-pkg: wild pointer dereference and daemon crash via versionless stanza in debDebFileParser::UsePackage
Moritz Mühlenhoff <[email protected]>
| Newsgroups | gmane.linux.debian.apt.devel |
|---|---|
| Message-ID | <[email protected]> |
On Fri, Aug 21, 2026 at 02:39:50PM +0300, Luci Stanescu wrote:
> As David mentioned, this issue is now publicly disclosed. Therefore, and
> considering you mentioned it is unfixed in upstream, I would suggest
> reporting a bug against apt (please verify that this has not been already
> reported first): https://bugs.debian.org/cgi-bin/pkgreport.cgi?src=apt
Sounds good. When it has been filed it would be great if you could send
us the bug number.
> On the Ubuntu Security Team front, in this instance we would defer to the
> APT maintainers as to whether it constitutes a security vulnerability.
Same for Debian.
Cheers,
Moritz