dpkg (1.22.21) unstable; urgency=medium
[ Guillem Jover ]
* dpkg-deb: Fix cleanup for control member with restricted directories.
Fixes CVE-2025-6297. Reported by zhutyra on HackerOne.
* Perl modules:
- Dpkg::BuildDriver::DebianRules: Fix uninitialized Perl variables.
Closes: #1107971
- Dpkg::BuildDriver::DebianRules: Fix R³ dpkg/target/<target> values
handling.
- Dpkg::BuildTree: Fix needs_root() for R³ with implementation specific
keywords. See #
1107971.
* Code internals:
- libdpkg: Do not segfault when adding triggers in no-act mode.
Closes: #1108192
[dgit import package dpkg 1.22.21]