PT-2026-90898 · Azure Linux · Cloud Hypervisor

Published

2026-09-03

·

Updated

2026-09-03

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
zlib versions 1.3.1.2 through 1.3.2 contain a heap buffer overflow vulnerability in the gz vacate() function when processing non-blocking gzwrite() operations with stale external buffer pointers. Attackers can trigger the overflow by calling gzprintf() or gzvprintf() after a write stall, causing an unchecked memmove() to write beyond the internal input buffer boundary.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-99174

Affected Products

Cloud Hypervisor