CVE-2016-9842

Aliases:DEBIAN-CVE-2016-9842CGA-26v9-mh34-g2p2CGA-3m69-f9x5-g3p4CGA-47w6-rhh8-vx4mCGA-4rqw-qjgj-34qvCGA-57wm-xwr6-4v7hCGA-5cmj-hr78-9g8xCGA-73ff-jw59-w4wqCGA-7qhr-rj8m-f5h2CGA-85r9-8p2v-vgvcCGA-86p3-6x36-c9r5CGA-8v6x-7g85-ff4gCGA-94mh-6wvr-v3wmCGA-97px-24pf-qhpqCGA-9frv-7fh4-5m82CGA-9vg5-qh98-9wq3CGA-cm3j-4hcm-v2jmCGA-f44g-xgrh-4w77CGA-f6jr-9hmj-47jxCGA-fcg8-2mmc-cpv3CGA-g3hp-vcw4-jr4xCGA-hg8c-vj25-vg3vCGA-hqcp-4rxp-wh4fCGA-j3gw-w4q5-wqp3CGA-jgmh-qxjc-wv92CGA-m2fp-hv33-6pggCGA-m5vg-7pfq-x2qqCGA-mh53-g9c8-fpqmCGA-pgxm-3xx2-mfxwCGA-phc9-qxw5-49xqCGA-pqqp-f5fh-9j6hCGA-q47w-hqxv-792hCGA-q82c-gr92-fmhwCGA-r365-733m-qg9rCGA-r5v2-hpvm-55fqCGA-rf83-5ggx-9c4pCGA-rvf8-5m4m-h8mcCGA-rwc3-9qwj-537fCGA-vx6c-p93v-97chCGA-wwgw-pqh9-v9c6CGA-wx75-xr86-53vvCGA-x37j-m7x2-5qfmCGA-x777-h48r-67rgCGA-x7mv-wj8v-9f6hCGA-xp2m-m48x-xvmf
Advisory lineage Upstream: 0 Downstream: 27
Modified
Published: 23 May 2017, 03:56
Last modified:14 Jul 2026, 11:44

Vulnerability Summary

Overall Risk (default)
medium
36/100
CVSS Score
8.8 HIGH
v3.1 (cve.org)
EPSS Score
5.2% LOW
5% probability -8.49%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

23 May 2017, 03:56
Published
Vulnerability first disclosed
14 Jul 2026, 11:44
Last Modified
Vulnerability information updated

Description

The inflateMark function in inflate.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving left shifts of negative integers.

CVSS Metrics

  • v3.1HIGHScore: 8.8CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
  • v2.0MEDIUMScore: 6.8AV:N/AC:M/Au:N/C:P/I:P/A:P

EPSS Trends

Current EPSS score: 5.20% Percentile: 92%

Techniques & Countermeasures

  • CWE-1335Incorrect Bitwise Shift of Integer

    An integer value is specified to be shifted by a negative amount or an amount greater than or equal to the number of bits contained in the value causing an unexpected or indeterminate result.

Affected Systems

  • chainguardmysql-8.0

    < 8.0.38-r0

  • chainguardmysql-8.0-client

    < 8.0.38-r0

  • chainguardmysql-8.0-dev

    < 8.0.38-r0

  • chainguardmysql-8.0-iamguarded-compat

    < 8.0.38-r0

  • chainguardmysql-8.0-oci-entrypoint

    < 8.0.38-r0

  • chainguardmysql-8.0-oci-entrypoint-compat

    < 8.0.38-r0

  • chainguardopenjdk-11-openj9-default-policy

    < 0.53.0-r0

  • chainguardopenjdk-17-openj9-default-policy

    < 0.53.0-r0

  • chainguardopenjdk-21-openj9-default-policy

    < 0.53.0-r0

  • chainguardopenjdk-25-openj9

    < 0.59.0-r1

  • chainguardopenjdk-25-openj9-dbg

    < 0.59.0-r1

  • chainguardopenjdk-25-openj9-default-jdk

    < 0.59.0-r1

  • chainguardopenjdk-25-openj9-default-jvm

    < 0.59.0-r1

  • chainguardopenjdk-25-openj9-jmods

    < 0.59.0-r1

  • chainguardopenjdk-25-openj9-jre

    < 0.59.0-r1

  • chainguardopenjdk-26-openj9

    < 0.59.0-r1

  • chainguardopenjdk-26-openj9-dbg

    < 0.59.0-r1

  • chainguardopenjdk-26-openj9-default-jdk

    < 0.59.0-r1

  • chainguardopenjdk-26-openj9-default-jvm

    < 0.59.0-r1

  • chainguardopenjdk-26-openj9-jmods

    < 0.59.0-r1

  • chainguardopenjdk-26-openj9-jre

    < 0.59.0-r1

  • chainguardopenjdk-8-openj9-dbg

    < 0.53.0-r1

  • appleiphone_os

    < 11

  • applemac_os_x

    ≥ 10.0.0, < 10.13.0

  • appletvos

    < 11.0

  • applewatchos

    < 4

  • canonicalubuntu_linux

    16.04 | 18.04

  • debianrsync

    < 3.1.3-6 | < 3.1.3-6 | < 3.1.3-6 | < 3.1.3-6

  • debianzlib

    < 1:1.2.8.dfsg-3 | < 1:1.2.8.dfsg-3 | < 1:1.2.8.dfsg-3 | < 1:1.2.8.dfsg-3

  • debiandebian_linux

    8.0

  • nodejsnode.js

    ≥ 4.0.0, ≤ 4.1.2 | ≥ 4.2.0, < 4.8.2 | ≥ 6.0.0, ≤ 6.8.1 | ≥ 6.9.0, < 6.10.2 | ≥ 7.0.0, < 7.6.0

  • opensuseleap

    42.1 | 42.2

  • opensuseopensuse

    13.2

  • oracledatabase_server

    18c

  • oraclejdk

    1.6.0:update161 | 1.7.0:update151 | 1.8.0:update144

  • oraclejre

    1.6.0:update161 | 1.7.0:update151 | 1.8.0:update144

  • oraclemysql

    ≥ 5.5.0, ≤ 5.5.61 | ≥ 5.6.0, ≤ 5.6.41 | ≥ 5.7.0, ≤ 5.7.23 | ≥ 8.0.0, ≤ 8.0.12

  • redhatenterprise_linux_desktop

    6.0 | 7.0

  • redhatenterprise_linux_eus

    7.4 | 7.5

  • redhatenterprise_linux_server

    6.0 | 7.0

  • redhatenterprise_linux_workstation

    6.0 | 7.0

  • redhatsatellite

    5.8

  • zlibzlib

    ≥ 1.2.3.4, < 1.2.9

References (32)