[Pkg-utopia-maintainers] Bug#1144105: ostree: GHSA-7cgc-gp99-6jmm: resource exhaustion via LZMA decoding
Simon McVittie
smcv at debian.org
Tue Aug 11 10:10:27 BST 2026
Package: libostree-1-1
Severity: important
Tags: security upstream help
X-Debbugs-Cc: Debian Security Team <team at security.debian.org>
Control: fixed -1 2026.3-1
https://github.com/ostreedev/ostree/security/advisories/GHSA-7cgc-gp99-6jmm
A vulnerability in libostree allows the operator of a malicious or
compromised OSTree repository to serve crafted static delta content that
causes clients to exhaust memory and disk space during `ostree pull`.
All versions ever shipped by Debian appear to be affected. There is
currently no known CVE ID.
A mitigation is that if an OSTree repository is malicious or
compromised, its operator can also do worse things, like inserting
malicious OS images, or Flatpak apps with malicious metadata; so resource
exhaustion is perhaps not a particularly exciting vulnerability.
I would very much appreciate it if someone else could take
responsibility for identifying the specific fixes and preparing a
backport to Debian 13.
Thanks,
smcv
More information about the Pkg-utopia-maintainers
mailing list