CVE-2026-3381: Compress::Raw::Zlib versions through 2.219 for Perl use potentially insecure versions of zlib

Overview

Severity
Critical (CVSS 9.8)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploit Status
Not Exploited
Patch Tuesday
2026-Mar
Released
2026-03-07
Last Updated
2026-03-26
EPSS Score
0.55% (percentile: 44.1%)

Affected Products (14)

Open Source Software

  • cbl2 cloud-hypervisor 32.0-7 on CBL Mariner 2.0
  • cbl2 cloud-hypervisor-cvm 38.0.72.2-5 on CBL Mariner 2.0
  • cbl2 conda 4.11.0-1 on CBL Mariner 2.0
  • cbl2 erlang 25.3.2.21-4 on CBL Mariner 2.0
  • azl3 cloud-hypervisor 48.0.246-3 on Azure Linux 3.0
  • azl3 erlang 26.2.5.17-1 on Azure Linux 3.0
  • azl3 kata-containers 3.19.1.kata2-6 on Azure Linux 3.0
  • cbl2 rubygem-mini_portile2 2.8.0-1 on CBL Mariner 2.0
  • cbl2 rust 1.72.0-14 on CBL Mariner 2.0
  • azl3 rubygem-mini_portile2 2.8.4-1 on Azure Linux 3.0

Mariner

  • cbl2 tcl 8.6.13-3 on CBL Mariner 2.0
  • cbl2 zlib 1.2.13-2 on CBL Mariner 2.0
  • azl3 tcl 8.6.13-3 on Azure Linux 3.0
  • azl3 zlib 1.3.1-1 on Azure Linux 3.0

Revision History

  • 2026-03-07: Information published.
  • 2026-03-11: Information published.
  • 2026-03-14: Information published.
  • 2026-03-17: Information published.
  • 2026-03-17: Information published.
  • 2026-03-23: Information published.
  • 2026-03-23: Information published.
  • 2026-03-26: Information published.