-
Notifications
You must be signed in to change notification settings - Fork 49
update: zlib #2062
Copy link
Copy link
Open
Labels
advisorysecurity advisorysecurity advisorycvss/LOW< 4 assessed CVSS< 4 assessed CVSSsecuritysecurity concernssecurity concerns
Metadata
Metadata
Assignees
Labels
advisorysecurity advisorysecurity advisorycvss/LOW< 4 assessed CVSS< 4 assessed CVSSsecuritysecurity concernssecurity concerns
Type
Projects
Status
🪵Backlog
Name: zlib
CVEs: CVE-2026-27171
CVSSs: 2.9
Action Needed: update to >= 1.3.2
Summary: zlib before 1.3.2 allows CPU consumption via crc32_combine64 and crc32_combine_gen64 because x2nmodp can do right shifts within a loop that has no termination condition.
See also https://bugzilla.redhat.com/show_bug.cgi?id=2440530, madler/zlib#904.
refmap.gentoo: https://bugs.gentoo.org/970211