Impact
The zlib library, in releases from 1.2.11 through 1.3.2, contains a heap buffer overflow that is triggered after an attempted write operation fails. When the underlying write returns an error, the gz_write function does not reset the stream’s next_in pointer, leaving it pointing to the caller’s buffer. Subsequent gz* calls then compute a cache position from this stale pointer and write past the allocated heap space. The flaw is categorized as CWE-787, indicating an uncontrolled write to a buffer.
Affected Systems
The affected product is the zlib compression library itself. All releases from 1.2.11 up to and including 1.3.2 contain the vulnerability. Any application that links against these versions and performs GZIP or ZIP compression or decompression may be impacted. Versions newer than 1.3.2, or forks that have applied the patch, are not affected.
Risk and Exploitability
The vulnerability has a CVSS score of 8.3, denoting high severity, and an EPSS score of less than 1%, indicating a low frequency of exploitation at present. It is not listed in the CISA KEV catalog. An attacker can induce a write failure by sending malformed input or abruptly terminating a socket connection to a process using the library. If the attacker can control the payload after the failure, the overflow could lead to arbitrary code execution, denial of service, or a crash of the affected process. The exact threat depends on how the library is integrated and the presence of runtime memory protection measures.
OpenCVE Enrichment
Github GHSA