{"id":"AZL-105345","summary":"CVE-2026-76844 affecting package zlib 1.3.2-1","details":"zlib 1.2.11 through 1.3.2 contains a heap buffer overflow: after an underlying write() fails, gz_write() returns without resetting strm.next_in, leaving it pointed at the caller's buffer. A later gz* write call then derives a position from the stale pointer and writes past a heap allocation; any write() failure reaches it, including EPIPE on a blocking descriptor, and in versions before 1.3.1.2 the failed write must be followed by a gzclearerr() call.","modified":"2026-10-03T05:35:10Z","published":"2026-08-24T14:17:02Z","upstream":["CVE-2026-76844"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-76844"}],"affected":[{"package":{"name":"zlib","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/zlib"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"1.3.2-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-105345.json"}}],"schema_version":"1.9.0"}