Buffer overflow in zlib - CVE-2026-27820
Published: April 21, 2026 / Updated: April 21, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause memory corruption.
The vulnerability exists due to buffer overflow in zstream_buffer_ungets() function when parsing input within the Zlib::GzipReader. A remote attacker can provide crafted input that causes the buffer length to exceed its capacity to cause memory corruption.
User interaction is required.
Affected software
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
Basesystem Module
ruby2.5-debuginfo
ruby2.5
libruby2_5-2_5
ruby2.5-debugsource
ruby2.5-devel
ruby2.5-devel-extra
libruby2_5-2_5-debuginfo
ruby2.5-stdlib
ruby2.5-stdlib-debuginfo
How to mitigate CVE-2026-27820
ruby2.5-debuginfo - update to 2.5.9-150700.24.6.1
ruby2.5 - update to 2.5.9-150700.24.6.1
libruby2_5-2_5 - update to 2.5.9-150700.24.6.1
ruby2.5-debugsource - update to 2.5.9-150700.24.6.1
ruby2.5-devel - update to 2.5.9-150700.24.6.1
ruby2.5-devel-extra - update to 2.5.9-150700.24.6.1
libruby2_5-2_5-debuginfo - update to 2.5.9-150700.24.6.1
ruby2.5-stdlib - update to 2.5.9-150700.24.6.1
ruby2.5-stdlib-debuginfo - update to 2.5.9-150700.24.6.1