https://github.com/ostreedev/ostree/security/advisories/GHSA-7cgc-gp99-6jmm
A vulnerability in libostree allows the operator of a malicious or
compromised OSTree repository to serve crafted static delta content that
causes clients to exhaust memory and disk space during `ostree pull`.
All versions ever shipped by Debian appear to be affected. There is
currently no known CVE ID.
A mitigation is that if an OSTree repository is malicious or
compromised, its operator can also do worse things, like inserting
malicious OS images, or Flatpak apps with malicious metadata; so resource
exhaustion is perhaps not a particularly exciting vulnerability.
I would very much appreciate it if someone else could take
responsibility for identifying the specific fixes and preparing a
backport to Debian 13.
Thanks,
smcv