#1144105 ostree: GHSA-7cgc-gp99-6jmm: resource exhaustion via LZMA decoding

Package:
libostree-1-1
Source:
libostree-1-1
Description:
content-addressed filesystem for operating system binaries (library)
Submitter:
Simon McVittie
Date:
2026-08-21 00:07:01 UTC
Severity:
normal
Tags:
#1144105#5
Date:
2026-08-11 09:10:27 UTC
From:
To:
https://github.com/ostreedev/ostree/security/advisories/GHSA-7cgc-gp99-6jmm

A vulnerability in libostree allows the operator of a malicious or
compromised OSTree repository to serve crafted static delta content that
causes clients to exhaust memory and disk space during `ostree pull`.
All versions ever shipped by Debian appear to be affected. There is
currently no known CVE ID.

A mitigation is that if an OSTree repository is malicious or
compromised, its operator can also do worse things, like inserting
malicious OS images, or Flatpak apps with malicious metadata; so resource
exhaustion is perhaps not a particularly exciting vulnerability.

I would very much appreciate it if someone else could take
responsibility for identifying the specific fixes and preparing a
backport to Debian 13.

Thanks,
    smcv

#1144105#12
Date:
2026-08-11 09:44:06 UTC
From:
To:
Thanks for the bug report, I can take care of that (also for ##1144106
/ GHSA-xppc-j946-vcj7).

Berto

#1144105#17
Date:
2026-08-12 15:26:03 UTC
From:
To:
The current fix for this bug is causing regressions, so let's wait a
bit until they are resolved:

https://github.com/ostreedev/ostree/issues/3635

Berto

#1144105#22
Date:
2026-08-20 23:59:56 UTC
From:
To:
Control: reopen -1 2026.4-1

One of the changes made to address this was reverted, fixing the
regression but also reopening the resource-exhaustion issue.

     smcv