yocto ▾
›
scarthgap ▾
›
vulnerability
›
CVE-2026-27171
Component Overview
Vulnerability Overview
Name
CVE-2026-27171
Source
NVD (
link
)
Debian (
link
)
Description
zlib before 1.3.2 allows CPU consumption via crc32_combine64 and crc32_combine_gen64 because x2nmodp can do right shifts within a loop that has no termination condition.
CWEs
CWE-1284
Published Date
Feb 18, 2026
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://7asecurity.com/blog/2026/02/zlib-7asecurity-audit/
Product
https://7asecurity.com/reports/pentest-report-zlib-RC1.1.pdf
Technical Description
https://github.com/madler/zlib/issues/904
Exploit
https://github.com/madler/zlib/releases/tag/v1.3.2
Release Notes
https://ostif.org/zlib-audit-complete/
Product
https://7asecurity.com/reports/pentest-report-zlib-RC1.1.pdf
Technical Description
Analysis
#
Affected Component
Analysis
zlib
Patched
Vulnerability Ratings
#
2.9
CVSSv31
5.5
CVSSv31
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
libzlib
buildroot
2025.02.x
1.3.2
Not Affected
libzlib
buildroot
master
1.3.2
Not Affected
zlib
openwrt
master
1.3.2-r1
Not Affected
zlib
openwrt
openwrt-25.12
1.3.1-r1
Exploitable
zlib
yocto
kirkstone
1.2.11
Not Affected
zlib
yocto
master
1.3.2
Not Affected
Resolved with patches
#
zlib (yocto:scarthgap)
#
Title
Author
Resolve
1
Check for negative lengths in crc32_combine functions.
Mark Adler <git@madler.net>
CVE-2026-27171