CVE-2016-9841
Aliases:DEBIAN-CVE-2016-9841CGA-293m-qm7g-h392CGA-345j-fw6c-572wCGA-3rcm-c8wv-2hvhCGA-3xmx-jh34-9f84CGA-53m9-q84w-wf6mCGA-5w5g-h3jj-6q49CGA-66pf-9pfx-ww7rCGA-6c97-rjf5-vgq5CGA-6r8p-9g7v-wh7xCGA-73qc-v56x-mpqjCGA-76g8-2xm9-9wvpCGA-7g45-vh4x-xfhfCGA-8qg8-95q2-j59gCGA-8x38-4xgv-xprqCGA-97hq-f5jp-9m93CGA-9fh9-57mj-68v2CGA-c7rj-gw47-jqpwCGA-cp6x-52vj-7wh2CGA-cvhv-q282-767wCGA-f4gr-m8rf-xjj8CGA-f67p-j7cr-947jCGA-f9c3-xx88-c3cwCGA-ffcm-rqfr-9h47CGA-fh94-24cw-pvqpCGA-fm9g-x757-g4jcCGA-h7mv-h3qg-2xghCGA-j69p-q8pc-2f83CGA-jj5h-hchm-32c4CGA-mv44-87g7-rm39CGA-pg76-3q6h-gvmcCGA-pqhg-73g7-6mm5CGA-pxm2-9fpm-729wCGA-qwf7-j9xg-hx32CGA-r9j4-9rw8-4854CGA-rhpx-hqqc-vpgrCGA-rrv6-63qm-2j9gCGA-v33c-pwpr-q68pCGA-vg86-crch-8wr3CGA-vgjc-qcfq-43w2CGA-w9v7-w5xf-7764CGA-wjx7-rwfh-wmxmCGA-xfvv-vr3p-cr6xCGA-xj72-mpf5-gqg4CGA-xrg3-p9g9-3vv6
Advisory lineage Upstream: 0 Downstream: 35
Modified
Published: 23 May 2017, 03:56
Last modified:14 Jul 2026, 11:44
Vulnerability Summary
Overall Risk (default)
high
70/100 CVSS Score
9.8 CRITICAL
v3.1 (nvd)
EPSS Score
7.55% LOW
8% probability -12.73%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
23 May 2017, 03:56
Published
Vulnerability first disclosed
14 Jul 2026, 11:44
Last Modified
Vulnerability information updated
Description
inffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.
CVSS Metrics
- v3.1•CRITICAL•Score: 9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- v2.0•HIGH•Score: 7.5AV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS Trends
Current EPSS score: 7.55%• Percentile: 94%
Affected Systems
- chainguard•mysql-8.0
< 8.0.38-r0
- chainguard•mysql-8.0-client
< 8.0.38-r0
- chainguard•mysql-8.0-dev
< 8.0.38-r0
- chainguard•mysql-8.0-iamguarded-compat
< 8.0.38-r0
- chainguard•mysql-8.0-oci-entrypoint
< 8.0.38-r0
- chainguard•mysql-8.0-oci-entrypoint-compat
< 8.0.38-r0
- chainguard•openjdk-11-openj9-default-policy
< 0.53.0-r0
- chainguard•openjdk-17-openj9-default-policy
< 0.53.0-r0
- chainguard•openjdk-21-openj9-default-policy
< 0.53.0-r0
- chainguard•openjdk-25-openj9
< 0.59.0-r1
- chainguard•openjdk-25-openj9-dbg
< 0.59.0-r1
- chainguard•openjdk-25-openj9-default-jdk
< 0.59.0-r1
- chainguard•openjdk-25-openj9-default-jvm
< 0.59.0-r1
- chainguard•openjdk-25-openj9-jmods
< 0.59.0-r1
- chainguard•openjdk-25-openj9-jre
< 0.59.0-r1
- chainguard•openjdk-26-openj9
< 0.59.0-r1
- chainguard•openjdk-26-openj9-dbg
< 0.59.0-r1
- chainguard•openjdk-26-openj9-default-jdk
< 0.59.0-r1
- chainguard•openjdk-26-openj9-default-jvm
< 0.59.0-r1
- chainguard•openjdk-26-openj9-jmods
< 0.59.0-r1
- chainguard•openjdk-26-openj9-jre
< 0.59.0-r1
- chainguard•openjdk-8-openj9-dbg
< 0.53.0-r1
- apple•iphone_os
< 11
- apple•mac_os_x
≥ 10.0.0, < 10.13.0
- apple•tvos
< 11.0
- apple•watchos
< 4
- canonical•ubuntu_linux
16.04 | 18.04
- debian•rsync
< 3.1.3-6 | < 3.1.3-6 | < 3.1.3-6 | < 3.1.3-6
- debian•zlib
< 1:1.2.8.dfsg-4 | < 1:1.2.8.dfsg-4 | < 1:1.2.8.dfsg-4 | < 1:1.2.8.dfsg-4
- debian•debian_linux
8.0
- netapp•active_iq_unified_manager
≥ 7.3 | ≥ 9.5
- netapp•cloud_backup
na
- netapp•e-series_santricity_management
na
- netapp•e-series_santricity_os_controller
≥ 11.0.0, ≤ 11.70.1
- netapp•e-series_santricity_storage_manager
na
- netapp•e-series_santricity_web_services
na
- netapp•hci_storage_node_bios
na
- netapp•oncommand_balance
na
- netapp•oncommand_insight
na
- netapp•oncommand_performance_manager
na
- netapp•oncommand_shift
na
- netapp•oncommand_unified_manager
≤ 7.1 | na
- netapp•oncommand_workflow_automation
na
- netapp•snapmanager
na
- netapp•solidfire
na
- netapp•steelstore_cloud_integrated_storage
na
- netapp•storage_replication_adapter_for_clustered_data_ontap
na
- netapp•symantec_netbackup
na
- netapp•vasa_provider_for_clustered_data_ontap
≥ 7.2
- netapp•virtual_storage_console
na
Showing first 50 affected entries in server-rendered view.
References (35)
- https://access.redhat.com/errata/RHSA-2017:1221
- https://access.redhat.com/errata/RHSA-2017:1220
- https://access.redhat.com/errata/RHSA-2017:3047
- http://www.openwall.com/lists/oss-security/2016/12/05/21
- http://www.securityfocus.com/bid/95131
- https://access.redhat.com/errata/RHSA-2017:3046
- http://lists.opensuse.org/opensuse-updates/2017-01/msg00050.html
- http://www.securitytracker.com/id/1039596
- https://security.gentoo.org/glsa/201701-56
- http://www.securitytracker.com/id/1039427
- https://access.redhat.com/errata/RHSA-2017:1222
- http://lists.opensuse.org/opensuse-updates/2017-01/msg00053.html
- https://access.redhat.com/errata/RHSA-2017:3453
- http://lists.opensuse.org/opensuse-updates/2016-12/msg00127.html
- https://access.redhat.com/errata/RHSA-2017:2999
- https://lists.debian.org/debian-lts-announce/2019/03/msg00027.html
- https://usn.ubuntu.com/4246-1/
- https://lists.debian.org/debian-lts-announce/2020/01/msg00030.html
- https://usn.ubuntu.com/4292-1/
- http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html
- http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
- https://www.oracle.com/security-alerts/cpujul2020.html
- http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html
- https://support.apple.com/HT208144
- https://wiki.mozilla.org/MOSS/Secure_Open_Source/Completed#zlib
- https://support.apple.com/HT208113
- https://support.apple.com/HT208112
- https://support.apple.com/HT208115
- https://wiki.mozilla.org/images/0/09/Zlib-report.pdf
- https://bugzilla.redhat.com/show_bug.cgi?id=1402346
- https://github.com/madler/zlib/commit/9aaec95e82117c1cb0f9624264c3618fc380cecb
- https://security.netapp.com/advisory/ntap-20171019-0001/
- https://security.gentoo.org/glsa/202007-54
- https://cert-portal.siemens.com/productcert/html/ssa-470355.html
- https://security-tracker.debian.org/tracker/CVE-2016-9841