CVE-2016-9842: Apple iPhone OS

High severity, CVSS 8.8. EPSS: 5.2% chance of exploitation in the next 30 days.

The inflateMark function in inflate.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving left shifts of negative integers.

Affected products

  • Apple iPhone OS: before 11 (fixed in 11)
  • Apple Mac OS X: from 10.0.0, before 10.13.0 (fixed in 10.13.0)
  • Apple tvOS: before 11.0 (fixed in 11.0)
  • Apple watchOS: before 4 (fixed in 4)
  • Canonical Ubuntu Linux: version 16.04 only; version 18.04 only
  • Debian Debian Linux: version 8.0 only
  • Node.js Node.js: from 4.0.0, up to and including 4.1.2; from 4.2.0, before 4.8.2 (fixed in 4.8.2); from 6.0.0, up to and including 6.8.1; from 6.9.0, before 6.10.2 (fixed in 6.10.2); from 7.0.0, before 7.6.0 (fixed in 7.6.0)
  • Opensuse Leap: version 42.1 only; version 42.2 only
  • Opensuse Opensuse: version 13.2 only
  • Oracle Database Server: version 18c only
  • Oracle JDK: version 1.6.0 only; version 1.7.0 only; version 1.8.0 only
  • Oracle JRE: version 1.6.0 only; version 1.7.0 only; version 1.8.0 only
  • Oracle MySQL: from 5.5.0, up to and including 5.5.61; from 5.6.0, up to and including 5.6.41; from 5.7.0, up to and including 5.7.23; from 8.0.0, up to and including 8.0.12
  • Red Hat Enterprise Linux Desktop: version 6.0 only; version 7.0 only
  • Red Hat Enterprise Linux Eus: version 7.4 only; version 7.5 only
  • Red Hat Enterprise Linux Server: version 6.0 only; version 7.0 only
  • Red Hat Enterprise Linux Workstation: version 6.0 only; version 7.0 only
  • Red Hat Satellite: version 5.8 only
  • Zlib Zlib: from 1.2.3.4, before 1.2.9 (fixed in 1.2.9)

Published 2017-05-23. Last modified 2026-07-14.