CVE-2016-9840
Vulnerability Summary
Timeline
Description
inftrees.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.
CVSS Metrics
- v3.1•HIGH•Score: 8.8CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- v3.0•HIGH•Score: 8.8CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- v2.0•MEDIUM•Score: 6.8AV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS Trends
Current EPSS score: 4.79%• Percentile: 92%
Affected Systems
- chainguard•mysql-8.0
< 8.0.38-r0
- chainguard•mysql-8.0-client
< 8.0.38-r0
- chainguard•mysql-8.0-dev
< 8.0.38-r0
- chainguard•mysql-8.0-iamguarded-compat
< 8.0.38-r0
- chainguard•mysql-8.0-oci-entrypoint
< 8.0.38-r0
- chainguard•mysql-8.0-oci-entrypoint-compat
< 8.0.38-r0
- chainguard•openjdk-11-openj9-default-policy
< 0.53.0-r0
- chainguard•openjdk-17-openj9-default-policy
< 0.53.0-r0
- chainguard•openjdk-21-openj9-default-policy
< 0.53.0-r0
- chainguard•openjdk-25-openj9
< 0.59.0-r1
- chainguard•openjdk-25-openj9-dbg
< 0.59.0-r1
- chainguard•openjdk-25-openj9-default-jdk
< 0.59.0-r1
- chainguard•openjdk-25-openj9-default-jvm
< 0.59.0-r1
- chainguard•openjdk-25-openj9-jmods
< 0.59.0-r1
- chainguard•openjdk-25-openj9-jre
< 0.59.0-r1
- chainguard•openjdk-26-openj9
< 0.59.0-r1
- chainguard•openjdk-26-openj9-dbg
< 0.59.0-r1
- chainguard•openjdk-26-openj9-default-jdk
< 0.59.0-r1
- chainguard•openjdk-26-openj9-default-jvm
< 0.59.0-r1
- chainguard•openjdk-26-openj9-jmods
< 0.59.0-r1
- chainguard•openjdk-26-openj9-jre
< 0.59.0-r1
- chainguard•openjdk-8-openj9-dbg
< 0.53.0-r1
- apple•iphone_os
< 11
- apple•mac_os_x
≥ 10.0.0, < 10.13.0
- apple•tvos
< 11.0
- apple•watchos
< 4
- boost•boost
< 1.78.0
- canonical•ubuntu_linux
16.04 | 18.04
- debian•rsync
< 3.1.3-6 | < 3.1.3-6 | < 3.1.3-6 | < 3.1.3-6
- debian•zlib
< 1:1.2.8.dfsg-3 | < 1:1.2.8.dfsg-3 | < 1:1.2.8.dfsg-3 | < 1:1.2.8.dfsg-3
- debian•debian_linux
8.0
- nodejs•node.js
≥ 4.0.0, ≤ 4.1.2 | ≥ 4.2.0, < 4.8.2 | ≥ 6.0.0, ≤ 6.8.1 | ≥ 6.9.0, < 6.10.2 | ≥ 7.0.0, < 7.6.0
- opensuse•leap
42.1 | 42.2
- opensuse•opensuse
13.2
- oracle•database_server
18c
- oracle•jdk
1.6.0:update161 | 1.7.0:update151 | 1.8.0:update144
- oracle•jre
1.6.0:update161 | 1.7.0:update151 | 1.8.0:update144
- oracle•mysql
≥ 5.5.0, ≤ 5.5.61 | ≥ 5.6.0, ≤ 5.6.41 | ≥ 5.7.0, ≤ 5.7.23 | ≥ 8.0.0, ≤ 8.0.12
- redhat•enterprise_linux_desktop
6.0 | 7.0
- redhat•enterprise_linux_eus
7.4 | 7.5
- redhat•enterprise_linux_server
6.0 | 7.0
- redhat•enterprise_linux_workstation
6.0 | 7.0
- redhat•satellite
5.8
- redhat•minizip
< 0:1.2.7-21.el7_9.1
- redhat•minizip-devel
< 0:1.2.7-21.el7_9.1
- redhat•rsync
< 0:3.1.3-12.el8_4.5 | < 0:3.1.3-7.el8_2.5 | < 0:3.1.3-14.el8_6.8 | < 0:3.1.3-20.el8_8.3 | < 0:3.1.3-23.el8_10
- redhat•rsync-daemon
< 0:3.1.3-12.el8_4.5 | < 0:3.1.3-7.el8_2.5 | < 0:3.1.3-14.el8_6.8 | < 0:3.1.3-20.el8_8.3 | < 0:3.1.3-23.el8_10
- redhat•rsync-debuginfo
< 0:3.1.3-12.el8_4.5 | < 0:3.1.3-7.el8_2.5 | < 0:3.1.3-14.el8_6.8 | < 0:3.1.3-20.el8_8.3 | < 0:3.1.3-23.el8_10
- redhat•rsync-debugsource
< 0:3.1.3-12.el8_4.5 | < 0:3.1.3-7.el8_2.5 | < 0:3.1.3-14.el8_6.8 | < 0:3.1.3-20.el8_8.3 | < 0:3.1.3-23.el8_10
- redhat•zlib
< 0:1.2.7-21.el7_9.1
Showing first 50 affected entries in server-rendered view.
References (51)
- https://access.redhat.com/errata/RHSA-2017:1221
- https://access.redhat.com/errata/RHSA-2017:1220
- https://access.redhat.com/errata/RHSA-2017:3047
- http://www.openwall.com/lists/oss-security/2016/12/05/21
- http://www.securityfocus.com/bid/95131
- https://access.redhat.com/errata/RHSA-2017:3046
- http://lists.opensuse.org/opensuse-updates/2017-01/msg00050.html
- https://security.gentoo.org/glsa/201701-56
- http://www.securitytracker.com/id/1039427
- https://access.redhat.com/errata/RHSA-2017:1222
- http://lists.opensuse.org/opensuse-updates/2017-01/msg00053.html
- https://access.redhat.com/errata/RHSA-2017:3453
- http://lists.opensuse.org/opensuse-updates/2016-12/msg00127.html
- https://access.redhat.com/errata/RHSA-2017:2999
- https://lists.debian.org/debian-lts-announce/2019/03/msg00027.html
- https://usn.ubuntu.com/4246-1/
- https://lists.debian.org/debian-lts-announce/2020/01/msg00030.html
- https://usn.ubuntu.com/4292-1/
- http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
- https://www.oracle.com/security-alerts/cpujul2020.html
- http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html
- https://support.apple.com/HT208144
- https://github.com/madler/zlib/commit/6a043145ca6e9c55184013841a67b2fef87e44c0
- https://wiki.mozilla.org/MOSS/Secure_Open_Source/Completed#zlib
- https://bugzilla.redhat.com/show_bug.cgi?id=1402345
- https://support.apple.com/HT208113
- https://support.apple.com/HT208112
- https://support.apple.com/HT208115
- https://wiki.mozilla.org/images/0/09/Zlib-report.pdf
- https://security.gentoo.org/glsa/202007-54
- https://cert-portal.siemens.com/productcert/html/ssa-470355.html
- https://access.redhat.com/errata/RHSA-2025:10541
- https://access.redhat.com/security/updates/classification/#low
- https://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_10541.json
- https://access.redhat.com/security/cve/CVE-2016-9840
- https://www.cve.org/CVERecord?id=CVE-2016-9840
- https://nvd.nist.gov/vuln/detail/CVE-2016-9840
- https://docs.google.com/document/d/10i1KZS5so8xDqH2rplRa2xet0tyTvvJlLbQQmZIUIKE/edit#heading=h.t13tvnx4loq7
- https://access.redhat.com/errata/RHSA-2025:11048
- https://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_11048.json
- https://access.redhat.com/errata/RHSA-2025:12013
- https://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_12013.json
- https://access.redhat.com/errata/RHSA-2025:13947
- https://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_13947.json
- https://access.redhat.com/errata/RHSA-2025:8314
- https://access.redhat.com/security/updates/classification/#important
- https://bugzilla.redhat.com/show_bug.cgi?id=2366317
- https://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_8314.json
- https://access.redhat.com/errata/RHSA-2025:8395
- https://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_8395.json
- https://security-tracker.debian.org/tracker/CVE-2016-9840