Resource exhaustion in Zlib - CVE-2026-27171
Published: March 11, 2026
Vulnerability identifier: #VU123895
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-27171
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.
Affected software
Zlib
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Micro
IBM i
Basesystem Module
Development Tools Module
openSUSE Leap
Anolis OS
openEuler
LANTIME Operating System Firmware (LTOS)
minizip
minizip-devel
zlib
zlib-help
zlib-devel
zlib-debugsource
zlib-debuginfo
zlib-doc
zlib-static
minizip-compat-devel
minizip-compat
zlib-devel-static
zlib-devel-static-32bit
libminizip1-debuginfo
libminizip1
zlib-testsuite
libz1
libz1-debuginfo
libz1-32bit-debuginfo
libz1-32bit
libminizip1-32bit-debuginfo
libminizip1-32bit
libminizip1-64bit-debuginfo
libz1-64bit
libz1-64bit-debuginfo
zlib-devel-64bit
zlib-devel-static-64bit
libminizip1-64bit
zlib-testsuite-debuginfo
zlib-devel-32bit
perl-Compress-Raw-Zlib-tests
perl-Compress-Raw-Zlib
perl-Compress-Raw-Zlib-doc
EntireX
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Micro
IBM i
Basesystem Module
Development Tools Module
openSUSE Leap
Anolis OS
openEuler
LANTIME Operating System Firmware (LTOS)
minizip
minizip-devel
zlib
zlib-help
zlib-devel
zlib-debugsource
zlib-debuginfo
zlib-doc
zlib-static
minizip-compat-devel
minizip-compat
zlib-devel-static
zlib-devel-static-32bit
libminizip1-debuginfo
libminizip1
zlib-testsuite
libz1
libz1-debuginfo
libz1-32bit-debuginfo
libz1-32bit
libminizip1-32bit-debuginfo
libminizip1-32bit
libminizip1-64bit-debuginfo
libz1-64bit
libz1-64bit-debuginfo
zlib-devel-64bit
zlib-devel-static-64bit
libminizip1-64bit
zlib-testsuite-debuginfo
zlib-devel-32bit
perl-Compress-Raw-Zlib-tests
perl-Compress-Raw-Zlib
perl-Compress-Raw-Zlib-doc
EntireX
How to mitigate CVE-2026-27171
Install updates from vendor's website.
Zlib - update to 1.3.2
LANTIME Operating System Firmware (LTOS) - update to 7.10.009
minizip - update to 1.2.13-5
minizip-devel - update to 1.2.13-5
zlib - update to 1.2.13-5
zlib-help - update to 1.2.13-5
zlib-devel - update to 1.2.13-5
zlib-debugsource - update to 1.2.13-5
zlib-debuginfo - update to 1.2.13-5
zlib-doc - update to 1.2.13-5
zlib-static - update to 1.2.13-5
zlib-devel - update to 1.2.13-5
zlib - update to 1.2.13-5
minizip-compat-devel - update to 1.2.13-5
minizip-compat - update to 1.2.13-5
zlib-devel-static - update to 1.2.13-150500.4.6.1
zlib-devel-static-32bit - update to 1.2.13-150500.4.6.1
libminizip1-debuginfo - update to 1.2.13-150500.4.6.1
libminizip1 - update to 1.2.13-150500.4.6.1
zlib-devel - update to 1.2.13-150500.4.6.1
zlib-testsuite - update to 1.2.13-150500.4.6.1
libz1 - update to 1.2.13-150500.4.6.1
zlib-debugsource - update to 1.2.13-150500.4.6.1
libz1-debuginfo - update to 1.2.13-150500.4.6.1
minizip-devel - update to 1.2.13-150500.4.6.1
libz1-32bit-debuginfo - update to 1.2.13-150500.4.6.1
libz1-32bit - update to 1.2.13-150500.4.6.1
libminizip1-32bit-debuginfo - update to 1.2.13-150500.4.6.1
libminizip1-32bit - update to 1.2.13-150500.4.6.1
libminizip1-64bit-debuginfo - update to 1.2.13-150500.4.6.1
libz1-64bit - update to 1.2.13-150500.4.6.1
libz1-64bit-debuginfo - update to 1.2.13-150500.4.6.1
zlib-devel-64bit - update to 1.2.13-150500.4.6.1
zlib-devel-static-64bit - update to 1.2.13-150500.4.6.1
libminizip1-64bit - update to 1.2.13-150500.4.6.1
zlib-testsuite-debuginfo - update to 1.2.13-150500.4.6.1
zlib-devel-32bit - update to 1.2.13-150500.4.6.1
perl-Compress-Raw-Zlib-tests - update to 2.222-1
perl-Compress-Raw-Zlib - update to 2.222-1
perl-Compress-Raw-Zlib-doc - update to 2.222-1
EntireX - update to 11.1 Broker Fix13
LANTIME Operating System Firmware (LTOS) - update to 7.10.009
minizip - update to 1.2.13-5
minizip-devel - update to 1.2.13-5
zlib - update to 1.2.13-5
zlib-help - update to 1.2.13-5
zlib-devel - update to 1.2.13-5
zlib-debugsource - update to 1.2.13-5
zlib-debuginfo - update to 1.2.13-5
zlib-doc - update to 1.2.13-5
zlib-static - update to 1.2.13-5
zlib-devel - update to 1.2.13-5
zlib - update to 1.2.13-5
minizip-compat-devel - update to 1.2.13-5
minizip-compat - update to 1.2.13-5
zlib-devel-static - update to 1.2.13-150500.4.6.1
zlib-devel-static-32bit - update to 1.2.13-150500.4.6.1
libminizip1-debuginfo - update to 1.2.13-150500.4.6.1
libminizip1 - update to 1.2.13-150500.4.6.1
zlib-devel - update to 1.2.13-150500.4.6.1
zlib-testsuite - update to 1.2.13-150500.4.6.1
libz1 - update to 1.2.13-150500.4.6.1
zlib-debugsource - update to 1.2.13-150500.4.6.1
libz1-debuginfo - update to 1.2.13-150500.4.6.1
minizip-devel - update to 1.2.13-150500.4.6.1
libz1-32bit-debuginfo - update to 1.2.13-150500.4.6.1
libz1-32bit - update to 1.2.13-150500.4.6.1
libminizip1-32bit-debuginfo - update to 1.2.13-150500.4.6.1
libminizip1-32bit - update to 1.2.13-150500.4.6.1
libminizip1-64bit-debuginfo - update to 1.2.13-150500.4.6.1
libz1-64bit - update to 1.2.13-150500.4.6.1
libz1-64bit-debuginfo - update to 1.2.13-150500.4.6.1
zlib-devel-64bit - update to 1.2.13-150500.4.6.1
zlib-devel-static-64bit - update to 1.2.13-150500.4.6.1
libminizip1-64bit - update to 1.2.13-150500.4.6.1
zlib-testsuite-debuginfo - update to 1.2.13-150500.4.6.1
zlib-devel-32bit - update to 1.2.13-150500.4.6.1
perl-Compress-Raw-Zlib-tests - update to 2.222-1
perl-Compress-Raw-Zlib - update to 2.222-1
perl-Compress-Raw-Zlib-doc - update to 2.222-1
EntireX - update to 11.1 Broker Fix13
External References
- https://7asecurity.com/blog/2026/02/zlib-7asecurity-audit/
- https://7asecurity.com/reports/pentest-report-zlib-RC1.1.pdf
- https://github.com/madler/zlib/issues/904
- https://github.com/madler/zlib/releases/tag/v1.3.2
- https://ostif.org/zlib-audit-complete/
- https://github.com/madler/zlib/commit/ba829a458576d1ff0f26fc7230c6de816d1f6a77
Related Security Bulletins
- Multiple vulnerabilities in zlib
- SUSE update for zlib
- Anolis OS update for perl-Compress-Raw-Zlib
- openEuler 24.03 LTS SP3 update for zlib
- openEuler 24.03 LTS SP2 update for zlib
- openEuler 24.03 LTS SP1 update for zlib
- openEuler 24.03 LTS update for zlib
- Anolis OS update for zlib
- Meinberg LANTIME firmware update for third-party components
- IBM i update for zlib
- Multiple vulnerabilities in IBM EntireX