CVE-2016-9840

Aliases:RHSA-2025:10541RHSA-2025:11048RHSA-2025:12013RHSA-2025:13947RHSA-2025:8314RHSA-2025:8395DEBIAN-CVE-2016-9840CGA-22w5-rxc5-vhc2CGA-2p93-pgjh-mvjjCGA-35fq-mvrh-p97mCGA-3hwx-qgm4-xp8fCGA-4mw7-cqjf-mpqfCGA-4p7j-vp2m-vr7rCGA-4w9h-x2rp-crmqCGA-54qq-c5h2-vf23CGA-58mv-rxc5-7fg3CGA-5vq7-7hqm-jjfgCGA-5xc8-7444-wqmmCGA-78xq-8h7m-m475CGA-8355-fcvm-9477CGA-89xh-vfv8-m5qcCGA-8frp-pg9q-vgjqCGA-8jr7-2q4r-pgc7CGA-8q3r-c4j5-7c6fCGA-95jc-gcqh-qm73CGA-9c7j-f2fg-qrvpCGA-9p63-vcc6-9fxqCGA-9vjm-22wx-36gvCGA-9w53-vf2q-p6fcCGA-c3hr-54p8-82vmCGA-cjgx-fv22-56pgCGA-cjrm-q26m-8jwfCGA-fp3w-vgxr-vjcgCGA-fqgr-4vf8-fx27CGA-g4x5-qfwj-96m4CGA-gcm2-v5q2-3rqgCGA-h7g8-c25x-gw3xCGA-h8pg-h598-9m8hCGA-hvp6-8q4v-4gcgCGA-m6qq-phqx-fv8wCGA-mm52-jffv-39vxCGA-mxff-8qm9-rm48CGA-p8qp-6vr7-7q5wCGA-qrw3-4xx7-9wp8CGA-rpmw-9ppf-55j8CGA-rqfv-7jph-wp56CGA-v39m-r334-2mwrCGA-vmv4-c87m-mrhpCGA-w79g-ff9f-9x7rCGA-wgxm-53vm-fv53CGA-wpq5-xwcp-7m87
Advisory lineage Upstream: 0 Downstream: 37
Modified
Published: 23 May 2017, 03:56
Last modified:14 Jul 2026, 11:44

Vulnerability Summary

Overall Risk (default)
medium
36/100
CVSS Score
8.8 HIGH
v3.1 (nvd)
EPSS Score
4.79% LOW
5% probability -8.21%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

23 May 2017, 03:56
Published
Vulnerability first disclosed
14 Jul 2026, 11:44
Last Modified
Vulnerability information updated

Description

inftrees.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.

CVSS Metrics

  • v3.1HIGHScore: 8.8CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
  • v3.0HIGHScore: 8.8CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
  • v2.0MEDIUMScore: 6.8AV:N/AC:M/Au:N/C:P/I:P/A:P

EPSS Trends

Current EPSS score: 4.79% Percentile: 92%

Affected Systems

  • chainguardmysql-8.0

    < 8.0.38-r0

  • chainguardmysql-8.0-client

    < 8.0.38-r0

  • chainguardmysql-8.0-dev

    < 8.0.38-r0

  • chainguardmysql-8.0-iamguarded-compat

    < 8.0.38-r0

  • chainguardmysql-8.0-oci-entrypoint

    < 8.0.38-r0

  • chainguardmysql-8.0-oci-entrypoint-compat

    < 8.0.38-r0

  • chainguardopenjdk-11-openj9-default-policy

    < 0.53.0-r0

  • chainguardopenjdk-17-openj9-default-policy

    < 0.53.0-r0

  • chainguardopenjdk-21-openj9-default-policy

    < 0.53.0-r0

  • chainguardopenjdk-25-openj9

    < 0.59.0-r1

  • chainguardopenjdk-25-openj9-dbg

    < 0.59.0-r1

  • chainguardopenjdk-25-openj9-default-jdk

    < 0.59.0-r1

  • chainguardopenjdk-25-openj9-default-jvm

    < 0.59.0-r1

  • chainguardopenjdk-25-openj9-jmods

    < 0.59.0-r1

  • chainguardopenjdk-25-openj9-jre

    < 0.59.0-r1

  • chainguardopenjdk-26-openj9

    < 0.59.0-r1

  • chainguardopenjdk-26-openj9-dbg

    < 0.59.0-r1

  • chainguardopenjdk-26-openj9-default-jdk

    < 0.59.0-r1

  • chainguardopenjdk-26-openj9-default-jvm

    < 0.59.0-r1

  • chainguardopenjdk-26-openj9-jmods

    < 0.59.0-r1

  • chainguardopenjdk-26-openj9-jre

    < 0.59.0-r1

  • chainguardopenjdk-8-openj9-dbg

    < 0.53.0-r1

  • appleiphone_os

    < 11

  • applemac_os_x

    ≥ 10.0.0, < 10.13.0

  • appletvos

    < 11.0

  • applewatchos

    < 4

  • boostboost

    < 1.78.0

  • canonicalubuntu_linux

    16.04 | 18.04

  • debianrsync

    < 3.1.3-6 | < 3.1.3-6 | < 3.1.3-6 | < 3.1.3-6

  • debianzlib

    < 1:1.2.8.dfsg-3 | < 1:1.2.8.dfsg-3 | < 1:1.2.8.dfsg-3 | < 1:1.2.8.dfsg-3

  • debiandebian_linux

    8.0

  • nodejsnode.js

    ≥ 4.0.0, ≤ 4.1.2 | ≥ 4.2.0, < 4.8.2 | ≥ 6.0.0, ≤ 6.8.1 | ≥ 6.9.0, < 6.10.2 | ≥ 7.0.0, < 7.6.0

  • opensuseleap

    42.1 | 42.2

  • opensuseopensuse

    13.2

  • oracledatabase_server

    18c

  • oraclejdk

    1.6.0:update161 | 1.7.0:update151 | 1.8.0:update144

  • oraclejre

    1.6.0:update161 | 1.7.0:update151 | 1.8.0:update144

  • oraclemysql

    ≥ 5.5.0, ≤ 5.5.61 | ≥ 5.6.0, ≤ 5.6.41 | ≥ 5.7.0, ≤ 5.7.23 | ≥ 8.0.0, ≤ 8.0.12

  • redhatenterprise_linux_desktop

    6.0 | 7.0

  • redhatenterprise_linux_eus

    7.4 | 7.5

  • redhatenterprise_linux_server

    6.0 | 7.0

  • redhatenterprise_linux_workstation

    6.0 | 7.0

  • redhatsatellite

    5.8

  • redhatminizip

    < 0:1.2.7-21.el7_9.1

  • redhatminizip-devel

    < 0:1.2.7-21.el7_9.1

  • redhatrsync

    < 0:3.1.3-12.el8_4.5 | < 0:3.1.3-7.el8_2.5 | < 0:3.1.3-14.el8_6.8 | < 0:3.1.3-20.el8_8.3 | < 0:3.1.3-23.el8_10

  • redhatrsync-daemon

    < 0:3.1.3-12.el8_4.5 | < 0:3.1.3-7.el8_2.5 | < 0:3.1.3-14.el8_6.8 | < 0:3.1.3-20.el8_8.3 | < 0:3.1.3-23.el8_10

  • redhatrsync-debuginfo

    < 0:3.1.3-12.el8_4.5 | < 0:3.1.3-7.el8_2.5 | < 0:3.1.3-14.el8_6.8 | < 0:3.1.3-20.el8_8.3 | < 0:3.1.3-23.el8_10

  • redhatrsync-debugsource

    < 0:3.1.3-12.el8_4.5 | < 0:3.1.3-7.el8_2.5 | < 0:3.1.3-14.el8_6.8 | < 0:3.1.3-20.el8_8.3 | < 0:3.1.3-23.el8_10

  • redhatzlib

    < 0:1.2.7-21.el7_9.1

Showing first 50 affected entries in server-rendered view.

References (51)