CVE-2025-6966: Debian Linux

Medium severity, CVSS 5.5. EPSS: 0.1% chance of exploitation in the next 30 days.

NULL pointer dereference in TagSection.keys() in python-apt on APT-based Linux systems allows a local attacker to cause a denial of service (process crash) via a crafted deb822 file with a malformed non-UTF-8 key.

Affected products

  • Debian Debian Linux: version 11.0 only
  • Ubuntu Python-Apt: before 0.9.3.11 (fixed in 0.9.3.11); from 1.6.0, before 1.6.6 (fixed in 1.6.6); from 2.0.0, before 2.0.1 (fixed in 2.0.1); from 2.7.0, before 2.7.7 (fixed in 2.7.7); version 0.9.3.5 only; version 0.9.3.11 only; …

Published 2025-12-05. Last modified 2026-09-25.