---
cve: "CVE-2025-6297"
severity: "HIGH"
cvss: 8.2
epss: "35%"
vendor: "Debian"
kev: false
exploited: false
published: "2025-07-01 17:15:30"
tags: [cve, security, high]
source: tsecurity.de CVE-Dossier
exported: "2026-09-11T13:03:46+02:00"
---

# CVE-2025-6297

> 8.2 HIGH

## Beschreibung

It was discovered that dpkg-deb does not properly sanitize directory permissions when extracting a control member into a temporary directory, which is
documented as being a safe operation even on untrusted data. This may result in leaving temporary files behind on cleanup. Given automated and repeated execution of dpkg-deb commands on
adversarial .deb packages or with well compressible files, placed
inside a directory with permissions not allowing removal by a non-root
user, this can end up in a DoS scenario due to causing disk quota
exhaustion or disk full conditions.

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Hoch | bad |
| I Integrität | Gering | warn |
| A Verfügbarkeit | Keine | good |

## Patch verfügbar (OSV)

- d72b038fd2113cb62972e4071db03dd1388394d8 (Commit)
- ed6bbd445dd8800308c67236ba35d08004c98e82 (Commit)

## Referenzen

- <https://git.dpkg.org/cgit/dpkg/dpkg.git/commit/?id=ed6bbd445dd8800308c67236ba35d08004c98e82>
- <https://lists.debian.org/debian-lts-announce/2026/07/msg00015.html>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2025-6297) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
