Re: [SECURITY] libapt-pkg: wild pointer dereference and daemon crash via versionless stanza in debDebFileParser::UsePackage
Julian Andres Klode <[email protected]>
| Newsgroups | gmane.linux.debian.apt.devel |
|---|---|
| Message-ID | <[email protected]> |
On Fri, Aug 21, 2026 at 11:55:53AM +0000, Moritz Mühlenhoff wrote: > On Fri, Aug 21, 2026 at 02:39:50PM +0300, Luci Stanescu wrote: > > As David mentioned, this issue is now publicly disclosed. Therefore, and > > considering you mentioned it is unfixed in upstream, I would suggest > > reporting a bug against apt (please verify that this has not been already > > reported first): https://bugs.debian.org/cgi-bin/pkgreport.cgi?src=apt > > Sounds good. When it has been filed it would be great if you could send > us the bug number. > > > On the Ubuntu Security Team front, in this instance we would defer to the > > APT maintainers as to whether it constitutes a security vulnerability. > > Same for Debian. > As far as APT is concerned this is a trusted code path and does not cross privilege boundaries, and is therefore not a security issue. Unfortunately, the trusted code path has been used at a privilege crossing border - untrusted input has been passed to a root daemon in PackageKit. This does not seem exploitable to code execution, and a denial of service of PackageKit has limited impact. It stands to reason that it would be helpful for PackageKit to isolate operations involving untrusted inputs into individual processes. We're evaluating a whole bunch of other out-of-bounds accesses and may do point releases of all the APT release series to address the whole lot in the upcoming weeks. -- debian developer - deb.li/jak | jak-linux.org - free software dev ubuntu core developer i speak de, en