---
id: CVE-2022-37434
title: >-
  zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in
  inflate in inflate.c via a large gzip header extra field
summary: >-
  zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in
  inflate in inflate.c via a large gzip header extra field. NOTE: only
  applications that call inflateGetHeader are affected. Some common applications
  bundle the af…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-787
  - CWE-120
  - CWE-119
vendor: zlib
product: zlib
affected:
  - zlib <= 1.2.12
  - fedora = 35
  - fedora = 36
  - fedora = 37
  - debian_linux = 10.0
  - active_iq_unified_manager
  - hci
  - management_services_for_element_software
  - oncommand_workflow_automation
  - ontap_select_deploy_administration_utility
  - storagegrid
  - hci_compute_node
  - h300s_firmware
  - h500s_firmware
  - h700s_firmware
  - ipados < 15.7.1
  - iphone_os < 15.7.1
  - 'iphone_os >= 16.0, < 16.1'
  - 'macos >= 11.0, < 11.7.1'
  - 'macos >= 12.0.0, < 12.6.1'
  - watchos < 9.1
  - 'stormshield_network_security >= 3.7.31, < 3.7.34'
  - 'stormshield_network_security >= 3.11.0, < 3.11.22'
  - 'stormshield_network_security >= 4.3.0, < 4.3.16'
  - 'stormshield_network_security >= 4.6.0, < 4.6.3'
patched:
  - ipados 15.7.1
  - iphone_os 16.1
  - macos 12.6.1
  - watchos 9.1
  - stormshield_network_security 4.6.3
published: '2022-08-05'
updated: '2026-07-14'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2022-37434'
references:
  - url: 'http://seclists.org/fulldisclosure/2022/Oct/37'
    label: cve@mitre.org
  - url: 'http://seclists.org/fulldisclosure/2022/Oct/38'
    label: cve@mitre.org
  - url: 'http://seclists.org/fulldisclosure/2022/Oct/41'
    label: cve@mitre.org
  - url: 'http://seclists.org/fulldisclosure/2022/Oct/42'
    label: cve@mitre.org
  - url: 'http://www.openwall.com/lists/oss-security/2022/08/05/2'
    label: cve@mitre.org
  - url: 'http://www.openwall.com/lists/oss-security/2022/08/09/1'
    label: cve@mitre.org
  - url: 'https://github.com/curl/curl/issues/9271'
    label: cve@mitre.org
  - url: 'https://github.com/ivd38/zlib_overflow'
    label: cve@mitre.org
  - url: >-
      https://github.com/madler/zlib/blob/21767c654d31d2dccdde4330529775c6c5fd5389/zlib.h#L1062-L1063
    label: cve@mitre.org
  - url: >-
      https://github.com/madler/zlib/commit/1eb7682f845ac9e9bf9ae35bbfb3bad5dacbd91d
    label: cve@mitre.org
  - url: >-
      https://github.com/madler/zlib/commit/eff308af425b67093bab25f80f1ae950166bece1
    label: cve@mitre.org
  - url: >-
      https://github.com/nodejs/node/blob/75b68c6e4db515f76df73af476eccf382bbcb00a/deps/zlib/inflate.c#L762-L764
    label: cve@mitre.org
  - url: 'https://lists.debian.org/debian-lts-announce/2022/09/msg00012.html'
    label: cve@mitre.org
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JWN4VE3JQR4O2SOUS5TXNLANRPMHWV4I/
    label: cve@mitre.org
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NMBOJ77A7T7PQCARMDUK75TE6LLESZ3O/
    label: cve@mitre.org
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PAVPQNCG3XRLCLNSQRM3KAN5ZFMVXVTY/
    label: cve@mitre.org
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X5U7OTKZSHY2I3ZFJSR2SHFHW72RKGDK/
    label: cve@mitre.org
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YRQAI7H4M4RQZ2IWZUEEXECBE5D56BH2/
    label: cve@mitre.org
  - url: 'https://security.netapp.com/advisory/ntap-20220901-0005/'
    label: cve@mitre.org
  - url: 'https://security.netapp.com/advisory/ntap-20230427-0007/'
    label: cve@mitre.org
  - url: 'https://support.apple.com/kb/HT213488'
    label: cve@mitre.org
  - url: 'https://support.apple.com/kb/HT213489'
    label: cve@mitre.org
  - url: 'https://support.apple.com/kb/HT213490'
    label: cve@mitre.org
  - url: 'https://support.apple.com/kb/HT213491'
    label: cve@mitre.org
  - url: 'https://support.apple.com/kb/HT213493'
    label: cve@mitre.org
  - url: 'https://support.apple.com/kb/HT213494'
    label: cve@mitre.org
  - url: 'https://www.debian.org/security/2022/dsa-5218'
    label: cve@mitre.org
  - url: 'http://seclists.org/fulldisclosure/2022/Oct/37'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://seclists.org/fulldisclosure/2022/Oct/38'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://seclists.org/fulldisclosure/2022/Oct/41'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://seclists.org/fulldisclosure/2022/Oct/42'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.openwall.com/lists/oss-security/2022/08/05/2'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.openwall.com/lists/oss-security/2022/08/09/1'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://github.com/curl/curl/issues/9271'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://github.com/ivd38/zlib_overflow'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://github.com/madler/zlib/blob/21767c654d31d2dccdde4330529775c6c5fd5389/zlib.h#L1062-L1063
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://github.com/madler/zlib/commit/eff308af425b67093bab25f80f1ae950166bece1
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://github.com/nodejs/node/blob/75b68c6e4db515f76df73af476eccf382bbcb00a/deps/zlib/inflate.c#L762-L764
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://lists.debian.org/debian-lts-announce/2022/09/msg00012.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JWN4VE3JQR4O2SOUS5TXNLANRPMHWV4I/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NMBOJ77A7T7PQCARMDUK75TE6LLESZ3O/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PAVPQNCG3XRLCLNSQRM3KAN5ZFMVXVTY/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X5U7OTKZSHY2I3ZFJSR2SHFHW72RKGDK/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YRQAI7H4M4RQZ2IWZUEEXECBE5D56BH2/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.netapp.com/advisory/ntap-20220901-0005/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.netapp.com/advisory/ntap-20230427-0007/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://support.apple.com/kb/HT213488'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://support.apple.com/kb/HT213489'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://support.apple.com/kb/HT213490'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://support.apple.com/kb/HT213491'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://support.apple.com/kb/HT213493'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://support.apple.com/kb/HT213494'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.debian.org/security/2022/dsa-5218'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://cert-portal.siemens.com/productcert/html/ssa-150063.html'
    label: 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e
  - url: 'https://cert-portal.siemens.com/productcert/html/ssa-202008.html'
    label: 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e
  - url: 'https://cert-portal.siemens.com/productcert/html/ssa-398330.html'
    label: 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e
  - url: 'https://cert-portal.siemens.com/productcert/html/ssa-470355.html'
    label: 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e
  - url: 'https://cert-portal.siemens.com/productcert/html/ssa-561322.html'
    label: 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e
  - url: 'https://github.com/curl/curl/issues/9271'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-37434.json
  - url: 'https://access.redhat.com/security/cve/CVE-2022-37434'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2116639'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2022-37434'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2022-37434'
  - url: 'https://access.redhat.com/errata/RHSA-2023:1095'
  - url: 'https://access.redhat.com/errata/RHSA-2022:7314'
  - url: 'https://access.redhat.com/errata/RHSA-2022:8291'
  - url: 'https://access.redhat.com/errata/RHSA-2024:0254'
  - url: 'https://access.redhat.com/errata/RHSA-2022:7106'
  - url: 'https://access.redhat.com/errata/RHSA-2022:7793'
tags:
  - nvd
  - exploit-available
  - csaf
  - vex
  - red-hat
  - score-dispute
epss: 0.17852
epssPercentile: 0.97042
ingestedAt: '2026-07-14T12:36:47.749Z'
exploits:
  github: 2
  githubRepos:
    - 'https://github.com/xen0bit/CVE-2022-37434_poc'
    - 'https://github.com/Trinadh465/external_zlib_CVE-2022-37434'
  checkedAt: '2026-09-24T07:52:49.275Z'
exploitAvailable: true
scores:
  nvd: 9.8
  vendor: 7
---

## Overview

zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHeader are affected. Some common applications bundle the affected zlib source code but may be unable to call inflateGetHeader (e.g., see the nodejs/node reference).

## Affected

- `zlib <= 1.2.12`
- `fedora = 35`
- `fedora = 36`
- `fedora = 37`
- `debian_linux = 10.0`
- `active_iq_unified_manager`
- `hci`
- `management_services_for_element_software`
- `oncommand_workflow_automation`
- `ontap_select_deploy_administration_utility`
- `storagegrid`
- `hci_compute_node`
- `h300s_firmware`
- `h500s_firmware`
- `h700s_firmware`
- `ipados < 15.7.1`
- `iphone_os < 15.7.1`
- `iphone_os >= 16.0, < 16.1`
- `macos >= 11.0, < 11.7.1`
- `macos >= 12.0.0, < 12.6.1`
- `watchos < 9.1`
- `stormshield_network_security >= 3.7.31, < 3.7.34`
- `stormshield_network_security >= 3.11.0, < 3.11.22`
- `stormshield_network_security >= 4.3.0, < 4.3.16`
- `stormshield_network_security >= 4.6.0, < 4.6.3`

## Remediation

Upgrade past the affected range:

- `ipados 15.7.1`
- `iphone_os 16.1`
- `macos 12.6.1`
- `watchos 9.1`
- `stormshield_network_security 4.6.3`

## Vendor advisories

- **RHSA-2023:1095** · Red Hat · fixed in: Red Hat Enterprise Linux Client (v. 7), Red Hat Enterprise Linux Client Optional (v. 7), Red Hat Enterprise Linux ComputeNode Optional (v. 7), Red Hat Enterprise Linux Server (v. 7), Red Hat Enterprise Linux Server Optional (v. 7), Red Hat Enterprise Linux Workstation (v. 7), … · released 2023-03-07 · [advisory](https://access.redhat.com/errata/RHSA-2023:1095)
- **RHSA-2022:7314** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 9), Red Hat Enterprise Linux BaseOS (v. 9), Red Hat CodeReady Linux Builder (v. 9) · released 2022-11-02 · [advisory](https://access.redhat.com/errata/RHSA-2022:7314)
- **RHSA-2022:8291** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 9), Red Hat Enterprise Linux BaseOS (v. 9) · released 2022-11-15 · [advisory](https://access.redhat.com/errata/RHSA-2022:8291)
- **RHSA-2024:0254** · Red Hat · fixed in: Red Hat Enterprise Linux BaseOS EUS (v.8.6) · released 2024-01-15 · [advisory](https://access.redhat.com/errata/RHSA-2024:0254)
- **RHSA-2022:7106** · Red Hat · fixed in: Red Hat Enterprise Linux BaseOS (v. 8), Red Hat Enterprise Linux CRB (v. 8) · released 2022-10-25 · [advisory](https://access.redhat.com/errata/RHSA-2022:7106)
- **RHSA-2022:7793** · Red Hat · fixed in: Red Hat Enterprise Linux BaseOS (v. 8) · released 2022-11-08 · [advisory](https://access.redhat.com/errata/RHSA-2022:7793)
- **Red Hat VEX** · Moderate · affected: Red Hat build of Quarkus, Red Hat Enterprise Linux 6 · no fix planned: Red Hat Enterprise Linux 6, Red Hat build of Quarkus · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-37434.json)
