Re: [SECURITY] libapt-pkg: wild pointer dereference and daemon crash via versionless stanza in debDebFileParser::UsePackage

Julian Andres Klode <[email protected]>
Newsgroups gmane.linux.debian.apt.devel
Message-ID <[email protected]>
On Fri, Aug 21, 2026 at 11:55:53AM +0000, Moritz Mühlenhoff wrote:
> On Fri, Aug 21, 2026 at 02:39:50PM +0300, Luci Stanescu wrote:
> > As David mentioned, this issue is now publicly disclosed. Therefore, and
> > considering you mentioned it is unfixed in upstream, I would suggest
> > reporting a bug against apt (please verify that this has not been already
> > reported first): https://bugs.debian.org/cgi-bin/pkgreport.cgi?src=apt
> 
> Sounds good. When it has been filed it would be great if you could send
> us the bug number.
> 
> > On the Ubuntu Security Team front, in this instance we would defer to the
> > APT maintainers as to whether it constitutes a security vulnerability.
> 
> Same for Debian.
> 

As far as APT is concerned this is a trusted code path and does not
cross privilege boundaries, and is therefore not a security issue.

Unfortunately, the trusted code path has been used at a privilege
crossing border - untrusted input has been passed to a root daemon
in PackageKit. This does not seem exploitable to code execution,
and a denial of service of PackageKit has limited impact.

It stands to reason that it would be helpful for PackageKit to
isolate operations involving untrusted inputs into individual
processes.

We're evaluating a whole bunch of other out-of-bounds accesses and
may do point releases of all the APT release series to address the
whole lot in the upcoming weeks.

-- 
debian developer - deb.li/jak | jak-linux.org - free software dev
ubuntu core developer                              i speak de, en
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.