Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-27820

Опубликовано: 16 апр. 2026
Источник: redhat
CVSS3: 5.6
EPSS Низкий

Описание

zlib is a Ruby interface for the zlib compression/decompression library. Versions 3.0.0 and below, 3.1.0, 3.1.1, 3.2.0 and 3.2.1 contain a buffer overflow vulnerability in the Zlib::GzipReader. The zstream_buffer_ungets function prepends caller-provided bytes ahead of previously produced output but fails to guarantee the backing Ruby string has enough capacity before the memmove shifts the existing data. This can lead to memory corruption when the buffer length exceeds capacity. This issue has been fixed in versions 3.0.1, 3.1.2 and 3.2.3.

A flaw was found in zlib, a Ruby interface for the zlib compression/decompression library. The Zlib::GzipReader component contains a buffer overflow vulnerability. This occurs because the zstream_buffer_ungets function does not ensure sufficient memory capacity before moving existing data, which can lead to memory corruption. An attacker could potentially exploit this to cause unexpected behavior or system instability.

Отчет

A buffer overflow vulnerability exists in the Zlib::GzipReader component of the Ruby zlib interface. This flaw, caused by insufficient memory capacity during data manipulation, could lead to memory corruption and system instability. This vulnerability is considered of a Moderate severity this happens because the high complexity to exploit, additionally the attacker may have not full control over the data is being corrupted or exfiltrated.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10rubyFix deferred
Red Hat Enterprise Linux 10ruby4.0Fix deferred
Red Hat Enterprise Linux 6rubyFix deferred
Red Hat Enterprise Linux 7rubyFix deferred
Red Hat Enterprise Linux 8rubyFix deferred
Red Hat Enterprise Linux 9rubyFix deferred
Red Hat Enterprise Linux 9ruby:3.3/rubyFix deferred
Red Hat Enterprise Linux 9ruby:4.0/rubyFix deferred
Red Hat Hardened Imagesruby3-3-main-3.3.10-23.1.hum1FixedRHSA-2026:730509.04.2026
Red Hat Hardened Imagesruby3-4-main-3.4.8-31.1.hum1FixedRHSA-2026:730709.04.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-131
https://bugzilla.redhat.com/show_bug.cgi?id=2459002zlib: zlib: Memory corruption via buffer overflow in Zlib::GzipReader

EPSS

Процентиль: 43%
0.00561
Низкий

5.6 Medium

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
4 месяца назад

zlib is a Ruby interface for the zlib compression/decompression library. Versions 3.0.0 and below, 3.1.0, 3.1.1, 3.2.0 and 3.2.1 contain a buffer overflow vulnerability in the Zlib::GzipReader. The zstream_buffer_ungets function prepends caller-provided bytes ahead of previously produced output but fails to guarantee the backing Ruby string has enough capacity before the memmove shifts the existing data. This can lead to memory corruption when the buffer length exceeds capacity. This issue has been fixed in versions 3.0.1, 3.1.2 and 3.2.3.

CVSS3: 9.8
nvd
4 месяца назад

zlib is a Ruby interface for the zlib compression/decompression library. Versions 3.0.0 and below, 3.1.0, 3.1.1, 3.2.0 and 3.2.1 contain a buffer overflow vulnerability in the Zlib::GzipReader. The zstream_buffer_ungets function prepends caller-provided bytes ahead of previously produced output but fails to guarantee the backing Ruby string has enough capacity before the memmove shifts the existing data. This can lead to memory corruption when the buffer length exceeds capacity. This issue has been fixed in versions 3.0.1, 3.1.2 and 3.2.3.

msrc
4 месяца назад

zlib: Buffer Overflow in Zlib::GzipReader ungetc via large input leads to memory corruption

CVSS3: 9.8
debian
4 месяца назад

zlib is a Ruby interface for the zlib compression/decompression librar ...

CVSS3: 9.8
github
4 месяца назад

Buffer Overflow in Zlib::GzipReader ungetc via large input leads to memory corruption

EPSS

Процентиль: 43%
0.00561
Низкий

5.6 Medium

CVSS3