CVE Vulnerabilities

CVE-2025-6966

NULL Pointer Dereference

Published: Dec 05, 2025 | Modified: Dec 08, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

NULL pointer dereference in TagSection.keys() in python-apt on APT-based Linux systems allows a local attacker to cause a denial of service (process crash) via a crafted deb822 file with a malformed non-UTF-8 key.

Weakness

The product dereferences a pointer that it expects to be valid but is NULL.

Affected Software

Name Vendor Start Version End Version
Python-apt Ubuntu devel *
Python-apt Ubuntu esm-infra-legacy/trusty *
Python-apt Ubuntu esm-infra/bionic *
Python-apt Ubuntu esm-infra/focal *
Python-apt Ubuntu esm-infra/xenial *
Python-apt Ubuntu focal *
Python-apt Ubuntu jammy *
Python-apt Ubuntu noble *
Python-apt Ubuntu plucky *
Python-apt Ubuntu questing *
Python-apt Ubuntu upstream *

Potential Mitigations

References