Dpkg in xenial-proposed now depends on libzstd, but it has open CVEs: https://ubuntu.com/security/cve?q=&package=libzstd
As I understand dpkg is not affected because it does not use the zstd command and does not implement compression. To not introduce CVE-2021-24031 and CVE-2021-24032 the zstd binary package could be kept in universe like in later releases. ** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2021-24031 ** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2021-24032 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1755310 Title: MIR libzstd To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/libzstd/+bug/1755310/+subscriptions -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs