CVE-2016-9843: Apple iPhone OS

Critical severity, CVSS 9.8. EPSS: 5.8% chance of exploitation in the next 30 days.

The crc32_big function in crc32.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving big-endian CRC calculation.

Affected products

  • Apple iPhone OS: before 11 (fixed in 11)
  • Apple Mac OS X: from 10.0.0, before 10.13.0 (fixed in 10.13.0)
  • Apple tvOS: before 11.0 (fixed in 11.0)
  • Apple watchOS: before 4 (fixed in 4)
  • Canonical Ubuntu Linux: version 16.04 only; version 18.04 only
  • Debian Debian Linux: version 8.0 only
  • MariaDB MariaDB: from 5.5.0, before 5.5.62 (fixed in 5.5.62); from 10.0.0, before 10.0.37 (fixed in 10.0.37); from 10.1.0, before 10.1.37 (fixed in 10.1.37); from 10.2.0, before 10.2.19 (fixed in 10.2.19); from 10.3.0, before 10.3.11 (fixed in 10.3.11)
  • Netapp Active Iq Unified Manager: from 7.3; from 9.5
  • Netapp Oncommand Insight: affected versions not specified
  • Netapp Oncommand Workflow Automation: affected versions not specified
  • Netapp Snapcenter: affected versions not specified
  • Node.js Node.js: from 4.0.0, up to and including 4.1.2; from 4.2.0, before 4.8.2 (fixed in 4.8.2); from 6.0.0, up to and including 6.8.1; from 6.9.0, before 6.10.2 (fixed in 6.10.2); from 7.0.0, before 7.6.0 (fixed in 7.6.0)
  • Opensuse Leap: version 42.1 only; version 42.2 only
  • Opensuse Opensuse: version 13.2 only
  • Oracle Database Server: version 18c only
  • Oracle JDK: version 1.6.0 only; version 1.7.0 only; version 1.8.0 only
  • Oracle JRE: version 1.6.0 only; version 1.7.0 only; version 1.8.0 only
  • Oracle MySQL: from 5.5.0, up to and including 5.5.61; from 5.6.0, up to and including 5.6.41; from 5.7.0, up to and including 5.7.23; from 8.0.0, up to and including 8.0.12
  • Red Hat Enterprise Linux Desktop: version 6.0 only; version 7.0 only
  • Red Hat Enterprise Linux Eus: version 7.4 only; version 7.5 only
  • Red Hat Enterprise Linux Server: version 6.0 only; version 7.0 only
  • Red Hat Enterprise Linux Workstation: version 6.0 only; version 7.0 only
  • Red Hat Satellite: version 5.8 only
  • Zlib Zlib: from 1.2.0, before 1.2.9 (fixed in 1.2.9)

Published 2017-05-23. Last modified 2026-06-17.