Bug 35291 - zlib new security issue CVE-2026-27171
Summary: zlib new security issue CVE-2026-27171
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 9
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA9-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2026-03-30 10:37 CEST by Nicolas Salguero
Modified: 2026-04-01 01:07 CEST (History)
2 users (show)

See Also:
Source RPM: zlib-1.2.13-1.3.mga9.src.rpm
CVE: CVE-2026-27171
Status comment:
j.alberto.vc: test_passed_mga9_64+


Attachments

Comment 1 Nicolas Salguero 2026-03-30 10:38:26 CEST
Fix: https://github.com/madler/zlib/commit/ba829a458576d1ff0f26fc7230c6de816d1f6a77

Source RPM: (none) => zlib-1.2.13-1.3.mga9.src.rpm
Status comment: (none) => Patch available from upstream
CVE: (none) => CVE-2026-27171

Comment 2 Nicolas Salguero 2026-03-30 10:53:20 CEST
Suggested advisory:
========================

The updated packages fix a security vulnerability:

zlib before 1.3.2 allows CPU consumption via crc32_combine64 and crc32_combine_gen64 because x2nmodp can do right shifts within a loop that has no termination condition. (CVE-2026-27171)

References:
https://bugzilla.redhat.com/show_bug.cgi?id=2440530
https://ubuntu.com/security/CVE-2026-27171
https://security-tracker.debian.org/tracker/CVE-2026-27171
========================

Updated packages in core/updates_testing:
========================
lib(64)minizip-devel-1.2.13-1.4.mga9
lib(64)minizip1-1.2.13-1.4.mga9
lib(64)zlib-devel-1.2.13-1.4.mga9
lib(64)zlib-static-devel-1.2.13-1.4.mga9
lib(64)zlib1-1.2.13-1.4.mga9

from SRPM:
zlib-1.2.13-1.4.mga9.src.rpm

Status: NEW => ASSIGNED
Status comment: Patch available from upstream => (none)
Assignee: bugsquad => qa-bugs

katnatek 2026-03-31 02:43:25 CEST

Keywords: (none) => advisory

Comment 3 katnatek 2026-03-31 03:41:45 CEST
RH x86_64

installing lib64minizip1-1.2.13-1.4.mga9.x86_64.rpm lib64zlib1-1.2.13-1.4.mga9.x86_64.rpm lib64zlib-devel-1.2.13-1.4.mga9.x86_64.rpm from //home/katnatek/qa-testing/x86_64
Preparing...                     ###################################################################################################
      1/3: lib64zlib1            ###################################################################################################
      2/3: lib64minizip1         ###################################################################################################
      3/3: lib64zlib-devel       ###################################################################################################
      1/3: removing lib64zlib-devel-1.2.13-1.3.mga9.x86_64
                                 ###################################################################################################
      2/3: removing lib64minizip1-1.2.13-1.3.mga9.x86_64
                                 ###################################################################################################
      3/3: removing lib64zlib1-1.2.13-1.3.mga9.x86_64
                                 ###################################################################################################

Repeat bug 34954 comment 3 test

strace smplayer shows
openat(AT_FDCWD, "/usr/lib64/libz.so.1", O_RDONLY|O_CLOEXEC) = 3

strace vlc
openat(AT_FDCWD, "/usr/lib64/libzstd.so.1", O_RDONLY|O_CLOEXEC) = 3

strace zapzap
openat(AT_FDCWD, "/usr/lib64/libminizip.so.1", O_RDONLY|O_CLOEXEC) = 3

The 3 works

Flags: (none) => test_passed_mga9_64+
Whiteboard: (none) => MGA9-64-OK

Comment 4 Thomas Andrews 2026-03-31 18:26:02 CEST
Validating.

Keywords: (none) => validated_update
CC: (none) => andrewsfarm, sysadmin-bugs

Comment 5 Mageia Robot 2026-04-01 01:07:43 CEST
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2026-0076.html

Resolution: (none) => FIXED
Status: ASSIGNED => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.