CVE-2025-6297: Vulnerability in Debian dpkg
It was discovered that dpkg-deb does not properly sanitize directory permissions when extracting a control member into a temporary directory, which is documented as being a safe operation even on untrusted data. This may result in leaving temporary files behind on cleanup. Given automated and repeated execution of dpkg-deb commands on adversarial .deb packages or with well compressible files, placed inside a directory with permissions not allowing removal by a non-root user, this can end up in a DoS scenario due to causing disk quota exhaustion or disk full conditions.
AI Analysis
Technical Summary
CVE-2025-6297 is a vulnerability in Debian's dpkg package management tool, specifically in the dpkg-deb utility. The flaw involves improper sanitization of directory permissions during the extraction of control members into temporary directories, which are expected to be safe even with untrusted data. This improper handling can cause temporary files to remain after cleanup, especially under repeated automated execution with adversarial .deb packages or well-compressible files located in directories where non-root users cannot remove files. The resulting accumulation of leftover files can exhaust disk quota or fill the disk, causing a denial-of-service condition. The vulnerability is rated with a CVSS 3.1 score of 8.2 (high severity) and involves CWE-732 (Incorrect Permission Assignment for Critical Resource) and CWE-400 (Uncontrolled Resource Consumption). No known exploits in the wild have been reported, and no patch or remediation details are provided in the available data.
Potential Impact
The vulnerability can lead to denial-of-service conditions by exhausting disk space or disk quota due to leftover temporary files that are not properly cleaned up. This can disrupt normal system operations, particularly on systems where dpkg-deb is executed repeatedly with crafted .deb packages or files in directories with restrictive permissions. Confidentiality and integrity impacts are low or none, but availability is significantly affected.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, avoid running dpkg-deb on untrusted or adversarial .deb packages in directories with restrictive permissions that prevent file removal by non-root users. Monitor for updates from Debian regarding patches or official mitigations.
CVE-2025-6297: Vulnerability in Debian dpkg
Description
It was discovered that dpkg-deb does not properly sanitize directory permissions when extracting a control member into a temporary directory, which is documented as being a safe operation even on untrusted data. This may result in leaving temporary files behind on cleanup. Given automated and repeated execution of dpkg-deb commands on adversarial .deb packages or with well compressible files, placed inside a directory with permissions not allowing removal by a non-root user, this can end up in a DoS scenario due to causing disk quota exhaustion or disk full conditions.
CVSS v3.1
Score 8.2high
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2025-6297 is a vulnerability in Debian's dpkg package management tool, specifically in the dpkg-deb utility. The flaw involves improper sanitization of directory permissions during the extraction of control members into temporary directories, which are expected to be safe even with untrusted data. This improper handling can cause temporary files to remain after cleanup, especially under repeated automated execution with adversarial .deb packages or well-compressible files located in directories where non-root users cannot remove files. The resulting accumulation of leftover files can exhaust disk quota or fill the disk, causing a denial-of-service condition. The vulnerability is rated with a CVSS 3.1 score of 8.2 (high severity) and involves CWE-732 (Incorrect Permission Assignment for Critical Resource) and CWE-400 (Uncontrolled Resource Consumption). No known exploits in the wild have been reported, and no patch or remediation details are provided in the available data.
Potential Impact
The vulnerability can lead to denial-of-service conditions by exhausting disk space or disk quota due to leftover temporary files that are not properly cleaned up. This can disrupt normal system operations, particularly on systems where dpkg-deb is executed repeatedly with crafted .deb packages or files in directories with restrictive permissions. Confidentiality and integrity impacts are low or none, but availability is significantly affected.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, avoid running dpkg-deb on untrusted or adversarial .deb packages in directories with restrictive permissions that prevent file removal by non-root users. Monitor for updates from Debian regarding patches or official mitigations.
Technical Details
- Data Version
- 5.1
- Assigner Short Name
- debian
- Date Reserved
- 2025-06-19T07:40:18.350Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 68641d506f40f0eb72902caa
Added to database: 07/01/2025, 17:39:28 UTC
Last enriched: 07/15/2026, 12:25:47 UTC
Last updated: 09/10/2026, 19:36:51 UTC
Views: 340
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.