Bug 2539017 (CVE-2026-77301)

Summary: CVE-2026-77301 adm-zip: adm-zip: Denial of Service via uncontrolled memory allocation
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: abarbaro, akhatavk, alizardo, aos-team-art-private, asdas, dpaolell, dschmidt, gbenhaim, gmalinko, gparvin, janstey, jbalunas, jchui, jdelft, jhe, jlanda, jupierce, kshier, ktsao, lgarciaa, mbiarnes, nboldt, niyer, oaljalju, pdelbell, ppalepu, ppostler, prdhamdh, psrna, rhaigner, rhel-process-autobot, rstepani, sghai, sidsharm, simaishi, stcannon, suppawar, tsze, twaugh, vlaad, watson-tool-maintainers, yguenane
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in adm-zip, a JavaScript library for handling ZIP archives. The `getData()` function in `zipEntry.js` allocates memory based on the declared uncompressed size in a ZIP entry's central directory without validating this value against the actual compressed data. A remote attacker can exploit this by providing a specially crafted, small ZIP file that declares a multi-gigabyte uncompressed size. This can lead to excessive memory consumption, causing applications to terminate or suffer service-wide memory exhaustion, resulting in a Denial of Service (DoS).
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description OSIDB Bzimport 2026-09-22 21:58:30 UTC
adm-zip is a JavaScript library for creating and extracting ZIP archives in Node.js. Prior to 0.6.1, getData() in zipEntry.js trusts an entry's central-directory uncompressed size and allocates output memory before validating that value against the actual compressed data and decompression result. A small crafted ZIP can declare a multi-gigabyte uncompressed size, causing Buffer.alloc and decompression handling to commit excessive resident memory before CRC validation reports an error. Applications that read entries from untrusted archives can therefore be terminated by the operating system or suffer service-wide memory exhaustion. This issue is fixed in version 0.6.1.