-
-
Notifications
You must be signed in to change notification settings - Fork 2.6k
Open
Labels
cvelibrariesFor things referring to osquery third party librariesFor things referring to osquery third party librariessecurityseverity-high
Description
https://nvd.nist.gov/vuln/detail/CVE-2025-6297
It was discovered that dpkg-deb does not properly sanitize directory permissions when extracting a control member into a temporary directory, which is
documented as being a safe operation even on untrusted data. This may result in leaving temporary files behind on cleanup. Given automated and repeated execution of dpkg-deb commands on
adversarial .deb packages or with well compressible files, placed
inside a directory with permissions not allowing removal by a non-root
user, this can end up in a DoS scenario due to causing disk quota
exhaustion or disk full conditions.
NOTE: This is an automated issue created based on the library metadata. Osquery may or may not be affected.
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
cvelibrariesFor things referring to osquery third party librariesFor things referring to osquery third party librariessecurityseverity-high