CVE-2026-76844
zlib 1.2.11 through 1.3.2 Heap Buffer Overflow via Stale gzwrite Pointer After Failed Write
CVSS Score
7.4
EPSS Score
0.5%
EPSS Percentile
39th
zlib 1.2.11 through 1.3.2 contains a heap buffer overflow: after an underlying write() fails, gz_write() returns without resetting strm.next_in, leaving it pointed at the caller's buffer. A later gz* write call then derives a position from the stale pointer and writes past a heap allocation; any write() failure reaches it, including EPIPE on a blocking descriptor, and in versions before 1.3.1.2 the failed write must be followed by a gzclearerr() call.
| CWE | CWE-787 |
| Vendor | zlib |
| Product | zlib |
| Published | Aug 24, 2026 |
| Last Updated | Oct 1, 2026 |
Stay Ahead of the Next One
Get instant alerts for zlib zlib
Be the first to know when new high vulnerabilities affecting zlib zlib are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
High
Affected Versions
zlib / zlib
1.2.11 โค 1.3.2
References
gist.github.com: https://gist.github.com/thesmartshadow/e0b9481792afb7c31e86fee1ff084490 github.com: https://github.com/madler/zlib/commit/df84af25dc1942490e1d1c899a07619152a46148 github.com: https://github.com/madler/zlib/blob/v1.3.2/gzwrite.c#L393 github.com: https://github.com/madler/zlib vulncheck.com: https://www.vulncheck.com/advisories/zlib-1.3.1.2-through-1.3.2-heap-buffer-overflow-via-gz-vacate
Credits
Ali Firas (thesmartshadow) Michael Mullins