Update zlib to version 1.3.2 (MINDBREEZE41726)

ID: MINDBREEZE41726 
Affected Components: Mindbreeze InSpire, Mindbreeze InSpire SaaS 
Severity: 5.5 Medium 
Status: Final 
First published: August 5, 2026 
CVEs: CVE-2026-27171, CVE-2026-22184 

Summary 

  • zlib before 1.3.2 allows CPU consumption via crc32_combine64 and crc32_combine_gen64 because x2nmodp can do right shifts within a loop that has no termination condition. 
  • zlib versions up to and including 1.3.1.2 include a global buffer overflow in the untgz utility located under contrib/untgz. The vulnerability is limited to the standalone demonstration utility and does not affect the core zlib compression library. The flaw occurs when a user executes the untgz command with an excessively long archive name supplied via the command line, leading to an out-of-bounds write in a fixed-size global buffer. 

 

Hotfix Information 

Fixed with following versions of Mindbreeze InSpire On-Premises or Mindbreeze InSpire SaaS: 

  • Mindbreeze InSpire 26.4 Release
  • Mindbreeze InSpire SaaS 26.4 Release