{"id":"CVE-2022-37434","title":"zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field","summary":"zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHeader are affected. Some common applications bundle the af…","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-787","CWE-120","CWE-119"],"vendor":"zlib","product":"zlib","affected":["zlib <= 1.2.12","fedora = 35","fedora = 36","fedora = 37","debian_linux = 10.0","active_iq_unified_manager","hci","management_services_for_element_software","oncommand_workflow_automation","ontap_select_deploy_administration_utility","storagegrid","hci_compute_node","h300s_firmware","h500s_firmware","h700s_firmware","ipados < 15.7.1","iphone_os < 15.7.1","iphone_os >= 16.0, < 16.1","macos >= 11.0, < 11.7.1","macos >= 12.0.0, < 12.6.1","watchos < 9.1","stormshield_network_security >= 3.7.31, < 3.7.34","stormshield_network_security >= 3.11.0, < 3.11.22","stormshield_network_security >= 4.3.0, < 4.3.16","stormshield_network_security >= 4.6.0, < 4.6.3"],"patched":["ipados 15.7.1","iphone_os 16.1","macos 12.6.1","watchos 9.1","stormshield_network_security 4.6.3"],"published":"2022-08-05","updated":"2026-07-14","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2022-37434","references":[{"url":"http://seclists.org/fulldisclosure/2022/Oct/37","label":"cve@mitre.org"},{"url":"http://seclists.org/fulldisclosure/2022/Oct/38","label":"cve@mitre.org"},{"url":"http://seclists.org/fulldisclosure/2022/Oct/41","label":"cve@mitre.org"},{"url":"http://seclists.org/fulldisclosure/2022/Oct/42","label":"cve@mitre.org"},{"url":"http://www.openwall.com/lists/oss-security/2022/08/05/2","label":"cve@mitre.org"},{"url":"http://www.openwall.com/lists/oss-security/2022/08/09/1","label":"cve@mitre.org"},{"url":"https://github.com/curl/curl/issues/9271","label":"cve@mitre.org"},{"url":"https://github.com/ivd38/zlib_overflow","label":"cve@mitre.org"},{"url":"https://github.com/madler/zlib/blob/21767c654d31d2dccdde4330529775c6c5fd5389/zlib.h#L1062-L1063","label":"cve@mitre.org"},{"url":"https://github.com/madler/zlib/commit/1eb7682f845ac9e9bf9ae35bbfb3bad5dacbd91d","label":"cve@mitre.org"},{"url":"https://github.com/madler/zlib/commit/eff308af425b67093bab25f80f1ae950166bece1","label":"cve@mitre.org"},{"url":"https://github.com/nodejs/node/blob/75b68c6e4db515f76df73af476eccf382bbcb00a/deps/zlib/inflate.c#L762-L764","label":"cve@mitre.org"},{"url":"https://lists.debian.org/debian-lts-announce/2022/09/msg00012.html","label":"cve@mitre.org"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JWN4VE3JQR4O2SOUS5TXNLANRPMHWV4I/","label":"cve@mitre.org"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NMBOJ77A7T7PQCARMDUK75TE6LLESZ3O/","label":"cve@mitre.org"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PAVPQNCG3XRLCLNSQRM3KAN5ZFMVXVTY/","label":"cve@mitre.org"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X5U7OTKZSHY2I3ZFJSR2SHFHW72RKGDK/","label":"cve@mitre.org"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YRQAI7H4M4RQZ2IWZUEEXECBE5D56BH2/","label":"cve@mitre.org"},{"url":"https://security.netapp.com/advisory/ntap-20220901-0005/","label":"cve@mitre.org"},{"url":"https://security.netapp.com/advisory/ntap-20230427-0007/","label":"cve@mitre.org"},{"url":"https://support.apple.com/kb/HT213488","label":"cve@mitre.org"},{"url":"https://support.apple.com/kb/HT213489","label":"cve@mitre.org"},{"url":"https://support.apple.com/kb/HT213490","label":"cve@mitre.org"},{"url":"https://support.apple.com/kb/HT213491","label":"cve@mitre.org"},{"url":"https://support.apple.com/kb/HT213493","label":"cve@mitre.org"},{"url":"https://support.apple.com/kb/HT213494","label":"cve@mitre.org"},{"url":"https://www.debian.org/security/2022/dsa-5218","label":"cve@mitre.org"},{"url":"http://seclists.org/fulldisclosure/2022/Oct/37","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://seclists.org/fulldisclosure/2022/Oct/38","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://seclists.org/fulldisclosure/2022/Oct/41","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://seclists.org/fulldisclosure/2022/Oct/42","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.openwall.com/lists/oss-security/2022/08/05/2","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.openwall.com/lists/oss-security/2022/08/09/1","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://github.com/curl/curl/issues/9271","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://github.com/ivd38/zlib_overflow","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://github.com/madler/zlib/blob/21767c654d31d2dccdde4330529775c6c5fd5389/zlib.h#L1062-L1063","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://github.com/madler/zlib/commit/eff308af425b67093bab25f80f1ae950166bece1","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://github.com/nodejs/node/blob/75b68c6e4db515f76df73af476eccf382bbcb00a/deps/zlib/inflate.c#L762-L764","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.debian.org/debian-lts-announce/2022/09/msg00012.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JWN4VE3JQR4O2SOUS5TXNLANRPMHWV4I/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NMBOJ77A7T7PQCARMDUK75TE6LLESZ3O/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PAVPQNCG3XRLCLNSQRM3KAN5ZFMVXVTY/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X5U7OTKZSHY2I3ZFJSR2SHFHW72RKGDK/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YRQAI7H4M4RQZ2IWZUEEXECBE5D56BH2/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.netapp.com/advisory/ntap-20220901-0005/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.netapp.com/advisory/ntap-20230427-0007/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://support.apple.com/kb/HT213488","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://support.apple.com/kb/HT213489","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://support.apple.com/kb/HT213490","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://support.apple.com/kb/HT213491","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://support.apple.com/kb/HT213493","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://support.apple.com/kb/HT213494","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.debian.org/security/2022/dsa-5218","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://cert-portal.siemens.com/productcert/html/ssa-150063.html","label":"0b142b55-0307-4c5a-b3c9-f314f3fb7c5e"},{"url":"https://cert-portal.siemens.com/productcert/html/ssa-202008.html","label":"0b142b55-0307-4c5a-b3c9-f314f3fb7c5e"},{"url":"https://cert-portal.siemens.com/productcert/html/ssa-398330.html","label":"0b142b55-0307-4c5a-b3c9-f314f3fb7c5e"},{"url":"https://cert-portal.siemens.com/productcert/html/ssa-470355.html","label":"0b142b55-0307-4c5a-b3c9-f314f3fb7c5e"},{"url":"https://cert-portal.siemens.com/productcert/html/ssa-561322.html","label":"0b142b55-0307-4c5a-b3c9-f314f3fb7c5e"},{"url":"https://github.com/curl/curl/issues/9271","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-37434.json"},{"url":"https://access.redhat.com/security/cve/CVE-2022-37434"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2116639"},{"url":"https://www.cve.org/CVERecord?id=CVE-2022-37434"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2022-37434"},{"url":"https://access.redhat.com/errata/RHSA-2023:1095"},{"url":"https://access.redhat.com/errata/RHSA-2022:7314"},{"url":"https://access.redhat.com/errata/RHSA-2022:8291"},{"url":"https://access.redhat.com/errata/RHSA-2024:0254"},{"url":"https://access.redhat.com/errata/RHSA-2022:7106"},{"url":"https://access.redhat.com/errata/RHSA-2022:7793"}],"tags":["nvd","exploit-available","csaf","vex","red-hat","score-dispute"],"epss":0.17852,"epssPercentile":0.97104,"ingestedAt":"2026-07-14T12:36:47.749Z","exploits":{"github":2,"githubRepos":["https://github.com/xen0bit/CVE-2022-37434_poc","https://github.com/Trinadh465/external_zlib_CVE-2022-37434"],"checkedAt":"2026-09-21T15:25:30.214Z"},"exploitAvailable":true,"scores":{"nvd":9.8,"vendor":7},"slug":"CVE-2022-37434","body":"## Overview\n\nzlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHeader are affected. Some common applications bundle the affected zlib source code but may be unable to call inflateGetHeader (e.g., see the nodejs/node reference).\n\n## Affected\n\n- `zlib <= 1.2.12`\n- `fedora = 35`\n- `fedora = 36`\n- `fedora = 37`\n- `debian_linux = 10.0`\n- `active_iq_unified_manager`\n- `hci`\n- `management_services_for_element_software`\n- `oncommand_workflow_automation`\n- `ontap_select_deploy_administration_utility`\n- `storagegrid`\n- `hci_compute_node`\n- `h300s_firmware`\n- `h500s_firmware`\n- `h700s_firmware`\n- `ipados < 15.7.1`\n- `iphone_os < 15.7.1`\n- `iphone_os >= 16.0, < 16.1`\n- `macos >= 11.0, < 11.7.1`\n- `macos >= 12.0.0, < 12.6.1`\n- `watchos < 9.1`\n- `stormshield_network_security >= 3.7.31, < 3.7.34`\n- `stormshield_network_security >= 3.11.0, < 3.11.22`\n- `stormshield_network_security >= 4.3.0, < 4.3.16`\n- `stormshield_network_security >= 4.6.0, < 4.6.3`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `ipados 15.7.1`\n- `iphone_os 16.1`\n- `macos 12.6.1`\n- `watchos 9.1`\n- `stormshield_network_security 4.6.3`\n\n## Vendor advisories\n\n- **RHSA-2023:1095** · Red Hat · fixed in: Red Hat Enterprise Linux Client (v. 7), Red Hat Enterprise Linux Client Optional (v. 7), Red Hat Enterprise Linux ComputeNode Optional (v. 7), Red Hat Enterprise Linux Server (v. 7), Red Hat Enterprise Linux Server Optional (v. 7), Red Hat Enterprise Linux Workstation (v. 7), … · released 2023-03-07 · [advisory](https://access.redhat.com/errata/RHSA-2023:1095)\n- **RHSA-2022:7314** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 9), Red Hat Enterprise Linux BaseOS (v. 9), Red Hat CodeReady Linux Builder (v. 9) · released 2022-11-02 · [advisory](https://access.redhat.com/errata/RHSA-2022:7314)\n- **RHSA-2022:8291** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 9), Red Hat Enterprise Linux BaseOS (v. 9) · released 2022-11-15 · [advisory](https://access.redhat.com/errata/RHSA-2022:8291)\n- **RHSA-2024:0254** · Red Hat · fixed in: Red Hat Enterprise Linux BaseOS EUS (v.8.6) · released 2024-01-15 · [advisory](https://access.redhat.com/errata/RHSA-2024:0254)\n- **RHSA-2022:7106** · Red Hat · fixed in: Red Hat Enterprise Linux BaseOS (v. 8), Red Hat Enterprise Linux CRB (v. 8) · released 2022-10-25 · [advisory](https://access.redhat.com/errata/RHSA-2022:7106)\n- **RHSA-2022:7793** · Red Hat · fixed in: Red Hat Enterprise Linux BaseOS (v. 8) · released 2022-11-08 · [advisory](https://access.redhat.com/errata/RHSA-2022:7793)\n- **Red Hat VEX** · Moderate · affected: Red Hat build of Quarkus, Red Hat Enterprise Linux 6 · no fix planned: Red Hat Enterprise Linux 6, Red Hat build of Quarkus · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-37434.json)","depth":"abyssal","depthScore":69,"depthScoreParts":{"impact":53.9,"likelihood":3.6,"exploitation":12,"ransomware":0},"changes":[{"seq":4634,"id":"CVE-2022-37434","ts":1788887195055,"field":"exploit_available","old":"false","new":"true"},{"seq":3517,"id":"CVE-2022-37434","ts":1788886311536,"field":"exploit_available","old":"true","new":"false"},{"seq":2371,"id":"CVE-2022-37434","ts":1788882980946,"field":"exploit_available","old":"false","new":"true"},{"seq":1400,"id":"CVE-2022-37434","ts":1788882393633,"field":"exploit_available","old":"true","new":"false"},{"seq":514,"id":"CVE-2022-37434","ts":1788881829954,"field":"exploit_available","old":"false","new":"true"}]}