CVE Vulnerabilities

CVE-2025-6966

NULL Pointer Dereference

Published: Dec 05, 2025 | Modified: Jan 07, 2026
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
4 MODERATE
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

NULL pointer dereference in TagSection.keys() in python-apt on APT-based Linux systems allows a local attacker to cause a denial of service (process crash) via a crafted deb822 file with a malformed non-UTF-8 key.

Weakness

The product dereferences a pointer that it expects to be valid but is NULL.

Affected Software

NameVendorStart VersionEnd Version
Python-aptUbuntu*0.9.3.11 (excluding)
Python-aptUbuntu1.6.0 (including)1.6.6 (excluding)
Python-aptUbuntu2.0.0 (including)2.0.1 (excluding)
Python-aptUbuntu2.7.0 (including)2.7.7 (excluding)
Python-aptUbuntu0.9.3.5-ubuntu1 (including)0.9.3.5-ubuntu1 (including)
Python-aptUbuntu0.9.3.5-ubuntu2 (including)0.9.3.5-ubuntu2 (including)
Python-aptUbuntu0.9.3.11 (including)0.9.3.11 (including)
Python-aptUbuntu0.9.3.11-build1 (including)0.9.3.11-build1 (including)
Python-aptUbuntu1.1.0-beta1 (including)1.1.0-beta1 (including)
Python-aptUbuntu1.1.0-beta1build1 (including)1.1.0-beta1build1 (including)
Python-aptUbuntu1.1.0-beta1ubuntu0.16.04.1 (including)1.1.0-beta1ubuntu0.16.04.1 (including)
Python-aptUbuntu1.1.0-beta1ubuntu0.16.04.10 (including)1.1.0-beta1ubuntu0.16.04.10 (including)
Python-aptUbuntu1.1.0-beta1ubuntu0.16.04.11 (including)1.1.0-beta1ubuntu0.16.04.11 (including)
Python-aptUbuntu1.1.0-beta1ubuntu0.16.04.2 (including)1.1.0-beta1ubuntu0.16.04.2 (including)
Python-aptUbuntu1.1.0-beta1ubuntu0.16.04.3 (including)1.1.0-beta1ubuntu0.16.04.3 (including)
Python-aptUbuntu1.1.0-beta1ubuntu0.16.04.4 (including)1.1.0-beta1ubuntu0.16.04.4 (including)
Python-aptUbuntu1.1.0-beta1ubuntu0.16.04.5 (including)1.1.0-beta1ubuntu0.16.04.5 (including)
Python-aptUbuntu1.1.0-beta1ubuntu0.16.04.7 (including)1.1.0-beta1ubuntu0.16.04.7 (including)
Python-aptUbuntu1.1.0-beta1ubuntu0.16.04.8 (including)1.1.0-beta1ubuntu0.16.04.8 (including)
Python-aptUbuntu1.1.0-beta1ubuntu0.16.04.9 (including)1.1.0-beta1ubuntu0.16.04.9 (including)
Python-aptUbuntu1.1.0-beta2ubuntu1 (including)1.1.0-beta2ubuntu1 (including)
Python-aptUbuntu1.1.0-beta3 (including)1.1.0-beta3 (including)
Python-aptUbuntu1.1.0-beta4 (including)1.1.0-beta4 (including)
Python-aptUbuntu1.1.0-beta4ubuntu1 (including)1.1.0-beta4ubuntu1 (including)
Python-aptUbuntu1.1.0-beta5 (including)1.1.0-beta5 (including)
Python-aptUbuntu1.1.0-beta5ubuntu1 (including)1.1.0-beta5ubuntu1 (including)
Python-aptUbuntu1.6.6 (including)1.6.6 (including)
Python-aptUbuntu2.0.1 (including)2.0.1 (including)
Python-aptUbuntu2.4.0-+22.10 (including)2.4.0-+22.10 (including)
Python-aptUbuntu2.4.0 (including)2.4.0 (including)
Python-aptUbuntu2.4.0-ubuntu1 (including)2.4.0-ubuntu1 (including)
Python-aptUbuntu2.4.0-ubuntu2 (including)2.4.0-ubuntu2 (including)
Python-aptUbuntu2.4.0-ubuntu3 (including)2.4.0-ubuntu3 (including)
Python-aptUbuntu2.4.0-ubuntu4 (including)2.4.0-ubuntu4 (including)
Python-aptUbuntu2.7.7 (including)2.7.7 (including)
Python-aptUbuntu2.7.7-build1 (including)2.7.7-build1 (including)
Python-aptUbuntu2.7.7-ubuntu1 (including)2.7.7-ubuntu1 (including)
Python-aptUbuntu2.7.7-ubuntu2 (including)2.7.7-ubuntu2 (including)
Python-aptUbuntu2.7.7-ubuntu3 (including)2.7.7-ubuntu3 (including)
Python-aptUbuntu2.7.7-ubuntu4 (including)2.7.7-ubuntu4 (including)
Python-aptUbuntu2.7.7-ubuntu5 (including)2.7.7-ubuntu5 (including)
Python-aptUbuntu3.0.0 (including)3.0.0 (including)
Python-aptUbuntu3.0.0-ubuntu1 (including)3.0.0-ubuntu1 (including)
Python-aptUbuntuesm-infra-legacy/trusty*
Python-aptUbuntuesm-infra/bionic*
Python-aptUbuntuesm-infra/focal*
Python-aptUbuntuesm-infra/xenial*
Python-aptUbuntufocal*
Python-aptUbuntujammy*
Python-aptUbuntunoble*
Python-aptUbuntuplucky*
Python-aptUbuntuquesting*
Python-aptUbuntuupstream*

Potential Mitigations

References