---
id: CVE-2018-25032
title: >-
  zlib before 1.2.12 allows memory corruption when deflating (i.e., when
  compressing) if the input has many distant matches.
summary: >-
  zlib before 1.2.12 allows memory corruption when deflating (i.e., when
  compressing) if the input has many distant matches.
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-787
  - CWE-787
vendor: nokogiri
product: nokogiri
affected:
  - nokogiri < 1.13.4
  - 'python >= 3.7.0, < 3.7.14'
  - 'python >= 3.8.0, < 3.8.14'
  - 'python >= 3.9.0, < 3.9.13'
  - 'python >= 3.10.0, < 3.10.5'
  - 'zlib >= 1.2.2.2, < 1.2.12'
  - debian_linux = 9.0
  - debian_linux = 10.0
  - debian_linux = 11.0
  - fedora = 34
  - fedora = 35
  - fedora = 36
  - 'mac_os_x >= 10.15, < 10.15.7'
  - mac_os_x = 10.15.7
  - 'macos >= 11.0, < 11.6.6'
  - 'macos >= 12.0.0, < 12.4'
  - 'mariadb >= 10.3.0, < 10.3.36'
  - 'mariadb >= 10.4.0, < 10.4.26'
  - 'mariadb >= 10.5.0, < 10.5.17'
  - 'mariadb >= 10.6.0, < 10.6.9'
  - 'mariadb >= 10.7.0, < 10.7.5'
  - 'mariadb >= 10.8.0, < 10.8.4'
  - 'mariadb >= 10.9.0, < 10.9.2'
  - active_iq_unified_manager
  - 'e-series_santricity_os_controller >= 11.0.0, <= 11.70.2'
  - management_services_for_element_software
  - oncommand_workflow_automation
  - ontap_select_deploy_administration_utility
  - hci_compute_node
  - h300s_firmware
  - h500s_firmware
  - h700s_firmware
  - h410s_firmware
  - h410c_firmware
  - scalance_sc622-2c_firmware < 3.0
  - scalance_sc626-2c_firmware < 3.0
  - scalance_sc632-2c_firmware < 3.0
  - scalance_sc636-2c_firmware < 3.0
  - scalance_sc642-2c_firmware < 3.0
  - scalance_sc646-2c_firmware < 3.0
  - zulu = 6.45
  - zulu = 7.52
  - zulu = 8.60
  - zulu = 11.54
  - zulu = 13.46
  - zulu = 15.38
  - zulu = 17.32
  - gotoassist < 11.9.18
patched:
  - nokogiri 1.13.4
  - python 3.10.5
  - zlib 1.2.12
  - mac_os_x 10.15.7
  - macos 12.4
  - mariadb 10.9.2
  - scalance_sc622-2c_firmware 3.0
  - scalance_sc626-2c_firmware 3.0
  - scalance_sc632-2c_firmware 3.0
  - scalance_sc636-2c_firmware 3.0
  - scalance_sc642-2c_firmware 3.0
  - scalance_sc646-2c_firmware 3.0
  - gotoassist 11.9.18
published: '2022-03-25'
updated: '2026-07-14'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2018-25032'
references:
  - url: 'http://seclists.org/fulldisclosure/2022/May/33'
    label: cve@mitre.org
  - url: 'http://seclists.org/fulldisclosure/2022/May/35'
    label: cve@mitre.org
  - url: 'http://seclists.org/fulldisclosure/2022/May/38'
    label: cve@mitre.org
  - url: 'http://www.openwall.com/lists/oss-security/2022/03/25/2'
    label: cve@mitre.org
  - url: 'http://www.openwall.com/lists/oss-security/2022/03/26/1'
    label: cve@mitre.org
  - url: 'https://cert-portal.siemens.com/productcert/pdf/ssa-333517.pdf'
    label: cve@mitre.org
  - url: >-
      https://github.com/madler/zlib/commit/5c44459c3b28a9bd3283aaceab7c615f8020c531
    label: cve@mitre.org
  - url: 'https://github.com/madler/zlib/compare/v1.2.11...v1.2.12'
    label: cve@mitre.org
  - url: 'https://github.com/madler/zlib/issues/605'
    label: cve@mitre.org
  - url: 'https://lists.debian.org/debian-lts-announce/2022/04/msg00000.html'
    label: cve@mitre.org
  - url: 'https://lists.debian.org/debian-lts-announce/2022/05/msg00008.html'
    label: cve@mitre.org
  - url: 'https://lists.debian.org/debian-lts-announce/2022/09/msg00023.html'
    label: cve@mitre.org
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DCZFIJBJTZ7CL5QXBFKTQ22Q26VINRUF/
    label: cve@mitre.org
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DF62MVMH3QUGMBDCB3DY2ERQ6EBHTADB/
    label: cve@mitre.org
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JZZPTWRYQULAOL3AW7RZJNVZ2UONXCV4/
    label: cve@mitre.org
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NS2D2GFPFGOJUL4WQ3DUAY7HF4VWQ77F/
    label: cve@mitre.org
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VOKNP2L734AEL47NRYGVZIKEFOUBQY5Y/
    label: cve@mitre.org
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XOKFMSNQ5D5WGMALBNBXU3GE442V74WU/
    label: cve@mitre.org
  - url: 'https://security.gentoo.org/glsa/202210-42'
    label: cve@mitre.org
  - url: 'https://security.netapp.com/advisory/ntap-20220526-0009/'
    label: cve@mitre.org
  - url: 'https://security.netapp.com/advisory/ntap-20220729-0004/'
    label: cve@mitre.org
  - url: 'https://support.apple.com/kb/HT213255'
    label: cve@mitre.org
  - url: 'https://support.apple.com/kb/HT213256'
    label: cve@mitre.org
  - url: 'https://support.apple.com/kb/HT213257'
    label: cve@mitre.org
  - url: 'https://www.debian.org/security/2022/dsa-5111'
    label: cve@mitre.org
  - url: 'https://www.openwall.com/lists/oss-security/2022/03/24/1'
    label: cve@mitre.org
  - url: 'https://www.openwall.com/lists/oss-security/2022/03/28/1'
    label: cve@mitre.org
  - url: 'https://www.openwall.com/lists/oss-security/2022/03/28/3'
    label: cve@mitre.org
  - url: 'https://www.oracle.com/security-alerts/cpujul2022.html'
    label: cve@mitre.org
  - url: 'http://seclists.org/fulldisclosure/2022/May/33'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://seclists.org/fulldisclosure/2022/May/35'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://seclists.org/fulldisclosure/2022/May/38'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.openwall.com/lists/oss-security/2022/03/25/2'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.openwall.com/lists/oss-security/2022/03/26/1'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://cert-portal.siemens.com/productcert/pdf/ssa-333517.pdf'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://github.com/madler/zlib/commit/5c44459c3b28a9bd3283aaceab7c615f8020c531
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://github.com/madler/zlib/compare/v1.2.11...v1.2.12'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://github.com/madler/zlib/issues/605'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://lists.debian.org/debian-lts-announce/2022/04/msg00000.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://lists.debian.org/debian-lts-announce/2022/05/msg00008.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://lists.debian.org/debian-lts-announce/2022/09/msg00023.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DCZFIJBJTZ7CL5QXBFKTQ22Q26VINRUF/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DF62MVMH3QUGMBDCB3DY2ERQ6EBHTADB/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JZZPTWRYQULAOL3AW7RZJNVZ2UONXCV4/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NS2D2GFPFGOJUL4WQ3DUAY7HF4VWQ77F/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VOKNP2L734AEL47NRYGVZIKEFOUBQY5Y/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XOKFMSNQ5D5WGMALBNBXU3GE442V74WU/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.gentoo.org/glsa/202210-42'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.netapp.com/advisory/ntap-20220526-0009/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.netapp.com/advisory/ntap-20220729-0004/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://support.apple.com/kb/HT213255'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://support.apple.com/kb/HT213256'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://support.apple.com/kb/HT213257'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.debian.org/security/2022/dsa-5111'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.openwall.com/lists/oss-security/2022/03/24/1'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.openwall.com/lists/oss-security/2022/03/28/1'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.openwall.com/lists/oss-security/2022/03/28/3'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpujul2022.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://cert-portal.siemens.com/productcert/html/ssa-333517.html'
    label: 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e
  - url: 'https://cert-portal.siemens.com/productcert/html/ssa-398330.html'
    label: 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e
  - url: 'https://cert-portal.siemens.com/productcert/html/ssa-419740.html'
    label: 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e
  - url: 'https://cert-portal.siemens.com/productcert/html/ssa-470355.html'
    label: 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e
  - url: 'https://cert-portal.siemens.com/productcert/html/ssa-565386.html'
    label: 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e
  - url: 'https://cert-portal.siemens.com/productcert/html/ssa-942865.html'
    label: 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2018/cve-2018-25032.json
  - url: 'https://access.redhat.com/security/cve/CVE-2018-25032'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2067945'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2018-25032'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2018-25032'
  - url: 'https://access.redhat.com/errata/RHSA-2022:2214'
  - url: 'https://access.redhat.com/errata/RHSA-2022:2213'
  - url: 'https://access.redhat.com/errata/RHSA-2023:0976'
  - url: 'https://access.redhat.com/errata/RHSA-2023:0975'
  - url: 'https://access.redhat.com/errata/RHSA-2023:0943'
  - url: 'https://access.redhat.com/errata/RHSA-2022:5439'
  - url: 'https://access.redhat.com/errata/RHSA-2022:4896'
  - url: 'https://access.redhat.com/errata/RHSA-2022:4584'
  - url: 'https://access.redhat.com/errata/RHSA-2022:4592'
  - url: 'https://access.redhat.com/errata/RHSA-2022:2197'
  - url: 'https://access.redhat.com/errata/RHSA-2022:1591'
  - url: 'https://access.redhat.com/errata/RHSA-2022:2192'
  - url: 'https://access.redhat.com/errata/RHSA-2022:1661'
  - url: 'https://access.redhat.com/errata/RHSA-2022:2198'
  - url: 'https://access.redhat.com/errata/RHSA-2022:4845'
  - url: 'https://access.redhat.com/errata/RHSA-2022:1642'
  - url: 'https://access.redhat.com/errata/RHSA-2022:2201'
  - url: 'https://access.redhat.com/errata/RHSA-2022:7813'
  - url: 'https://access.redhat.com/errata/RHSA-2022:8420'
tags:
  - nvd
  - exploit-available
  - csaf
  - vex
  - red-hat
epss: 0.51733
epssPercentile: 0.98925
ingestedAt: '2026-07-14T12:36:47.726Z'
exploits:
  github: 3
  githubRepos:
    - 'https://github.com/Trinadh465/external_zlib_4.4_CVE-2018-25032'
    - 'https://github.com/Satheesh575555/external_zlib-1.2.7_CVE-2018-25032'
    - 'https://github.com/Trinadh465/external_zlib_AOSP10_r33_CVE-2018-25032'
  checkedAt: '2026-09-21T15:24:39.445Z'
exploitAvailable: true
scores:
  nvd: 7.5
  vendor: 8.2
---

## Overview

zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.

## Affected

- `nokogiri < 1.13.4`
- `python >= 3.7.0, < 3.7.14`
- `python >= 3.8.0, < 3.8.14`
- `python >= 3.9.0, < 3.9.13`
- `python >= 3.10.0, < 3.10.5`
- `zlib >= 1.2.2.2, < 1.2.12`
- `debian_linux = 9.0`
- `debian_linux = 10.0`
- `debian_linux = 11.0`
- `fedora = 34`
- `fedora = 35`
- `fedora = 36`
- `mac_os_x >= 10.15, < 10.15.7`
- `mac_os_x = 10.15.7`
- `macos >= 11.0, < 11.6.6`
- `macos >= 12.0.0, < 12.4`
- `mariadb >= 10.3.0, < 10.3.36`
- `mariadb >= 10.4.0, < 10.4.26`
- `mariadb >= 10.5.0, < 10.5.17`
- `mariadb >= 10.6.0, < 10.6.9`
- `mariadb >= 10.7.0, < 10.7.5`
- `mariadb >= 10.8.0, < 10.8.4`
- `mariadb >= 10.9.0, < 10.9.2`
- `active_iq_unified_manager`
- `e-series_santricity_os_controller >= 11.0.0, <= 11.70.2`
- `management_services_for_element_software`
- `oncommand_workflow_automation`
- `ontap_select_deploy_administration_utility`
- `hci_compute_node`
- `h300s_firmware`
- `h500s_firmware`
- `h700s_firmware`
- `h410s_firmware`
- `h410c_firmware`
- `scalance_sc622-2c_firmware < 3.0`
- `scalance_sc626-2c_firmware < 3.0`
- `scalance_sc632-2c_firmware < 3.0`
- `scalance_sc636-2c_firmware < 3.0`
- `scalance_sc642-2c_firmware < 3.0`
- `scalance_sc646-2c_firmware < 3.0`
- `zulu = 6.45`
- `zulu = 7.52`
- `zulu = 8.60`
- `zulu = 11.54`
- `zulu = 13.46`
- `zulu = 15.38`
- `zulu = 17.32`
- `gotoassist < 11.9.18`

## Remediation

Upgrade past the affected range:

- `nokogiri 1.13.4`
- `python 3.10.5`
- `zlib 1.2.12`
- `mac_os_x 10.15.7`
- `macos 12.4`
- `mariadb 10.9.2`
- `scalance_sc622-2c_firmware 3.0`
- `scalance_sc626-2c_firmware 3.0`
- `scalance_sc632-2c_firmware 3.0`
- `scalance_sc636-2c_firmware 3.0`
- `scalance_sc642-2c_firmware 3.0`
- `scalance_sc646-2c_firmware 3.0`
- `gotoassist 11.9.18`

## Vendor advisories

- **RHSA-2022:2214** · Red Hat · fixed in: Red Hat Enterprise Linux Server (v. 6 ELS), Red Hat Enterprise Linux Server Optional (v. 6 ELS) · released 2022-05-11 · [advisory](https://access.redhat.com/errata/RHSA-2022:2214)
- **RHSA-2022:2213** · Red Hat · fixed in: Red Hat Enterprise Linux Client (v. 7), Red Hat Enterprise Linux Client Optional (v. 7), Red Hat Enterprise Linux ComputeNode Optional (v. 7), Red Hat Enterprise Linux Server (v. 7), Red Hat Enterprise Linux Server Optional (v. 7), Red Hat Enterprise Linux Workstation (v. 7), … · released 2022-05-11 · [advisory](https://access.redhat.com/errata/RHSA-2022:2213)
- **RHSA-2023:0976** · Red Hat · fixed in: Red Hat Enterprise Linux Server AUS (v. 7.4), Red Hat Enterprise Linux Server Optional AUS (v. 7.4) · released 2023-02-28 · [advisory](https://access.redhat.com/errata/RHSA-2023:0976)
- **RHSA-2023:0975** · Red Hat · fixed in: Red Hat Enterprise Linux Server AUS (v. 7.6), Red Hat Enterprise Linux Server Optional AUS (v. 7.6) · released 2023-02-28 · [advisory](https://access.redhat.com/errata/RHSA-2023:0975)
- **RHSA-2023:0943** · Red Hat · fixed in: Red Hat Enterprise Linux Server AUS (v. 7.7), Red Hat Enterprise Linux Server E4S (v. 7.7), Red Hat Enterprise Linux Server TUS (v. 7.7), Red Hat Enterprise Linux Server Optional AUS (v. 7.7), Red Hat Enterprise Linux Server Optional E4S (v. 7.7), Red Hat Enterprise Linux Server Optional TUS (v. 7.7) · released 2023-02-28 · [advisory](https://access.redhat.com/errata/RHSA-2023:0943)
- **RHSA-2022:5439** · Red Hat · fixed in: Red Hat Virtualization 4 Hypervisor for RHEL 7, RHEL 7-based RHEV-H for RHEV 4 (build requirements) · released 2022-07-01 · [advisory](https://access.redhat.com/errata/RHSA-2022:5439)
- **RHSA-2022:4896** · Red Hat · fixed in: Red Hat Virtualization 4 Hypervisor for RHEL 8 · released 2022-06-03 · [advisory](https://access.redhat.com/errata/RHSA-2022:4896)
- **RHSA-2022:4584** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 9), Red Hat Enterprise Linux BaseOS (v. 9), Red Hat CodeReady Linux Builder (v. 9) · released 2022-05-17 · [advisory](https://access.redhat.com/errata/RHSA-2022:4584)
- **RHSA-2022:4592** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 9), Red Hat Enterprise Linux BaseOS (v. 9) · released 2022-05-18 · [advisory](https://access.redhat.com/errata/RHSA-2022:4592)
- **RHSA-2022:2197** · Red Hat · fixed in: Red Hat Enterprise Linux BaseOS E4S (v. 8.1) · released 2022-05-11 · [advisory](https://access.redhat.com/errata/RHSA-2022:2197)
- **RHSA-2022:1591** · Red Hat · fixed in: Red Hat Enterprise Linux BaseOS E4S (v. 8.1) · released 2022-04-26 · [advisory](https://access.redhat.com/errata/RHSA-2022:1591)
