CVE-2026-3381: Compress::Raw::Zlib versions through 2.219 for Perl use potentially insecure versions of zlib
Overview
- Severity
- Critical (CVSS 9.8)
- CVSS Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Exploit Status
- Not Exploited
- Patch Tuesday
- 2026-Mar
- Released
- 2026-03-07
- Last Updated
- 2026-03-26
- EPSS Score
- 0.55% (percentile: 44.1%)
Affected Products (14)
Open Source Software
- cbl2 cloud-hypervisor 32.0-7 on CBL Mariner 2.0
- cbl2 cloud-hypervisor-cvm 38.0.72.2-5 on CBL Mariner 2.0
- cbl2 conda 4.11.0-1 on CBL Mariner 2.0
- cbl2 erlang 25.3.2.21-4 on CBL Mariner 2.0
- azl3 cloud-hypervisor 48.0.246-3 on Azure Linux 3.0
- azl3 erlang 26.2.5.17-1 on Azure Linux 3.0
- azl3 kata-containers 3.19.1.kata2-6 on Azure Linux 3.0
- cbl2 rubygem-mini_portile2 2.8.0-1 on CBL Mariner 2.0
- cbl2 rust 1.72.0-14 on CBL Mariner 2.0
- azl3 rubygem-mini_portile2 2.8.4-1 on Azure Linux 3.0
Mariner
- cbl2 tcl 8.6.13-3 on CBL Mariner 2.0
- cbl2 zlib 1.2.13-2 on CBL Mariner 2.0
- azl3 tcl 8.6.13-3 on Azure Linux 3.0
- azl3 zlib 1.3.1-1 on Azure Linux 3.0
Revision History
- 2026-03-07: Information published.
- 2026-03-11: Information published.
- 2026-03-14: Information published.
- 2026-03-17: Information published.
- 2026-03-17: Information published.
- 2026-03-23: Information published.
- 2026-03-23: Information published.
- 2026-03-26: Information published.