ELA-1596-1 python-apt security update

denial of service

2025-12-16
Packagepython-apt
Version1.4.4 (stretch), 1.8.4.4 (buster)
Related CVEs CVE-2025-6966


Julian Andres Klode discovered that python-apt, a Python interface to libapt-pkg, incorrectly handled deb822 configuration files. An attacker could use this issue to cause python-apt to crash, resulting in a denial of service.



For Debian 10 buster, these problems have been fixed in version 1.8.4.4.

For Debian 9 stretch, these problems have been fixed in version 1.4.4.

We recommend that you upgrade your python-apt packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.