Back

MEDIUM

Null-pointer dereference in python-apt TagSection.keys()

Published Dec 5, 2025

Description

NULL pointer dereference in TagSection.keys() in python-apt on APT-based Linux systems allows a local attacker to cause a denial of service (process crash) via a crafted deb822 file with a malformed non-UTF-8 key.

Affected products

Remediation

Red Hat statement

This vulnerability is rated Low for Red Hat as it requires a local attacker to provide a crafted deb822 file to trigger a NULL pointer dereference in `python-apt`, leading to a denial of service (process crash). Red Hat products that utilize `python-apt` and process untrusted deb822 files may be affected.

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Metrics

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner canonical
Published Dec 5, 2025
Updated Dec 15, 2025
Reserved Jul 1, 2025
CISA Vulnrichment
Updated Dec 5, 2025
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Dec 5, 2025