#1146895 zlib: CVE-2026-85091

Package:
src:zlib
Source:
src:zlib
Submitter:
Salvatore Bonaccorso
Date:
2026-10-05 04:47:02 UTC
Severity:
normal
Tags:
#1146895#5
Date:
2026-09-06 19:02:48 UTC
From:
To:
Hi,

The following vulnerability was published for zlib.

CVE-2026-85091[0]:
| zlib versions 1.3.1.2 through 1.3.2 contain a heap buffer overflow
| vulnerability in the gz_vacate() function when processing non-
| blocking gzwrite() operations with stale external buffer pointers.
| Attackers can trigger the overflow by calling gzprintf() or
| gzvprintf() after a write stall, causing an unchecked memmove() to
| write beyond the internal input buffer boundary.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-85091
https://www.cve.org/CVERecord?id=CVE-2026-85091
[1] https://gist.github.com/thesmartshadow/e0b9481792afb7c31e86fee1ff084490
[2] https://github.com/madler/zlib/commit/e3dc0a85b7032e98380dec011bc8f2c2ee0d8fca

Regards,
Salvatore

#1146895#10
Date:
2026-09-06 19:21:59 UTC
From:
To:
Hi,

FWIW, [2] might not be correct, can you check with upstream?

Regards,
Salvatore

#1146895#17
Date:
2026-09-11 16:22:16 UTC
From:
To:
(Sorry Claude wrote this, but if true thought it be helpful for ya'll,
thanks. CVEs this year have been insane!)

Hi,

CVE-2026-85091 is the heap overflow in gz_vacate() (gzwrite.c), reached
through gzprintf()/gzvprintf() after a non-blocking write stall. The
advisory (GHSA-g5fp-32jq-cfw2) gives the affected range as 1.3.1.2
through 1.3.2, and the upstream history agrees:

- gz_vacate() and the non-blocking handling in the gz* routines were
  introduced in upstream commit 81cc0bebedd935daeb81b0b6e475d8786b51af3d
  ("Support non-blocking devices in the gz* routines.", 2025-05-25),
  after the v1.3.1 tag. v1.3.1.2 is the first tag that contains it and
  v1.3.2 (2026-02-17) the first release.
- gzwrite.c at v1.3.1 defines only gz_init, gz_comp, gz_zero and
  gz_write. There is no gz_vacate() and no stall handling: a short or
  failed write() is treated as a fatal Z_ERRNO.

The tracker currently lists trixie (1:1.3.dfsg+really1.3.1-1) and
bookworm (1:1.2.13.dfsg-1) as vulnerable. Both predate the vulnerable
code, so I believe they should be marked <not-affected> (vulnerable code
introduced in 1.3.2), leaving only 1:1.3.dfsg+really1.3.2-* in
forky/sid affected.

#1146895#22
Date:
2026-09-17 06:52:13 UTC
From:
To:
Hi Mark,

Attached is a proposed update for zlib in unstable with one related
patch cherry-picked and the upstream commited change for
CVE-2026-85091.

I tested the update as well against the published reporducers, and the
update would be tested as well on
https://debusine.debian.net/debian/developers/work-request/1293184/

Regards,
Salvatore

#1146895#27
Date:
2026-09-17 06:53:18 UTC
From:
To:
Hi,

And now attached for real :-(

Regards,
Salvatore

#1146895#36
Date:
2026-09-22 00:37:38 UTC
From:
To:
The CVE text limits the affected range to 1.3.1.2 through 1.3.2. That
range is too narrow. The overflow predates non-blocking write support:
I reproduced it under ASan on upstream 1.2.11 and 1.2.13 in both
gz_write() and gzvprintf(). The direct-path code involved dates from
1.2.3.5.

No write stall is needed to reach it. Any gz_comp() failure on the
direct path leaves the same state, so a descriptor opened read-only
reproduces it without sockets or timing.

Method and per-patch results are in my comment on the upstream issue:

https://github.com/madler/zlib/issues/1292#issuecomment-5562455575

Upstream fix, already noted in the tracker:


https://github.com/madler/zlib/commit/df84af25dc1942490e1d1c899a07619152a46148

The commit applies to the bookworm and trixie sources as well as sid,
so a backport of that single hunk covers all three.

Steve Antonakakis

#1146895#45
Date:
2026-10-02 10:46:20 UTC
From:
To:
Hello,

The tracker currently lists zlib as vulnerable to CVE-2026-85091 in
bookworm and trixie. As far as I can tell, neither release contains the
vulnerable code.

   - The CVE covers zlib 1.3.1.2 through 1.3.2. The vulnerable function
   gz_vacate() and the non-blocking write code came in with upstream commit
   81cc0be ("Support non-blocking devices in the gz* routines", 25 May 2025).
   That commit is in v1.3.1.2 but not in v1.3.1.
   - trixie (1:1.3.dfsg+really1.3.1-1) ships upstream 1.3.1 with no Debian
   patches. Its gzwrite.c has no gz_vacate().
https://sources.debian.org/src/zlib/1:1.3.dfsg+really1.3.1-1/gzwrite.c/
   - bookworm (1:1.2.13.dfsg-1) predates the commit as well.
   - forky/sid (1:1.3.dfsg+really1.3.2-3) does contain the code (gz_vacate()
   at line 382), so it remains affected:
https://sources.debian.org/src/zlib/1:1.3.dfsg+really1.3.2-3/gzwrite.c/

Upstream discussion: https://github.com/madler/zlib/issues/1310

If the analysis above is correct, could you please mark bookworm and trixie
as not-affected?
Thank you,
Dimitris

#1146895#50
Date:
2026-10-05 04:46:22 UTC
From:
To:
Hi,

No, we won't mark it yet as such. The reasons are explained in
https://github.com/madler/zlib/issues/1310#issuecomment-5979623265 ,
https://github.com/madler/zlib/issues/1292#issuecomment-5562455575 and
https://bugs.debian.org/1146895#36 .

So it will depends if upstream will consider this a separate issue or
in scope of the assignment.

Regards,
Salvatore