CVE-2026-27171

zlib before 1.3.2 allows CPU consumption via crc32_combine64 and crc32_combine_gen64 because x2nmodp can do right shifts within a loop that has no termination condition.
Configurations

Configuration 1 (hide)

cpe:2.3:a:zlib:zlib:*:*:*:*:*:*:*:*

History

20 Feb 2026, 16:45

Type Values Removed Values Added
First Time Zlib
Zlib zlib
CPE cpe:2.3:a:zlib:zlib:*:*:*:*:*:*:*:*
References () https://7asecurity.com/blog/2026/02/zlib-7asecurity-audit/ - () https://7asecurity.com/blog/2026/02/zlib-7asecurity-audit/ - Product
References () https://7asecurity.com/reports/pentest-report-zlib-RC1.1.pdf - () https://7asecurity.com/reports/pentest-report-zlib-RC1.1.pdf - Technical Description
References () https://github.com/madler/zlib/issues/904 - () https://github.com/madler/zlib/issues/904 - Issue Tracking, Exploit
References () https://github.com/madler/zlib/releases/tag/v1.3.2 - () https://github.com/madler/zlib/releases/tag/v1.3.2 - Release Notes
References () https://ostif.org/zlib-audit-complete/ - () https://ostif.org/zlib-audit-complete/ - Product

18 Feb 2026, 14:16

Type Values Removed Values Added
Summary
  • (es) zlib anterior a 1.3.2 permite el consumo de CPU a través de crc32_combine64 y crc32_combine_gen64 porque x2nmodp puede realizar desplazamientos a la derecha dentro de un bucle que no tiene condición de terminación.
References () https://7asecurity.com/reports/pentest-report-zlib-RC1.1.pdf - () https://7asecurity.com/reports/pentest-report-zlib-RC1.1.pdf -

18 Feb 2026, 04:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-18 04:16

Updated : 2026-02-20 16:45


NVD link : CVE-2026-27171

Mitre link : CVE-2026-27171

CVE.ORG link : CVE-2026-27171


JSON object : View

Products Affected

zlib

  • zlib
CWE
CWE-1284

Improper Validation of Specified Quantity in Input