Security Fix(es):
zlib before 1.3.2 allows CPU consumption via crc32combine64 and crc32combine_gen64 because x2nmodp can do right shifts within a loop that has no termination condition.(CVE-2026-27171)
{
"severity": "Medium"
}{
"aarch64": [
"minizip-1.2.13-5.oe2403sp2.aarch64.rpm",
"minizip-devel-1.2.13-5.oe2403sp2.aarch64.rpm",
"zlib-1.2.13-5.oe2403sp2.aarch64.rpm",
"zlib-debuginfo-1.2.13-5.oe2403sp2.aarch64.rpm",
"zlib-debugsource-1.2.13-5.oe2403sp2.aarch64.rpm",
"zlib-devel-1.2.13-5.oe2403sp2.aarch64.rpm"
],
"noarch": [
"zlib-help-1.2.13-5.oe2403sp2.noarch.rpm"
],
"src": [
"zlib-1.2.13-5.oe2403sp2.src.rpm"
],
"x86_64": [
"minizip-1.2.13-5.oe2403sp2.x86_64.rpm",
"minizip-devel-1.2.13-5.oe2403sp2.x86_64.rpm",
"zlib-1.2.13-5.oe2403sp2.x86_64.rpm",
"zlib-debuginfo-1.2.13-5.oe2403sp2.x86_64.rpm",
"zlib-debugsource-1.2.13-5.oe2403sp2.x86_64.rpm",
"zlib-devel-1.2.13-5.oe2403sp2.x86_64.rpm"
]
}