CVE-2016-9842

high
Published 2017-05-23 · Modified 2026-05-13
CVSS v3
8.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS v2
6.8
VIR risk
8.8

Description

The inflateMark function in inflate.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving left shifts of negative integers.

Predictions

Exploit likelihood
92%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2016-9842

vendor Authored 2026-05-27

Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2016-9842.html

vendor Authored 2026-05-27

Vendor advisory: security@opentext.com — https://github.com/madler/zlib/commit/e54e1299404101a5a9d0cf5e45512b543967f958

vendor Authored 2026-05-27

Vendor advisory: security@opentext.com — https://bugzilla.redhat.com/show_bug.cgi?id=1402348

vendor Authored 2026-05-27

Vendor advisory: security@opentext.com — http://www.openwall.com/lists/oss-security/2016/12/05/21

OS impact

OSVersionStatusFixed in
suse slesaffected
debian debian8.0affected
ubuntu ubuntu16.04affected
ubuntu ubuntu18.04affected
macos macosaffected11
suse suse42.1affected
suse suse42.2affected
suse suse13.2affected
redhat rhel6.0affected
redhat rhel7.0affected
redhat rhel7.4affected
redhat rhel7.5affected
debian debianbookwormfixed3.1.3-6
debian debianbullseyefixed3.1.3-6
debian debianforkyfixed3.1.3-6
debian debiansidfixed3.1.3-6
debian debiantrixiefixed3.1.3-6

Application impact

VendorProductVersionsFixed
zlibzlib{"startIncluding":"1.2.3.4","endExcluding":"1.2.9"}1.2.9
oracledatabase_server18c
oraclejdk1.6.0
oraclejdk1.7.0
oraclejdk1.8.0
oraclejre1.6.0
oraclejre1.7.0
oraclejre1.8.0
oraclemysql{"startIncluding":"5.5.0","endIncluding":"5.5.61"}
redhatsatellite5.8
nodejsnode.js{"startIncluding":"4.0.0","endIncluding":"4.1.2"}

References

CWEs

CWE-1335

Verify integrity in audit chain (admin only). AS-IS.