Bug 2452916 (CVE-2026-4176) - CVE-2026-4176 Perl: Compress::Raw::Zlib: zlib: Perl: Multiple vulnerabilities due to an outdated vendored zlib library
Summary: CVE-2026-4176 Perl: Compress::Raw::Zlib: zlib: Perl: Multiple vulnerabilities...
Keywords:
Status: NEW
Alias: CVE-2026-4176
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2453132
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-03-29 22:02 UTC by OSIDB Bzimport
Modified: 2026-03-30 21:57 UTC (History)
11 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-03-29 22:02:31 UTC
Perl versions from 5.9.4 before 5.40.4-RC1, from 5.41.0 before 5.42.2-RC1, from 5.43.0 before 5.43.9 contain a vulnerable version of Compress::Raw::Zlib.

Compress::Raw::Zlib is included in the Perl package as a dual-life core module, and is vulnerable to CVE-2026-3381 due to a vendored version of zlib which has several vulnerabilities, including CVE-2026-27171. The bundled Compress::Raw::Zlib was updated to version 2.221 in Perl blead commit c75ae9cc164205e1b6d6dbd57bd2c65c8593fe94.


Note You need to log in before you can comment on or make changes to this bug.