{"id":"CVE-2016-9842","title":"The inflateMark function in inflate.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving left shifts of negative integers.","summary":"The inflateMark function in inflate.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving left shifts of negative integers.","severity":"high","cvss":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","cwe":["CWE-1335"],"vendor":"zlib","product":"zlib","affected":["zlib >= 1.2.3.4, < 1.2.9","leap = 42.1","leap = 42.2","opensuse = 13.2","debian_linux = 8.0","ubuntu_linux = 16.04","ubuntu_linux = 18.04","database_server = 18c","jdk = 1.6.0","jdk = 1.7.0","jdk = 1.8.0","jre = 1.6.0","jre = 1.7.0","jre = 1.8.0","mysql >= 5.5.0, <= 5.5.61","mysql >= 5.6.0, <= 5.6.41","mysql >= 5.7.0, <= 5.7.23","mysql >= 8.0.0, <= 8.0.12","satellite = 5.8","enterprise_linux_desktop = 6.0","enterprise_linux_desktop = 7.0","enterprise_linux_eus = 7.4","enterprise_linux_eus = 7.5","enterprise_linux_server = 6.0","enterprise_linux_server = 7.0","enterprise_linux_workstation = 6.0","enterprise_linux_workstation = 7.0","iphone_os < 11","mac_os_x >= 10.0.0, < 10.13.0","tvos < 11.0","watchos < 4","node.js >= 4.0.0, <= 4.1.2","node.js >= 4.2.0, < 4.8.2","node.js >= 6.0.0, <= 6.8.1","node.js >= 6.9.0, < 6.10.2","node.js >= 7.0.0, < 7.6.0"],"patched":["zlib 1.2.9","iphone_os 11","mac_os_x 10.13.0","tvos 11.0","watchos 4","node.js 7.6.0"],"published":"2017-05-23","updated":"2026-07-14","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2016-9842","references":[{"url":"http://lists.opensuse.org/opensuse-updates/2016-12/msg00127.html","label":"security@opentext.com"},{"url":"http://lists.opensuse.org/opensuse-updates/2017-01/msg00050.html","label":"security@opentext.com"},{"url":"http://lists.opensuse.org/opensuse-updates/2017-01/msg00053.html","label":"security@opentext.com"},{"url":"http://www.openwall.com/lists/oss-security/2016/12/05/21","label":"security@opentext.com"},{"url":"http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html","label":"security@opentext.com"},{"url":"http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html","label":"security@opentext.com"},{"url":"http://www.securityfocus.com/bid/95131","label":"security@opentext.com"},{"url":"http://www.securitytracker.com/id/1039427","label":"security@opentext.com"},{"url":"https://access.redhat.com/errata/RHSA-2017:1220","label":"security@opentext.com"},{"url":"https://access.redhat.com/errata/RHSA-2017:1221","label":"security@opentext.com"},{"url":"https://access.redhat.com/errata/RHSA-2017:1222","label":"security@opentext.com"},{"url":"https://access.redhat.com/errata/RHSA-2017:2999","label":"security@opentext.com"},{"url":"https://access.redhat.com/errata/RHSA-2017:3046","label":"security@opentext.com"},{"url":"https://access.redhat.com/errata/RHSA-2017:3047","label":"security@opentext.com"},{"url":"https://access.redhat.com/errata/RHSA-2017:3453","label":"security@opentext.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=1402348","label":"security@opentext.com"},{"url":"https://github.com/madler/zlib/commit/e54e1299404101a5a9d0cf5e45512b543967f958","label":"security@opentext.com"},{"url":"https://lists.debian.org/debian-lts-announce/2019/03/msg00027.html","label":"security@opentext.com"},{"url":"https://lists.debian.org/debian-lts-announce/2020/01/msg00030.html","label":"security@opentext.com"},{"url":"https://security.gentoo.org/glsa/201701-56","label":"security@opentext.com"},{"url":"https://security.gentoo.org/glsa/202007-54","label":"security@opentext.com"},{"url":"https://support.apple.com/HT208112","label":"security@opentext.com"},{"url":"https://support.apple.com/HT208113","label":"security@opentext.com"},{"url":"https://support.apple.com/HT208115","label":"security@opentext.com"},{"url":"https://support.apple.com/HT208144","label":"security@opentext.com"},{"url":"https://usn.ubuntu.com/4246-1/","label":"security@opentext.com"},{"url":"https://usn.ubuntu.com/4292-1/","label":"security@opentext.com"},{"url":"https://wiki.mozilla.org/MOSS/Secure_Open_Source/Completed#zlib","label":"security@opentext.com"},{"url":"https://wiki.mozilla.org/images/0/09/Zlib-report.pdf","label":"security@opentext.com"},{"url":"https://www.oracle.com/security-alerts/cpujul2020.html","label":"security@opentext.com"},{"url":"http://lists.opensuse.org/opensuse-updates/2016-12/msg00127.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://lists.opensuse.org/opensuse-updates/2017-01/msg00050.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://lists.opensuse.org/opensuse-updates/2017-01/msg00053.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.openwall.com/lists/oss-security/2016/12/05/21","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.securityfocus.com/bid/95131","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.securitytracker.com/id/1039427","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://access.redhat.com/errata/RHSA-2017:1220","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://access.redhat.com/errata/RHSA-2017:1221","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://access.redhat.com/errata/RHSA-2017:1222","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://access.redhat.com/errata/RHSA-2017:2999","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://access.redhat.com/errata/RHSA-2017:3046","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://access.redhat.com/errata/RHSA-2017:3047","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://access.redhat.com/errata/RHSA-2017:3453","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=1402348","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://github.com/madler/zlib/commit/e54e1299404101a5a9d0cf5e45512b543967f958","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.debian.org/debian-lts-announce/2019/03/msg00027.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.debian.org/debian-lts-announce/2020/01/msg00030.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.gentoo.org/glsa/201701-56","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.gentoo.org/glsa/202007-54","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://support.apple.com/HT208112","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://support.apple.com/HT208113","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://support.apple.com/HT208115","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://support.apple.com/HT208144","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://usn.ubuntu.com/4246-1/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://usn.ubuntu.com/4292-1/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://wiki.mozilla.org/MOSS/Secure_Open_Source/Completed#zlib","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://wiki.mozilla.org/images/0/09/Zlib-report.pdf","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpujul2020.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://cert-portal.siemens.com/productcert/html/ssa-470355.html","label":"0b142b55-0307-4c5a-b3c9-f314f3fb7c5e"}],"tags":["nvd"],"epss":0.05204,"epssPercentile":0.92142,"ingestedAt":"2026-07-14T12:36:47.595Z","slug":"CVE-2016-9842","body":"## Overview\n\nThe inflateMark function in inflate.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving left shifts of negative integers.\n\n## Affected\n\n- `zlib >= 1.2.3.4, < 1.2.9`\n- `leap = 42.1`\n- `leap = 42.2`\n- `opensuse = 13.2`\n- `debian_linux = 8.0`\n- `ubuntu_linux = 16.04`\n- `ubuntu_linux = 18.04`\n- `database_server = 18c`\n- `jdk = 1.6.0`\n- `jdk = 1.7.0`\n- `jdk = 1.8.0`\n- `jre = 1.6.0`\n- `jre = 1.7.0`\n- `jre = 1.8.0`\n- `mysql >= 5.5.0, <= 5.5.61`\n- `mysql >= 5.6.0, <= 5.6.41`\n- `mysql >= 5.7.0, <= 5.7.23`\n- `mysql >= 8.0.0, <= 8.0.12`\n- `satellite = 5.8`\n- `enterprise_linux_desktop = 6.0`\n- `enterprise_linux_desktop = 7.0`\n- `enterprise_linux_eus = 7.4`\n- `enterprise_linux_eus = 7.5`\n- `enterprise_linux_server = 6.0`\n- `enterprise_linux_server = 7.0`\n- `enterprise_linux_workstation = 6.0`\n- `enterprise_linux_workstation = 7.0`\n- `iphone_os < 11`\n- `mac_os_x >= 10.0.0, < 10.13.0`\n- `tvos < 11.0`\n- `watchos < 4`\n- `node.js >= 4.0.0, <= 4.1.2`\n- `node.js >= 4.2.0, < 4.8.2`\n- `node.js >= 6.0.0, <= 6.8.1`\n- `node.js >= 6.9.0, < 6.10.2`\n- `node.js >= 7.0.0, < 7.6.0`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `zlib 1.2.9`\n- `iphone_os 11`\n- `mac_os_x 10.13.0`\n- `tvos 11.0`\n- `watchos 4`\n- `node.js 7.6.0`","depth":"twilight","depthScore":49,"depthScoreParts":{"impact":48.4,"likelihood":1,"exploitation":0,"ransomware":0},"changes":[]}