CVE-2026-85091

NameCVE-2026-85091
Descriptionzlib versions 1.3.1.2 through 1.3.2 contain a heap buffer overflow vulnerability in the gz_vacate() function when processing non-blocking gzwrite() operations with stale external buffer pointers. Attackers can trigger the overflow by calling gzprintf() or gzvprintf() after a write stall, causing an unchecked memmove() to write beyond the internal input buffer boundary.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
zlib (PTS)bookworm1:1.2.13.dfsg-1vulnerable
trixie1:1.3.dfsg+really1.3.1-1vulnerable
forky, sid1:1.3.dfsg+really1.3.2-3vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
zlibsource(unstable)(unfixed)

Notes

https://gist.github.com/thesmartshadow/e0b9481792afb7c31e86fee1ff084490
https://github.com/madler/zlib/commit/e3dc0a85b7032e98380dec011bc8f2c2ee0d8fca
check details

Search for package or bug name: Reporting problems