CVE-2025-6297
CVE Information
CVE ID
CVE-2025-6297
Severity
HIGH
CVSS 8.2
Publish Date
2025-07-01
Description
It was discovered that dpkg-deb does not properly sanitize directory permissions when extracting a control member into a temporary directory, which is documented as being a safe operation even on untrusted data. This may result in leaving temporary files behind on cleanup. Given automated and repeated execution of dpkg-deb commands on adversarial .deb packages or with well compressible files, placed inside a directory with permissions not allowing removal by a non-root user, this can end up in a DoS scenario due to causing disk quota exhaustion or disk full conditions.
Collection Date
2026-01-13
Impact Summary
Affected Hosts
3
Related Incidents
0
Related Alerts
0
Affected Hosts (3)
| Hostname | OS Type | Severity | Total CVEs |
|---|---|---|---|
| inbridge-42 | LINUX | CRITICAL | 142 |
| in-bridge-40 | LINUX | CRITICAL | 392 |
| inbridge-ubt-24 | LINUX | CRITICAL | 2364 |