CVE-2016-9840

Red Hat Security Advisory: OpenShift Container Platform 4.17.32 bug fix and security update

Description

inftrees.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.

Metrics

Severity
high
no public PoC known
8.8
Source: nvd-v3
91.4 %
Critical — this CVE ranks in the top fifth of all CVEs scored today (rank ≥ 80%).
4.8 %
Moderate — model estimates 1-10% exploitation likelihood.
Published
2025-06-04 09:19 UTC

Affected operating systems

  • linux

    debian / debian_linux8.0

  • linux

    redhat / enterprise_linux_desktop6.0

  • linux

    redhat / enterprise_linux_desktop7.0

  • linux

    redhat / enterprise_linux_eus7.4

  • linux

    redhat / enterprise_linux_eus7.5

  • linux

    redhat / enterprise_linux_server6.0

  • linux

    redhat / enterprise_linux_server7.0

  • linux

    redhat / enterprise_linux_workstation6.0

  • linux

    redhat / enterprise_linux_workstation7.0

  • linux

    opensuse / leap42.1

  • linux

    opensuse / leap42.2

  • linux

    opensuse / opensuse13.2

  • linux

    canonical / ubuntu_linux16.04

  • linux

    canonical / ubuntu_linux18.04

  • macos

    apple / mac_os_x

  • mobile

    apple / iphone_os

  • other

    apple / tvos

  • other

    apple / watchos

Affected products

Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.

  • boost

    boost1.78.0

  • go

    github.com/openshift/console

  • go

    golang.org/x/net

  • go

    golang.org/x/oauth2

  • nodejs

    node.js4.0.0 – 4.1.2

  • nodejs

    node.js4.2.0 – 4.8.2

  • nodejs

    node.js6.0.0 – 6.8.1

  • nodejs

    node.js6.9.0 – 6.10.2

  • nodejs

    node.js7.0.0 – 7.6.0

  • oracle

    database_server

  • oracle

    jdk

  • oracle

    jre

  • oracle

    mysql5.5.0 – 5.5.61

  • oracle

    mysql5.6.0 – 5.6.41

  • oracle

    mysql5.7.0 – 5.7.23

  • oracle

    mysql8.0.0 – 8.0.12

  • redhat

    satellite

  • zlib

    zlib1.2.0.6 – 1.2.9

References & sources

Linked CVEs

IDCVE-2016-9840