AZL-105345

See a problem?
Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-105345.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-105345
Upstream
Published
2026-08-24T14:17:02Z
Modified
2026-10-03T05:35:10Z
Summary
CVE-2026-76844 affecting package zlib 1.3.2-1
Details

zlib 1.2.11 through 1.3.2 contains a heap buffer overflow: after an underlying write() fails, gz_write() returns without resetting strm.next_in, leaving it pointed at the caller's buffer. A later gz* write call then derives a position from the stale pointer and writes past a heap allocation; any write() failure reaches it, including EPIPE on a blocking descriptor, and in versions before 1.3.1.2 the failed write must be followed by a gzclearerr() call.

References

Affected packages

Azure Linux:3 / zlib

Package

Name
zlib
Purl
pkg:rpm/azure-linux/zlib

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
1.3.2-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-105345.json"