Resource exhaustion in Zlib - CVE-2026-27171

 

Resource exhaustion in Zlib - CVE-2026-27171

Published: March 11, 2026


Vulnerability identifier: #VU123895
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-27171
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to application does not properly control consumption of internal resources. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.


Affected software

Zlib
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Micro
IBM i
Basesystem Module
Development Tools Module
openSUSE Leap
Anolis OS
openEuler
LANTIME Operating System Firmware (LTOS)
minizip
minizip-devel
zlib
zlib-help
zlib-devel
zlib-debugsource
zlib-debuginfo
zlib-doc
zlib-static
minizip-compat-devel
minizip-compat
zlib-devel-static
zlib-devel-static-32bit
libminizip1-debuginfo
libminizip1
zlib-testsuite
libz1
libz1-debuginfo
libz1-32bit-debuginfo
libz1-32bit
libminizip1-32bit-debuginfo
libminizip1-32bit
libminizip1-64bit-debuginfo
libz1-64bit
libz1-64bit-debuginfo
zlib-devel-64bit
zlib-devel-static-64bit
libminizip1-64bit
zlib-testsuite-debuginfo
zlib-devel-32bit
perl-Compress-Raw-Zlib-tests
perl-Compress-Raw-Zlib
perl-Compress-Raw-Zlib-doc
EntireX

How to mitigate CVE-2026-27171

Install updates from vendor's website.

Zlib - update to 1.3.2
LANTIME Operating System Firmware (LTOS) - update to 7.10.009
minizip - update to 1.2.13-5
minizip-devel - update to 1.2.13-5
zlib - update to 1.2.13-5
zlib-help - update to 1.2.13-5
zlib-devel - update to 1.2.13-5
zlib-debugsource - update to 1.2.13-5
zlib-debuginfo - update to 1.2.13-5
zlib-doc - update to 1.2.13-5
zlib-static - update to 1.2.13-5
zlib-devel - update to 1.2.13-5
zlib - update to 1.2.13-5
minizip-compat-devel - update to 1.2.13-5
minizip-compat - update to 1.2.13-5
zlib-devel-static - update to 1.2.13-150500.4.6.1
zlib-devel-static-32bit - update to 1.2.13-150500.4.6.1
libminizip1-debuginfo - update to 1.2.13-150500.4.6.1
libminizip1 - update to 1.2.13-150500.4.6.1
zlib-devel - update to 1.2.13-150500.4.6.1
zlib-testsuite - update to 1.2.13-150500.4.6.1
libz1 - update to 1.2.13-150500.4.6.1
zlib-debugsource - update to 1.2.13-150500.4.6.1
libz1-debuginfo - update to 1.2.13-150500.4.6.1
minizip-devel - update to 1.2.13-150500.4.6.1
libz1-32bit-debuginfo - update to 1.2.13-150500.4.6.1
libz1-32bit - update to 1.2.13-150500.4.6.1
libminizip1-32bit-debuginfo - update to 1.2.13-150500.4.6.1
libminizip1-32bit - update to 1.2.13-150500.4.6.1
libminizip1-64bit-debuginfo - update to 1.2.13-150500.4.6.1
libz1-64bit - update to 1.2.13-150500.4.6.1
libz1-64bit-debuginfo - update to 1.2.13-150500.4.6.1
zlib-devel-64bit - update to 1.2.13-150500.4.6.1
zlib-devel-static-64bit - update to 1.2.13-150500.4.6.1
libminizip1-64bit - update to 1.2.13-150500.4.6.1
zlib-testsuite-debuginfo - update to 1.2.13-150500.4.6.1
zlib-devel-32bit - update to 1.2.13-150500.4.6.1
perl-Compress-Raw-Zlib-tests - update to 2.222-1
perl-Compress-Raw-Zlib - update to 2.222-1
perl-Compress-Raw-Zlib-doc - update to 2.222-1
EntireX - update to 11.1 Broker Fix13

External References

Related Security Bulletins