logo

CVE-2026-22184 (CVSS 9.3): Critical zlib Flaw Opens Door to Global Buffer Overflow

ID: 5b77edff-bffe-5a6f-a1b2-34ab9262920f

STIX ID: report--5b77edff-bffe-5a6f-a1b2-34ab9262920f

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-01-12

Date Updated: 2026-04-23

Author: Ddos

...
...

Critical buffer-overflow vulnerability (CVE-2026-22184) has been disclosed in zlib's untgz utility: an unbounded strcpy in TGZfname() copies a command-line archive name into a fixed 1024-byte global buffer, allowing out-of-bounds writes that can cause crashes or, depending on environment, remote code execution; the flaw is trivially reachable via a long filename argument and affects zlib versions up to 1.3.1.2 (CVSS 9.3).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.