UbuntuUpdates.org

Package "dpkg"

Name: dpkg

Description:

Debian package management system

Latest version: 1.22.6ubuntu6.6
Release: noble (24.04)
Level: security
Repository: main
Homepage: https://wiki.debian.org/Teams/Dpkg

Links


Download "dpkg"


Other versions of "dpkg" in Noble

Repository Area Version
base main 1.22.6ubuntu6
updates main 1.22.6ubuntu6.6

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 1.22.6ubuntu6.6 2026-05-07 14:07:33 UTC

  dpkg (1.22.6ubuntu6.6) noble-security; urgency=medium

  * SECURITY UPDATE: infinite loop uncompressing a zstd-compressed .deb archive
    - lib/dpkg/compress.c: terminate zstd decompression when we have no
      more data.
    - 6610297a62c0780dd0e80b0e302ef64fdcc9d313
    - CVE-2026-2219

 -- Marc Deslauriers <email address hidden> Wed, 06 May 2026 13:38:18 -0400

Source diff to previous version
CVE-2026-2219 It was discovered that dpkg-deb (a component of dpkg, the Debian package management system) does not properly validate the end of the data stream whe

Version: 1.22.6ubuntu6.5 2025-09-24 16:07:06 UTC

  dpkg (1.22.6ubuntu6.5) noble-security; urgency=medium

  [ Joy Latten ]
  * SECURITY UPDATE:
  - Fix cleanup for control member with restricted directories. LP: #2122053
  - Fixes CVE-2025-6297

 -- Serge Hallyn <email address hidden> Thu, 18 Sep 2025 12:43:59 -0500

Source diff to previous version
2122053 dpkg-deb: Fix cleanup for control member with restricted directories
CVE-2025-6297 It was discovered that dpkg-deb does not properly sanitize directory permissions when extracting a control member into a temporary directory, which i

Version: 1.22.6ubuntu6.1 2024-08-20 14:07:15 UTC

  dpkg (1.22.6ubuntu6.1) noble-security; urgency=medium

  * SRU:
    - Disable framepointer on ppc64el. LP: #2064539.
    - Disable framepointer on s390x, leaving only -mbackchain. LP: #2064538.

 -- Matthias Klose <email address hidden> Wed, 17 Jul 2024 11:09:50 +0200




About   -   Send Feedback to @ubuntu_updates