---
id: CVE-2016-9842
title: >-
  The inflateMark function in inflate.c in zlib 1.2.8 might allow
  context-dependent attackers to have unspecified impact via vectors involving
  left shifts of negative integers.
summary: >-
  The inflateMark function in inflate.c in zlib 1.2.8 might allow
  context-dependent attackers to have unspecified impact via vectors involving
  left shifts of negative integers.
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-1335
vendor: zlib
product: zlib
affected:
  - 'zlib >= 1.2.3.4, < 1.2.9'
  - leap = 42.1
  - leap = 42.2
  - opensuse = 13.2
  - debian_linux = 8.0
  - ubuntu_linux = 16.04
  - ubuntu_linux = 18.04
  - database_server = 18c
  - jdk = 1.6.0
  - jdk = 1.7.0
  - jdk = 1.8.0
  - jre = 1.6.0
  - jre = 1.7.0
  - jre = 1.8.0
  - 'mysql >= 5.5.0, <= 5.5.61'
  - 'mysql >= 5.6.0, <= 5.6.41'
  - 'mysql >= 5.7.0, <= 5.7.23'
  - 'mysql >= 8.0.0, <= 8.0.12'
  - satellite = 5.8
  - enterprise_linux_desktop = 6.0
  - enterprise_linux_desktop = 7.0
  - enterprise_linux_eus = 7.4
  - enterprise_linux_eus = 7.5
  - enterprise_linux_server = 6.0
  - enterprise_linux_server = 7.0
  - enterprise_linux_workstation = 6.0
  - enterprise_linux_workstation = 7.0
  - iphone_os < 11
  - 'mac_os_x >= 10.0.0, < 10.13.0'
  - tvos < 11.0
  - watchos < 4
  - 'node.js >= 4.0.0, <= 4.1.2'
  - 'node.js >= 4.2.0, < 4.8.2'
  - 'node.js >= 6.0.0, <= 6.8.1'
  - 'node.js >= 6.9.0, < 6.10.2'
  - 'node.js >= 7.0.0, < 7.6.0'
patched:
  - zlib 1.2.9
  - iphone_os 11
  - mac_os_x 10.13.0
  - tvos 11.0
  - watchos 4
  - node.js 7.6.0
published: '2017-05-23'
updated: '2026-07-14'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2016-9842'
references:
  - url: 'http://lists.opensuse.org/opensuse-updates/2016-12/msg00127.html'
    label: security@opentext.com
  - url: 'http://lists.opensuse.org/opensuse-updates/2017-01/msg00050.html'
    label: security@opentext.com
  - url: 'http://lists.opensuse.org/opensuse-updates/2017-01/msg00053.html'
    label: security@opentext.com
  - url: 'http://www.openwall.com/lists/oss-security/2016/12/05/21'
    label: security@opentext.com
  - url: >-
      http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html
    label: security@opentext.com
  - url: >-
      http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
    label: security@opentext.com
  - url: 'http://www.securityfocus.com/bid/95131'
    label: security@opentext.com
  - url: 'http://www.securitytracker.com/id/1039427'
    label: security@opentext.com
  - url: 'https://access.redhat.com/errata/RHSA-2017:1220'
    label: security@opentext.com
  - url: 'https://access.redhat.com/errata/RHSA-2017:1221'
    label: security@opentext.com
  - url: 'https://access.redhat.com/errata/RHSA-2017:1222'
    label: security@opentext.com
  - url: 'https://access.redhat.com/errata/RHSA-2017:2999'
    label: security@opentext.com
  - url: 'https://access.redhat.com/errata/RHSA-2017:3046'
    label: security@opentext.com
  - url: 'https://access.redhat.com/errata/RHSA-2017:3047'
    label: security@opentext.com
  - url: 'https://access.redhat.com/errata/RHSA-2017:3453'
    label: security@opentext.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=1402348'
    label: security@opentext.com
  - url: >-
      https://github.com/madler/zlib/commit/e54e1299404101a5a9d0cf5e45512b543967f958
    label: security@opentext.com
  - url: 'https://lists.debian.org/debian-lts-announce/2019/03/msg00027.html'
    label: security@opentext.com
  - url: 'https://lists.debian.org/debian-lts-announce/2020/01/msg00030.html'
    label: security@opentext.com
  - url: 'https://security.gentoo.org/glsa/201701-56'
    label: security@opentext.com
  - url: 'https://security.gentoo.org/glsa/202007-54'
    label: security@opentext.com
  - url: 'https://support.apple.com/HT208112'
    label: security@opentext.com
  - url: 'https://support.apple.com/HT208113'
    label: security@opentext.com
  - url: 'https://support.apple.com/HT208115'
    label: security@opentext.com
  - url: 'https://support.apple.com/HT208144'
    label: security@opentext.com
  - url: 'https://usn.ubuntu.com/4246-1/'
    label: security@opentext.com
  - url: 'https://usn.ubuntu.com/4292-1/'
    label: security@opentext.com
  - url: 'https://wiki.mozilla.org/MOSS/Secure_Open_Source/Completed#zlib'
    label: security@opentext.com
  - url: 'https://wiki.mozilla.org/images/0/09/Zlib-report.pdf'
    label: security@opentext.com
  - url: 'https://www.oracle.com/security-alerts/cpujul2020.html'
    label: security@opentext.com
  - url: 'http://lists.opensuse.org/opensuse-updates/2016-12/msg00127.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://lists.opensuse.org/opensuse-updates/2017-01/msg00050.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://lists.opensuse.org/opensuse-updates/2017-01/msg00053.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.openwall.com/lists/oss-security/2016/12/05/21'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.securityfocus.com/bid/95131'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.securitytracker.com/id/1039427'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2017:1220'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2017:1221'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2017:1222'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2017:2999'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2017:3046'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2017:3047'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2017:3453'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=1402348'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://github.com/madler/zlib/commit/e54e1299404101a5a9d0cf5e45512b543967f958
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://lists.debian.org/debian-lts-announce/2019/03/msg00027.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://lists.debian.org/debian-lts-announce/2020/01/msg00030.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.gentoo.org/glsa/201701-56'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.gentoo.org/glsa/202007-54'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://support.apple.com/HT208112'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://support.apple.com/HT208113'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://support.apple.com/HT208115'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://support.apple.com/HT208144'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://usn.ubuntu.com/4246-1/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://usn.ubuntu.com/4292-1/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://wiki.mozilla.org/MOSS/Secure_Open_Source/Completed#zlib'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://wiki.mozilla.org/images/0/09/Zlib-report.pdf'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpujul2020.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://cert-portal.siemens.com/productcert/html/ssa-470355.html'
    label: 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e
tags:
  - nvd
epss: 0.05204
epssPercentile: 0.92142
ingestedAt: '2026-07-14T12:36:47.595Z'
---

## Overview

The inflateMark function in inflate.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving left shifts of negative integers.

## Affected

- `zlib >= 1.2.3.4, < 1.2.9`
- `leap = 42.1`
- `leap = 42.2`
- `opensuse = 13.2`
- `debian_linux = 8.0`
- `ubuntu_linux = 16.04`
- `ubuntu_linux = 18.04`
- `database_server = 18c`
- `jdk = 1.6.0`
- `jdk = 1.7.0`
- `jdk = 1.8.0`
- `jre = 1.6.0`
- `jre = 1.7.0`
- `jre = 1.8.0`
- `mysql >= 5.5.0, <= 5.5.61`
- `mysql >= 5.6.0, <= 5.6.41`
- `mysql >= 5.7.0, <= 5.7.23`
- `mysql >= 8.0.0, <= 8.0.12`
- `satellite = 5.8`
- `enterprise_linux_desktop = 6.0`
- `enterprise_linux_desktop = 7.0`
- `enterprise_linux_eus = 7.4`
- `enterprise_linux_eus = 7.5`
- `enterprise_linux_server = 6.0`
- `enterprise_linux_server = 7.0`
- `enterprise_linux_workstation = 6.0`
- `enterprise_linux_workstation = 7.0`
- `iphone_os < 11`
- `mac_os_x >= 10.0.0, < 10.13.0`
- `tvos < 11.0`
- `watchos < 4`
- `node.js >= 4.0.0, <= 4.1.2`
- `node.js >= 4.2.0, < 4.8.2`
- `node.js >= 6.0.0, <= 6.8.1`
- `node.js >= 6.9.0, < 6.10.2`
- `node.js >= 7.0.0, < 7.6.0`

## Remediation

Upgrade past the affected range:

- `zlib 1.2.9`
- `iphone_os 11`
- `mac_os_x 10.13.0`
- `tvos 11.0`
- `watchos 4`
- `node.js 7.6.0`
