CVE-2026-3381
CBL Mariner vulnerability analysis and mitigation

Overview

CVE-2026-3381 is a vulnerability in the Perl module Compress::Raw::Zlib arising from its use of a bundled, potentially insecure version of the zlib compression library. All versions of Compress::Raw::Zlib through 2.219 are affected; version 2.220 and later include zlib 1.3.2, which addresses the underlying issues identified in the 7ASecurity audit of zlib (including fixes for the related CVE-2026-27171). The vulnerability was published on March 5, 2026, and assigned by CPANSec (RedHat CVE). It carries a CVSS v3.1 base score of 9.8 (Critical) (RedHat CVE, Microsoft MSRC).

Technical details

The root cause is classified under CWE-1104 (Use of Unmaintained Third Party Components) and CWE-1284 (Improper Validation of Specified Quantity in Input). Compress::Raw::Zlib ships with a vendored copy of the zlib library rather than relying on the system-installed version; versions through 2.219 bundle zlib releases prior to 1.3.2, which contain vulnerabilities identified during the 7ASecurity security audit of zlib (7ASecurity Blog, zlib Release). The attack vector is network-based with low complexity and requires no authentication or user interaction, meaning any application that processes attacker-controlled compressed data via this module could be exploited (RedHat CVE). The upstream zlib 1.3.2 release (February 17, 2026) specifically addresses the 7ASecurity audit findings and is the basis for the fix (zlib Release).

Impact

Successful exploitation can result in complete compromise of confidentiality, integrity, and availability of affected systems, as reflected in the CVSS v3.1 score of 9.8 (RedHat CVE). Any Perl application that uses Compress::Raw::Zlib (directly or transitively through modules such as IO::Compress) to process untrusted compressed data is potentially at risk. The broad deployment of this module across Perl ecosystems — including enterprise products such as IBM Tivoli Network Manager — significantly widens the attack surface (IBM Advisory).

Exploitability

As of the time of reporting, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Feedly). The EPSS score is approximately 0.024% (0.000240), indicating a currently low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Detection plugins are available from Nessus (plugin IDs 301117, 304367) and Qualys (IDs 917387, 6563595–6563598) (Feedly).

Mitigation and workarounds

The primary remediation is to upgrade Compress::Raw::Zlib to version 2.220 or later, which bundles zlib 1.3.2 and addresses the identified vulnerabilities (Compress-Raw-Zlib Issue, zlib Release). Organizations should audit all systems running Perl applications that depend on Compress::Raw::Zlib versions 2.219 or earlier and prioritize patching given the critical CVSS score. OpenSUSE has issued updated packages for perl-Compress-Raw-Zlib (version 2.222), and IBM has released security bulletins for affected products such as IBM Tivoli Network Manager (IBM Advisory). No configuration-based workaround is available; upgrading the module is the only effective mitigation.

Community reactions

The vulnerability was discussed on the oss-security mailing list shortly after disclosure (oss-sec). Microsoft included CVE-2026-3381 in its March 2026 Patch Tuesday advisory, which received broad coverage from security media outlets including BleepingComputer and WinBuzzer (Microsoft MSRC). The Perl community discussed the fix via the perl5-porters mailing list, and the upstream Erlang/OTP project also committed a fix referencing this CVE, indicating broad ecosystem impact (Perl Porters).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

libcompress-raw-zlib-perl: 2.011-2

Fixed

sid

libcompress-raw-zlib-perl: 2.011-2

Fixed

trixie

libcompress-raw-zlib-perl: 2.011-2

Fixed

Ubuntu

Unknown

bionic (esm-apps)

libcompress-raw-zlib-perl

Unknown

bionic (esm-infra)

perl

Not Affected

devel

libcompress-raw-zlib-perl

Not Affected

focal (esm-apps)

libcompress-raw-zlib-perl

Unknown

focal (esm-infra)

perl

Not Affected

jammy

libcompress-raw-zlib-perl

Not Affected

jammy (esm-apps)

libcompress-raw-zlib-perl

Not Affected

noble

libcompress-raw-zlib-perl

Not Affected

RHEL / CentOS

Affected

RHEL 8

Not Affected

RHEL 9

Not Affected

RHEL 10

Not Affected

Alpine

Fixed

edge

perl-compress-raw-zlib: 2.222-r0

Fixed

v3.20

perl-compress-raw-zlib: 2.222-r0

Fixed

v3.21

perl-compress-raw-zlib: 2.222-r0

Fixed

v3.22

perl-compress-raw-zlib: 2.222-r0

Fixed

v3.23

perl-compress-raw-zlib: 2.222-r0

Fixed

SourceThis report was generated using AI

Related CBL Mariner vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-6554MEDIUM5.5
  • CBL Mariner logoCBL Mariner
  • libpcap.src
NoYesSep 05, 2026
CVE-2026-6244MEDIUM5.5
  • CBL Mariner logoCBL Mariner
  • libpcap
NoYesSep 05, 2026
CVE-2026-31912MEDIUM5.5
  • CBL Mariner logoCBL Mariner
  • libpcap-devel
NoYesSep 05, 2026
CVE-2026-31911MEDIUM5.5
  • CBL Mariner logoCBL Mariner
  • libpcap
NoYesSep 05, 2026
CVE-2026-18313MEDIUM4.3
  • CBL Mariner logoCBL Mariner
  • libpcap
NoYesSep 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management