CVE-2026-2219: Debian Dpkg
High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.
It was discovered that dpkg-deb (a component of dpkg, the Debian package management system) does not properly validate the end of the data stream when uncompressing a zstd-compressed .deb archive, which may result in denial of service (infinite loop spinning the CPU).
Affected products
- Debian Dpkg: from 1.21.18, before 1.21.23 (fixed in 1.21.23); from 1.22.0, before 1.22.22 (fixed in 1.22.22); from 1.23.0, before 1.23.6 (fixed in 1.23.6)
Published 2026-03-07. Last modified 2026-06-17.