CVE-2026-27171: Medium severity zlib vulnerability
Last updated 1 September 2026
Other sources
zlib before 1.3.2 allows CPU consumption via crc32combine64 and crc32combinegen64 because x2nmodp can do right shifts within a loop that has no termination condition.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/zlibto a version that resolves this vulnerability.Fixed in 1:1.3.dfsg+really1.3.2-3 - Upgrade
Upgrade
zlibto a version that resolves this vulnerability.Fixed in 1.3.2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-27171?
CVE-2026-27171 is classified with a high severity due to its potential to cause significant CPU consumption.
How do I fix CVE-2026-27171?
To fix CVE-2026-27171, you should upgrade to zlib version 1.3.2 or later.
What systems are affected by CVE-2026-27171?
CVE-2026-27171 affects all versions of zlib prior to version 1.3.2.
What type of vulnerability is CVE-2026-27171?
CVE-2026-27171 is a denial-of-service vulnerability that can lead to excessive CPU usage.
Is there a workaround for CVE-2026-27171?
There are no known effective workarounds for CVE-2026-27171, and updating zlib is recommended.