
Zlib for IBM i, while not utilized by every shop, presents a significant vulnerability that warrants attention. Vulnerability Details: - **CVEID:** CVE-2026-27171 - **Description:** Zlib versions prior to 1.3.2 allow for increased CPU consumption through the functions crc32_combine64 and crc32_combine_gen64. This occurs because x2nmodp can perform right shifts within a loop that lacks a termination condition. - **CWE:** CWE-1284: Improper Validation of Specified Quantity in Input - **CVSS Source:** NVD - **CVSS Base Score:** 5.5 - **CVSS Vector:** (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H) Remediation/Fixes: **IBM i Release PTF Number(s):** - 7.6: SJ09728 - 7.5: SJ09726 - 7.4: SJ09723 - 7.3: SJ09723 It is crucial for users to apply the necessary patches to mitigate this vulnerability.
Post summary
IBM i users should apply the provided PTF patches (SJ09728, SJ09726, SJ09723) to mitigate CVE‑2026‑27171, a vulnerability with a CVSS score of 5.5 that allows high CPU consumption.




