cbcvebase.
CVE-2025-6297
published 2025-07-01

CVE-2025-6297: It was discovered that dpkg-deb does not properly sanitize directory permissions when extracting a control member into a temporary directory, which is…

PriorityP346high8.2CVSS 3.1
AVNACLPRNUINSUCHILAN
EPSS
0.35%
26.5th percentile
It was discovered that dpkg-deb does not properly sanitize directory permissions when extracting a control member into a temporary directory, which is documented as being a safe operation even on untrusted data. This may result in leaving temporary files behind on cleanup. Given automated and repeated execution of dpkg-deb commands on adversarial .deb packages or with well compressible files, placed inside a directory with permissions not allowing removal by a non-root user, this can end up in a DoS scenario due to causing disk quota exhaustion or disk full conditions.

Affected

5 ranges
VendorProductVersion rangeFixed in
debiandpkg< ed6bbd445dd8800308c67236ba35d08004c98e82ed6bbd445dd8800308c67236ba35d08004c98e82
debiandpkg< 1.22.211.22.21
debiandpkg< dpkg 1.22.21 (forky)dpkg 1.22.21 (forky)
debiandpkg>= 0 < 1.22.211.22.21
debiandpkg>= 0 < 1.22.211.22.21

CVSS provenance

nvdv3.18.2HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
osv8.2HIGH
vendor_debian8.2HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.