CVE-2026-22184 (CVSS 9.3): Critical zlib Flaw Opens Door to Global Buffer Overflow
ID: 5b77edff-bffe-5a6f-a1b2-34ab9262920f
STIX ID: report--5b77edff-bffe-5a6f-a1b2-34ab9262920f
Feed Name: securityonline.info
Threat Score
Critical buffer-overflow vulnerability (CVE-2026-22184) has been disclosed in zlib's untgz utility: an unbounded strcpy in TGZfname() copies a command-line archive name into a fixed 1024-byte global buffer, allowing out-of-bounds writes that can cause crashes or, depending on environment, remote code execution; the flaw is trivially reachable via a long filename argument and affects zlib versions up to 1.3.1.2 (CVSS 9.3).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
