VYPR
Unrated severityOSV Advisory· Published Jan 7, 2026· Updated Mar 5, 2026

zlib <= 1.3.1.2 untgz Global Buffer Overflow in TGZfname()

CVE-2026-22184

Description

zlib versions up to and including 1.3.1.2 include a global buffer overflow in the untgz utility located under contrib/untgz. The vulnerability is limited to the standalone demonstration utility and does not affect the core zlib compression library. The flaw occurs when a user executes the untgz command with an excessively long archive name supplied via the command line, leading to an out-of-bounds write in a fixed-size global buffer.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

6

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.