CVE Vulnerabilities

CVE-2025-6966

NULL Pointer Dereference

Published: Dec 05, 2025 | Modified: Jan 07, 2026
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
4 MODERATE
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Ubuntu
MEDIUM

NULL pointer dereference in TagSection.keys() in python-apt on APT-based Linux systems allows a local attacker to cause a denial of service (process crash) via a crafted deb822 file with a malformed non-UTF-8 key.

Weakness

The product dereferences a pointer that it expects to be valid but is NULL.

Affected Software

Name Vendor Start Version End Version
Python-apt Ubuntu * 0.9.3.11 (excluding)
Python-apt Ubuntu 1.6.0 (including) 1.6.6 (excluding)
Python-apt Ubuntu 2.0.0 (including) 2.0.1 (excluding)
Python-apt Ubuntu 2.7.0 (including) 2.7.7 (excluding)
Python-apt Ubuntu 0.9.3.5-ubuntu1 (including) 0.9.3.5-ubuntu1 (including)
Python-apt Ubuntu 0.9.3.5-ubuntu2 (including) 0.9.3.5-ubuntu2 (including)
Python-apt Ubuntu 0.9.3.11 (including) 0.9.3.11 (including)
Python-apt Ubuntu 0.9.3.11-build1 (including) 0.9.3.11-build1 (including)
Python-apt Ubuntu 1.1.0-beta1 (including) 1.1.0-beta1 (including)
Python-apt Ubuntu 1.1.0-beta1build1 (including) 1.1.0-beta1build1 (including)
Python-apt Ubuntu 1.1.0-beta1ubuntu0.16.04.1 (including) 1.1.0-beta1ubuntu0.16.04.1 (including)
Python-apt Ubuntu 1.1.0-beta1ubuntu0.16.04.10 (including) 1.1.0-beta1ubuntu0.16.04.10 (including)
Python-apt Ubuntu 1.1.0-beta1ubuntu0.16.04.11 (including) 1.1.0-beta1ubuntu0.16.04.11 (including)
Python-apt Ubuntu 1.1.0-beta1ubuntu0.16.04.2 (including) 1.1.0-beta1ubuntu0.16.04.2 (including)
Python-apt Ubuntu 1.1.0-beta1ubuntu0.16.04.3 (including) 1.1.0-beta1ubuntu0.16.04.3 (including)
Python-apt Ubuntu 1.1.0-beta1ubuntu0.16.04.4 (including) 1.1.0-beta1ubuntu0.16.04.4 (including)
Python-apt Ubuntu 1.1.0-beta1ubuntu0.16.04.5 (including) 1.1.0-beta1ubuntu0.16.04.5 (including)
Python-apt Ubuntu 1.1.0-beta1ubuntu0.16.04.7 (including) 1.1.0-beta1ubuntu0.16.04.7 (including)
Python-apt Ubuntu 1.1.0-beta1ubuntu0.16.04.8 (including) 1.1.0-beta1ubuntu0.16.04.8 (including)
Python-apt Ubuntu 1.1.0-beta1ubuntu0.16.04.9 (including) 1.1.0-beta1ubuntu0.16.04.9 (including)
Python-apt Ubuntu 1.1.0-beta2ubuntu1 (including) 1.1.0-beta2ubuntu1 (including)
Python-apt Ubuntu 1.1.0-beta3 (including) 1.1.0-beta3 (including)
Python-apt Ubuntu 1.1.0-beta4 (including) 1.1.0-beta4 (including)
Python-apt Ubuntu 1.1.0-beta4ubuntu1 (including) 1.1.0-beta4ubuntu1 (including)
Python-apt Ubuntu 1.1.0-beta5 (including) 1.1.0-beta5 (including)
Python-apt Ubuntu 1.1.0-beta5ubuntu1 (including) 1.1.0-beta5ubuntu1 (including)
Python-apt Ubuntu 1.6.6 (including) 1.6.6 (including)
Python-apt Ubuntu 2.0.1 (including) 2.0.1 (including)
Python-apt Ubuntu 2.4.0-+22.10 (including) 2.4.0-+22.10 (including)
Python-apt Ubuntu 2.4.0 (including) 2.4.0 (including)
Python-apt Ubuntu 2.4.0-ubuntu1 (including) 2.4.0-ubuntu1 (including)
Python-apt Ubuntu 2.4.0-ubuntu2 (including) 2.4.0-ubuntu2 (including)
Python-apt Ubuntu 2.4.0-ubuntu3 (including) 2.4.0-ubuntu3 (including)
Python-apt Ubuntu 2.4.0-ubuntu4 (including) 2.4.0-ubuntu4 (including)
Python-apt Ubuntu 2.7.7 (including) 2.7.7 (including)
Python-apt Ubuntu 2.7.7-build1 (including) 2.7.7-build1 (including)
Python-apt Ubuntu 2.7.7-ubuntu1 (including) 2.7.7-ubuntu1 (including)
Python-apt Ubuntu 2.7.7-ubuntu2 (including) 2.7.7-ubuntu2 (including)
Python-apt Ubuntu 2.7.7-ubuntu3 (including) 2.7.7-ubuntu3 (including)
Python-apt Ubuntu 2.7.7-ubuntu4 (including) 2.7.7-ubuntu4 (including)
Python-apt Ubuntu 2.7.7-ubuntu5 (including) 2.7.7-ubuntu5 (including)
Python-apt Ubuntu 3.0.0 (including) 3.0.0 (including)
Python-apt Ubuntu 3.0.0-ubuntu1 (including) 3.0.0-ubuntu1 (including)
Python-apt Ubuntu esm-infra-legacy/trusty *
Python-apt Ubuntu esm-infra/bionic *
Python-apt Ubuntu esm-infra/focal *
Python-apt Ubuntu esm-infra/xenial *
Python-apt Ubuntu focal *
Python-apt Ubuntu jammy *
Python-apt Ubuntu noble *
Python-apt Ubuntu plucky *
Python-apt Ubuntu questing *
Python-apt Ubuntu upstream *

Potential Mitigations

References