Bug 2427832
| Summary: | CVE-2026-22184 zsync: zlib: Arbitrary code execution via buffer overflow in untgz utility [fedora-43] | ||
|---|---|---|---|
| Product: | [Fedora] Fedora | Reporter: | Sandipan Roy <saroy> |
| Component: | zsync | Assignee: | Tobi <t-fedora> |
| Status: | CLOSED NOTABUG | QA Contact: | |
| Severity: | high | Docs Contact: | |
| Priority: | high | ||
| Version: | 43 | CC: | t-fedora |
| Target Milestone: | --- | Keywords: | Security, SecurityTracking |
| Target Release: | --- | ||
| Hardware: | Unspecified | ||
| OS: | Unspecified | ||
| Whiteboard: | {"flaws": ["22c8540b-4d7b-47e6-940f-04ad54ca4373"]} | ||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2026-01-08 12:56:20 UTC | Type: | --- |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | |||
| Bug Blocks: | 2427688 | ||
|
Description
Sandipan Roy
2026-01-08 06:55:54 UTC
the zlib fork that's part of zsync does not ship the untgz binary, nor any of its source files. there is no reference to TGZfname in the source at all. so this cve is not applicable. |