|
|
Log in / Subscribe / Register

Ubuntu alert USN-8706-1 (zlib)

From:  noreply+usn-bot--- via ubuntu-security-announce <ubuntu-security-announce@lists.ubuntu.com>
To:  ubuntu-security-announce@lists.ubuntu.com
Subject:  [USN-8706-1] zlib vulnerability
Date:  Tue, 01 Sep 2026 07:28:04 +0000
Message-ID:  <E1x1Iua-0004vn-MZ@lists.ubuntu.com>
Cc:  noreply+usn-bot@canonical.com

========================================================================== Ubuntu Security Notice USN-8706-1 August 31, 2026 zlib vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 24.04 LTS Summary: zlib could be made to consume excessive CPU resources if it received specially crafted input. Software Description: - zlib: Lossless data-compression library Details: It was discovered that zlib incorrectly handled negative length parameters in CRC32 combine functions. An attacker could use this issue to cause a denial of service via excessive CPU consumption. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS lib32z1 1:1.3.dfsg+really1.3.1-1ubuntu3.1 lib32z1-dev 1:1.3.dfsg+really1.3.1-1ubuntu3.1 lib64z1 1:1.3.dfsg+really1.3.1-1ubuntu3.1 lib64z1-dev 1:1.3.dfsg+really1.3.1-1ubuntu3.1 libminizip-dev 1:1.3.dfsg+really1.3.1-1ubuntu3.1 libminizip1t64 1:1.3.dfsg+really1.3.1-1ubuntu3.1 libx32z1 1:1.3.dfsg+really1.3.1-1ubuntu3.1 libx32z1-dev 1:1.3.dfsg+really1.3.1-1ubuntu3.1 minizip 1:1.3.dfsg+really1.3.1-1ubuntu3.1 zlib1g 1:1.3.dfsg+really1.3.1-1ubuntu3.1 zlib1g-dev 1:1.3.dfsg+really1.3.1-1ubuntu3.1 Ubuntu 24.04 LTS lib32z1 1:1.3.dfsg-3.1ubuntu2.2 lib32z1-dev 1:1.3.dfsg-3.1ubuntu2.2 lib64z1 1:1.3.dfsg-3.1ubuntu2.2 lib64z1-dev 1:1.3.dfsg-3.1ubuntu2.2 libminizip-dev 1:1.3.dfsg-3.1ubuntu2.2 libminizip1t64 1:1.3.dfsg-3.1ubuntu2.2 libx32z1 1:1.3.dfsg-3.1ubuntu2.2 libx32z1-dev 1:1.3.dfsg-3.1ubuntu2.2 minizip 1:1.3.dfsg-3.1ubuntu2.2 zlib1g 1:1.3.dfsg-3.1ubuntu2.2 zlib1g-dev 1:1.3.dfsg-3.1ubuntu2.2 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8706-1 CVE-2026-27171 Package Information: https://launchpad.net/ubuntu/+source/zlib/1:1.3.dfsg+real... https://launchpad.net/ubuntu/+source/zlib/1:1.3.dfsg-3.1u...


Attachment: signature.asc (type=application/pgp-signature)

-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+8neBLO2Hp/ppPlOcpJm3tlzhgEFAmqWfmgACgkQcpJm3tlz hgG41Q/7BLt8C/7RfvUqqTSxHhXcE25XtG330jVZhNL1Paka0qxzeWj8MBtj4Tn0 YKcDtZ+Y1gfAbR8/rbeKTiTNKyVmbCzqXbv6hWWINGujhdyNLlZVZw/AtJMtd7Tp mgb2eUxVJpI/Uvd9vvXTIejJTiGJrcTFooVxp+VgAfFMDxWBgyxZMhf5iq6ER4XK co52KK9BPrGpFXDGm77A4Tuw1n1s5Zs0pJfAXvS7Tw8Yoj6AOfTXPRSzoPJnQDeV jGONDLd7628/jG9TcwbfVtw5FeP5DL6wnciC3QTGlt58d1W8sisUNycQKjkf2KO6 yXMSCUTQOB/ktIUOHZReEGdRZPNhsmVaPztq4JmRjB/eu3SQ5n0BWtu10B4S8zR+ 0xXb9R3SiUSBPTBwa1bBpGC+yCpLTfSxAoRc5y2mTQ6ijkbjXFSUfP+/yYJpTQYe 3V0u+JSqq+cSVNGAVtUwM55xhSP967q24Ix8uTJUFw9VGOhJdnXlfpP3MpQLoTTv zb32Eg+A9VDzphZ9TEZ7Fe4NtNcV32jTJp64oeTNPtHCcTVac3bpK76dIwdJi+k1 dTis/eySFVW4AbT+WCTg6RBpgS27d2GyUkmXFCAVHzPqEKtIn2tWppbf7rVkvK4i jYJeHzVHTDFsvnKr/4ALrWOcPbrolojVKDRJpNk3m9uOOzmlK2M= =VY52 -----END PGP SIGNATURE-----


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds