High severity8.8NVD Advisory· Published May 23, 2017· Updated May 13, 2026
CVE-2016-9842
CVE-2016-9842
Description
The inflateMark function in inflate.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving left shifts of negative integers.
Affected products
96- osv-coords96 versionspkg:apk/chainguard/mysql-8.0pkg:apk/chainguard/mysql-8.0-bitnami-compatpkg:apk/chainguard/mysql-8.0-clientpkg:apk/chainguard/mysql-8.0-devpkg:apk/chainguard/mysql-8.0-iamguarded-compatpkg:apk/chainguard/mysql-8.0-oci-entrypointpkg:apk/chainguard/mysql-8.0-oci-entrypoint-compatpkg:apk/chainguard/openjdk-11-openj9pkg:apk/chainguard/openjdk-11-openj9-dbgpkg:apk/chainguard/openjdk-11-openj9-default-jdkpkg:apk/chainguard/openjdk-11-openj9-default-jvmpkg:apk/chainguard/openjdk-11-openj9-default-policypkg:apk/chainguard/openjdk-11-openj9-docpkg:apk/chainguard/openjdk-11-openj9-jmodspkg:apk/chainguard/openjdk-11-openj9-jrepkg:apk/chainguard/openjdk-17-openj9pkg:apk/chainguard/openjdk-17-openj9-dbgpkg:apk/chainguard/openjdk-17-openj9-default-jdkpkg:apk/chainguard/openjdk-17-openj9-default-jvmpkg:apk/chainguard/openjdk-17-openj9-default-policypkg:apk/chainguard/openjdk-17-openj9-docpkg:apk/chainguard/openjdk-17-openj9-jmodspkg:apk/chainguard/openjdk-17-openj9-jrepkg:apk/chainguard/openjdk-21-openj9pkg:apk/chainguard/openjdk-21-openj9-dbgpkg:apk/chainguard/openjdk-21-openj9-default-jdkpkg:apk/chainguard/openjdk-21-openj9-default-jvmpkg:apk/chainguard/openjdk-21-openj9-default-policypkg:apk/chainguard/openjdk-21-openj9-docpkg:apk/chainguard/openjdk-21-openj9-jmodspkg:apk/chainguard/openjdk-21-openj9-jrepkg:apk/chainguard/openjdk-8-openj9pkg:apk/chainguard/openjdk-8-openj9-dbgpkg:apk/chainguard/openjdk-8-openj9-default-jdkpkg:apk/chainguard/openjdk-8-openj9-default-jvmpkg:apk/chainguard/openjdk-8-openj9-docpkg:apk/chainguard/openjdk-8-openj9-jrepkg:rpm/suse/java-1_6_0-ibm&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Legacy%2012pkg:rpm/suse/java-1_6_0-ibm&distro=SUSE%20Linux%20Enterprise%20Point%20of%20Sale%2011%20SP3pkg:rpm/suse/java-1_6_0-ibm&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP3-LTSSpkg:rpm/suse/java-1_6_0-ibm&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP3-TERADATApkg:rpm/suse/java-1_7_0-ibm&distro=SUSE%20Linux%20Enterprise%20Point%20of%20Sale%2011%20SP3pkg:rpm/suse/java-1_7_0-ibm&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP3-LTSSpkg:rpm/suse/java-1_7_0-ibm&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP3-TERADATApkg:rpm/suse/java-1_7_0-openjdk&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP2pkg:rpm/suse/java-1_7_0-openjdk&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP3pkg:rpm/suse/java-1_7_0-openjdk&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP1-LTSSpkg:rpm/suse/java-1_7_0-openjdk&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2pkg:rpm/suse/java-1_7_0-openjdk&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3pkg:rpm/suse/java-1_7_0-openjdk&distro=SUSE%20Linux%20Enterprise%20Server%2012-LTSSpkg:rpm/suse/java-1_7_0-openjdk&distro=SUSE%20Linux%20Enterprise%20Server%20for%20Raspberry%20Pi%2012%20SP2pkg:rpm/suse/java-1_7_0-openjdk&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012pkg:rpm/suse/java-1_7_0-openjdk&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP1pkg:rpm/suse/java-1_7_0-openjdk&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP2pkg:rpm/suse/java-1_7_0-openjdk&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP3pkg:rpm/suse/java-1_7_0-openjdk&distro=SUSE%20OpenStack%20Cloud%206pkg:rpm/suse/java-1_7_1-ibm&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4pkg:rpm/suse/java-1_7_1-ibm&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP1pkg:rpm/suse/java-1_7_1-ibm&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2pkg:rpm/suse/java-1_7_1-ibm&distro=SUSE%20Linux%20Enterprise%20Server%2012-LTSSpkg:rpm/suse/java-1_7_1-ibm&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2011%20SP4pkg:rpm/suse/java-1_7_1-ibm&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012pkg:rpm/suse/java-1_7_1-ibm&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP1pkg:rpm/suse/java-1_7_1-ibm&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP2pkg:rpm/suse/java-1_7_1-ibm&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2011%20SP4pkg:rpm/suse/java-1_7_1-ibm&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP1pkg:rpm/suse/java-1_7_1-ibm&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP2pkg:rpm/suse/java-1_8_0-ibm&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP1pkg:rpm/suse/java-1_8_0-ibm&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2pkg:rpm/suse/java-1_8_0-ibm&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP1pkg:rpm/suse/java-1_8_0-ibm&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP2pkg:rpm/suse/java-1_8_0-ibm&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP1pkg:rpm/suse/java-1_8_0-ibm&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP2pkg:rpm/suse/java-1_8_0-openjdk&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP2pkg:rpm/suse/java-1_8_0-openjdk&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP3pkg:rpm/suse/java-1_8_0-openjdk&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP1-LTSSpkg:rpm/suse/java-1_8_0-openjdk&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2pkg:rpm/suse/java-1_8_0-openjdk&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3pkg:rpm/suse/java-1_8_0-openjdk&distro=SUSE%20Linux%20Enterprise%20Server%20for%20Raspberry%20Pi%2012%20SP2pkg:rpm/suse/java-1_8_0-openjdk&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP1pkg:rpm/suse/java-1_8_0-openjdk&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP2pkg:rpm/suse/java-1_8_0-openjdk&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP3pkg:rpm/suse/java-1_8_0-openjdk&distro=SUSE%20OpenStack%20Cloud%206pkg:rpm/suse/zlib&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP1pkg:rpm/suse/zlib&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP2pkg:rpm/suse/zlib&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4pkg:rpm/suse/zlib&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP1pkg:rpm/suse/zlib&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2pkg:rpm/suse/zlib&distro=SUSE%20Linux%20Enterprise%20Server%20for%20Raspberry%20Pi%2012%20SP2pkg:rpm/suse/zlib&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2011%20SP4pkg:rpm/suse/zlib&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP1pkg:rpm/suse/zlib&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP2pkg:rpm/suse/zlib&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2011%20SP4pkg:rpm/suse/zlib&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP1pkg:rpm/suse/zlib&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP2pkg:rpm/suse/zlib&distro=SUSE%20Studio%20Onsite%201.3
< 8.0.38-r0+ 95 more
- (no CPE)range: < 8.0.38-r0
- (no CPE)range: < 8.0.38-r0
- (no CPE)range: < 8.0.38-r0
- (no CPE)range: < 8.0.38-r0
- (no CPE)range: < 8.0.38-r0
- (no CPE)range: < 8.0.38-r0
- (no CPE)range: < 8.0.38-r0
- (no CPE)range: < 0.53.0-r0
- (no CPE)range: < 0.53.0-r0
- (no CPE)range: < 0.53.0-r0
- (no CPE)range: < 0.53.0-r0
- (no CPE)range: < 0.53.0-r0
- (no CPE)range: < 0.53.0-r0
- (no CPE)range: < 0.53.0-r0
- (no CPE)range: < 0.53.0-r0
- (no CPE)range: < 0.53.0-r0
- (no CPE)range: < 0.53.0-r0
- (no CPE)range: < 0.53.0-r0
- (no CPE)range: < 0.53.0-r0
- (no CPE)range: < 0.53.0-r0
- (no CPE)range: < 0.53.0-r0
- (no CPE)range: < 0.53.0-r0
- (no CPE)range: < 0.53.0-r0
- (no CPE)range: < 0.53.0-r0
- (no CPE)range: < 0.53.0-r0
- (no CPE)range: < 0.53.0-r0
- (no CPE)range: < 0.53.0-r0
- (no CPE)range: < 0.53.0-r0
- (no CPE)range: < 0.53.0-r0
- (no CPE)range: < 0.53.0-r0
- (no CPE)range: < 0.53.0-r0
- (no CPE)range: < 0.53.0-r1
- (no CPE)range: < 0.53.0-r1
- (no CPE)range: < 0.53.0-r1
- (no CPE)range: < 0.53.0-r1
- (no CPE)range: < 0.53.0-r1
- (no CPE)range: < 0.53.0-r1
- (no CPE)range: < 1.6.0_sr16.45-49.1
- (no CPE)range: < 1.6.0_sr16.45-84.1
- (no CPE)range: < 1.6.0_sr16.45-84.1
- (no CPE)range: < 1.6.0_sr16.45-84.1
- (no CPE)range: < 1.7.0_sr10.5-64.1
- (no CPE)range: < 1.7.0_sr10.5-64.1
- (no CPE)range: < 1.7.0_sr10.5-64.1
- (no CPE)range: < 1.7.0.161-43.7.6
- (no CPE)range: < 1.7.0.161-43.7.6
- (no CPE)range: < 1.7.0.161-43.7.6
- (no CPE)range: < 1.7.0.161-43.7.6
- (no CPE)range: < 1.7.0.161-43.7.6
- (no CPE)range: < 1.7.0.161-43.7.6
- (no CPE)range: < 1.7.0.161-43.7.6
- (no CPE)range: < 1.7.0.161-43.7.6
- (no CPE)range: < 1.7.0.161-43.7.6
- (no CPE)range: < 1.7.0.161-43.7.6
- (no CPE)range: < 1.7.0.161-43.7.6
- (no CPE)range: < 1.7.0.161-43.7.6
- (no CPE)range: < 1.7.1_sr4.5-25.1
- (no CPE)range: < 1.7.1_sr4.5-37.1
- (no CPE)range: < 1.7.1_sr4.5-37.1
- (no CPE)range: < 1.7.1_sr4.5-37.1
- (no CPE)range: < 1.7.1_sr4.5-25.1
- (no CPE)range: < 1.7.1_sr4.5-37.1
- (no CPE)range: < 1.7.1_sr4.5-37.1
- (no CPE)range: < 1.7.1_sr4.5-37.1
- (no CPE)range: < 1.7.1_sr4.5-25.1
- (no CPE)range: < 1.7.1_sr4.5-37.1
- (no CPE)range: < 1.7.1_sr4.5-37.1
- (no CPE)range: < 1.8.0_sr4.5-29.1
- (no CPE)range: < 1.8.0_sr4.5-29.1
- (no CPE)range: < 1.8.0_sr4.5-29.1
- (no CPE)range: < 1.8.0_sr4.5-29.1
- (no CPE)range: < 1.8.0_sr4.5-29.1
- (no CPE)range: < 1.8.0_sr4.5-29.1
- (no CPE)range: < 1.8.0.151-27.8.1
- (no CPE)range: < 1.8.0.151-27.8.1
- (no CPE)range: < 1.8.0.151-27.8.1
- (no CPE)range: < 1.8.0.151-27.8.1
- (no CPE)range: < 1.8.0.151-27.8.1
- (no CPE)range: < 1.8.0.151-27.8.1
- (no CPE)range: < 1.8.0.151-27.8.1
- (no CPE)range: < 1.8.0.151-27.8.1
- (no CPE)range: < 1.8.0.151-27.8.1
- (no CPE)range: < 1.8.0.151-27.8.1
- (no CPE)range: < 1.2.8-6.3.1
- (no CPE)range: < 1.2.8-11.1
- (no CPE)range: < 1.2.7-0.14.1
- (no CPE)range: < 1.2.8-6.3.1
- (no CPE)range: < 1.2.8-11.1
- (no CPE)range: < 1.2.8-11.1
- (no CPE)range: < 1.2.7-0.14.1
- (no CPE)range: < 1.2.8-6.3.1
- (no CPE)range: < 1.2.8-11.1
- (no CPE)range: < 1.2.7-0.14.1
- (no CPE)range: < 1.2.8-6.3.1
- (no CPE)range: < 1.2.8-11.1
- (no CPE)range: < 1.2.7-0.135.3.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
30- www.openwall.com/lists/oss-security/2016/12/05/21nvdMailing ListPatch
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingPatch
- github.com/madler/zlib/commit/e54e1299404101a5a9d0cf5e45512b543967f958nvdPatch
- www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.htmlnvdThird Party Advisory
- www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.htmlnvdThird Party Advisory
- www.securityfocus.com/bid/95131nvdBroken LinkThird Party AdvisoryVDB Entry
- www.securitytracker.com/id/1039427nvdBroken LinkThird Party AdvisoryVDB Entry
- access.redhat.com/errata/RHSA-2017:1220nvdThird Party Advisory
- access.redhat.com/errata/RHSA-2017:1221nvdThird Party Advisory
- access.redhat.com/errata/RHSA-2017:1222nvdThird Party Advisory
- access.redhat.com/errata/RHSA-2017:2999nvdThird Party Advisory
- access.redhat.com/errata/RHSA-2017:3046nvdThird Party Advisory
- access.redhat.com/errata/RHSA-2017:3047nvdThird Party Advisory
- access.redhat.com/errata/RHSA-2017:3453nvdThird Party Advisory
- lists.debian.org/debian-lts-announce/2019/03/msg00027.htmlnvdMailing ListThird Party Advisory
- lists.debian.org/debian-lts-announce/2020/01/msg00030.htmlnvdMailing ListThird Party Advisory
- security.gentoo.org/glsa/201701-56nvdThird Party Advisory
- security.gentoo.org/glsa/202007-54nvdThird Party Advisory
- support.apple.com/HT208112nvdThird Party Advisory
- support.apple.com/HT208113nvdThird Party Advisory
- support.apple.com/HT208115nvdThird Party Advisory
- support.apple.com/HT208144nvdThird Party Advisory
- usn.ubuntu.com/4246-1/nvdThird Party Advisory
- usn.ubuntu.com/4292-1/nvdThird Party Advisory
- wiki.mozilla.org/MOSS/Secure_Open_Source/CompletednvdThird Party Advisory
- wiki.mozilla.org/images/0/09/Zlib-report.pdfnvdThird Party Advisory
- www.oracle.com/security-alerts/cpujul2020.htmlnvdThird Party Advisory
- lists.opensuse.org/opensuse-updates/2016-12/msg00127.htmlnvdBroken Link
- lists.opensuse.org/opensuse-updates/2017-01/msg00050.htmlnvdBroken Link
- lists.opensuse.org/opensuse-updates/2017-01/msg00053.htmlnvdBroken Link
News mentions
0No linked articles in our index yet.