[Pkg-utopia-maintainers] Bug#1144105: ostree: GHSA-7cgc-gp99-6jmm: resource exhaustion via LZMA decoding

Simon McVittie smcv at debian.org
Tue Aug 11 10:10:27 BST 2026


Package: libostree-1-1
Severity: important
Tags: security upstream help
X-Debbugs-Cc: Debian Security Team <team at security.debian.org>
Control: fixed -1 2026.3-1

https://github.com/ostreedev/ostree/security/advisories/GHSA-7cgc-gp99-6jmm

A vulnerability in libostree allows the operator of a malicious or 
compromised OSTree repository to serve crafted static delta content that 
causes clients to exhaust memory and disk space during `ostree pull`. 
All versions ever shipped by Debian appear to be affected. There is 
currently no known CVE ID.

A mitigation is that if an OSTree repository is malicious or 
compromised, its operator can also do worse things, like inserting 
malicious OS images, or Flatpak apps with malicious metadata; so resource 
exhaustion is perhaps not a particularly exciting vulnerability.

I would very much appreciate it if someone else could take 
responsibility for identifying the specific fixes and preparing a 
backport to Debian 13.

Thanks,
    smcv



More information about the Pkg-utopia-maintainers mailing list