zlib: A flaw found in zlib when compressing (not decompressing) certain inputs
Published Mar 25, 2022
8.2
HIGHCVSS 3.1
EPSS 51.73%
Description
zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.
Affected products
No data.
Configuration 2
Configuration 4
- 9.0
- 10.0
- 11.0
Configuration 5
- 34
- 35
- 36
Configuration 6
- ≥ 10.15 · < 10.15.7
- 10.15.7
- 10.15.7
- 10.15.7
- 10.15.7
- 10.15.7
- 10.15.7
- 10.15.7
- 10.15.7
- 10.15.7
- 10.15.7
- 10.15.7
- 10.15.7
- 10.15.7
- 10.15.7
- ≥ 11.0 · < 11.6.6
- ≥ 12.0.0 · < 12.4
Configuration 7
- ≥ 10.3.0 · < 10.3.36
- ≥ 10.4.0 · < 10.4.26
- ≥ 10.5.0 · < 10.5.17
- ≥ 10.6.0 · < 10.6.9
- ≥ 10.7.0 · < 10.7.5
- ≥ 10.8.0 · < 10.8.4
- ≥ 10.9.0 · < 10.9.2
Configuration 8
- n/a
- ≥ 11.0.0 · ≤ 11.70.2
- n/a
- n/a
- n/a
- n/a
Configuration 9
- n/a
Configuration 10
- n/a
Configuration 11
- n/a
Configuration 12
- n/a
Configuration 13
- n/a
Configuration 14
- < 3.0
Running on/with
- n/a
Configuration 15
- < 3.0
Running on/with
- n/a
Configuration 16
- < 3.0
Running on/with
- n/a
Configuration 17
- < 3.0
Running on/with
- n/a
Configuration 18
- < 3.0
Running on/with
- n/a
Configuration 19
- < 3.0
Running on/with
- n/a
Configuration 20
Configuration 21
- < 11.9.18
No data.
Red Hat Enterprise Linux 6 Extended Lifecycle Support
zlib-0:1.2.3-31.el6_10
Fixed · RHSA-2022:2214
Red Hat Enterprise Linux 7
zlib-0:1.2.7-20.el7_9
Fixed · RHSA-2022:2213
Red Hat Enterprise Linux 7.4 Advanced Update Support
zlib-0:1.2.7-17.el7_4.1
Fixed · RHSA-2023:0976
Red Hat Enterprise Linux 7.6 Advanced Update Support
zlib-0:1.2.7-18.el7_6.1
Fixed · RHSA-2023:0975
Red Hat Enterprise Linux 7.7 Advanced Update Support
zlib-0:1.2.7-18.el7_7.1
Fixed · RHSA-2023:0943
Red Hat Enterprise Linux 7.7 Telco Extended Update Support
zlib-0:1.2.7-18.el7_7.1
Fixed · RHSA-2023:0943
Red Hat Enterprise Linux 7.7 Update Services for SAP Solutions
zlib-0:1.2.7-18.el7_7.1
Fixed · RHSA-2023:0943
Red Hat Enterprise Linux 8
mingw-zlib-0:1.2.8-10.el8
Fixed · RHSA-2022:7813
Red Hat Enterprise Linux 8
rsync-0:3.1.3-14.el8_6.2
Fixed · RHSA-2022:2201
Red Hat Enterprise Linux 8
zlib-0:1.2.11-18.el8_5
Fixed · RHSA-2022:1642
Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions
rsync-0:3.1.3-6.el8_1.1
Fixed · RHSA-2022:2197
Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions
zlib-0:1.2.11-11.el8_1.1
Fixed · RHSA-2022:1591
Red Hat Enterprise Linux 8.2 Extended Update Support
rsync-0:3.1.3-7.el8_2.1
Fixed · RHSA-2022:2192
Red Hat Enterprise Linux 8.2 Extended Update Support
zlib-0:1.2.11-17.el8_2
Fixed · RHSA-2022:1661
Red Hat Enterprise Linux 8.4 Extended Update Support
rsync-0:3.1.3-12.el8_4.1
Fixed · RHSA-2022:2198
Red Hat Enterprise Linux 8.4 Extended Update Support
zlib-0:1.2.11-18.el8_4
Fixed · RHSA-2022:4845
Red Hat Enterprise Linux 9
mingw-zlib-0:1.2.12-2.el9
Fixed · RHSA-2022:8420
Red Hat Enterprise Linux 9
rsync-0:3.2.3-9.el9_0.1
Fixed · RHSA-2022:4592
Red Hat Enterprise Linux 9
rsync-0:3.2.3-9.el9_0.1
Fixed · RHSA-2022:4592
Red Hat Enterprise Linux 9
zlib-0:1.2.11-31.el9_0.1
Fixed · RHSA-2022:4584
Red Hat Enterprise Linux 9
zlib-0:1.2.11-31.el9_0.1
Fixed · RHSA-2022:4584
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7
redhat-virtualization-host-0:4.3.23-20220622.0.el7_9
Fixed · RHSA-2022:5439
Red Hat Virtualization 4 for Red Hat Enterprise Linux 8
redhat-virtualization-host-0:4.5.0-202205291010_8.6
Fixed · RHSA-2022:4896
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 Extended Lifecycle Support | zlib-0:1.2.3-31.el6_10 | Fixed | RHSA-2022:2214 |
| Red Hat Enterprise Linux 7 | zlib-0:1.2.7-20.el7_9 | Fixed | RHSA-2022:2213 |
| Red Hat Enterprise Linux 7.4 Advanced Update Support | zlib-0:1.2.7-17.el7_4.1 | Fixed | RHSA-2023:0976 |
| Red Hat Enterprise Linux 7.6 Advanced Update Support | zlib-0:1.2.7-18.el7_6.1 | Fixed | RHSA-2023:0975 |
| Red Hat Enterprise Linux 7.7 Advanced Update Support | zlib-0:1.2.7-18.el7_7.1 | Fixed | RHSA-2023:0943 |
| Red Hat Enterprise Linux 7.7 Telco Extended Update Support | zlib-0:1.2.7-18.el7_7.1 | Fixed | RHSA-2023:0943 |
| Red Hat Enterprise Linux 7.7 Update Services for SAP Solutions | zlib-0:1.2.7-18.el7_7.1 | Fixed | RHSA-2023:0943 |
| Red Hat Enterprise Linux 8 | mingw-zlib-0:1.2.8-10.el8 | Fixed | RHSA-2022:7813 |
| Red Hat Enterprise Linux 8 | rsync-0:3.1.3-14.el8_6.2 | Fixed | RHSA-2022:2201 |
| Red Hat Enterprise Linux 8 | zlib-0:1.2.11-18.el8_5 | Fixed | RHSA-2022:1642 |
| Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions | rsync-0:3.1.3-6.el8_1.1 | Fixed | RHSA-2022:2197 |
| Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions | zlib-0:1.2.11-11.el8_1.1 | Fixed | RHSA-2022:1591 |
| Red Hat Enterprise Linux 8.2 Extended Update Support | rsync-0:3.1.3-7.el8_2.1 | Fixed | RHSA-2022:2192 |
| Red Hat Enterprise Linux 8.2 Extended Update Support | zlib-0:1.2.11-17.el8_2 | Fixed | RHSA-2022:1661 |
| Red Hat Enterprise Linux 8.4 Extended Update Support | rsync-0:3.1.3-12.el8_4.1 | Fixed | RHSA-2022:2198 |
| Red Hat Enterprise Linux 8.4 Extended Update Support | zlib-0:1.2.11-18.el8_4 | Fixed | RHSA-2022:4845 |
| Red Hat Enterprise Linux 9 | mingw-zlib-0:1.2.12-2.el9 | Fixed | RHSA-2022:8420 |
| Red Hat Enterprise Linux 9 | rsync-0:3.2.3-9.el9_0.1 | Fixed | RHSA-2022:4592 |
| Red Hat Enterprise Linux 9 | rsync-0:3.2.3-9.el9_0.1 | Fixed | RHSA-2022:4592 |
| Red Hat Enterprise Linux 9 | zlib-0:1.2.11-31.el9_0.1 | Fixed | RHSA-2022:4584 |
| Red Hat Enterprise Linux 9 | zlib-0:1.2.11-31.el9_0.1 | Fixed | RHSA-2022:4584 |
| Red Hat Virtualization 4 for Red Hat Enterprise Linux 7 | redhat-virtualization-host-0:4.3.23-20220622.0.el7_9 | Fixed | RHSA-2022:5439 |
| Red Hat Virtualization 4 for Red Hat Enterprise Linux 8 | redhat-virtualization-host-0:4.5.0-202205291010_8.6 | Fixed | RHSA-2022:4896 |
No package ranges for this CVE.
Remediation
Red Hat statement
This bug was introduced in zlib v1.2.2.2 through zlib v1.2.11, with the addition of the Z_FIXED option, which forces the use of fixed Huffman codes, rather than dynamic Huffman codes, allowing for a simpler decoder for special applications. This bug is difficult to trigger, as Z_FIXED is usually only used in special circumstances. Rsync does the compression in-transit using zlib. As rsync uses vulnerable zlib v1.2.8 package, which incorrectly handles memory when performing certain zlib compressing or deflating operations. This results in rsync to crash. Note - The issue wasn't publicly labelled as security vulnerability until 2022, but the fix was public since 2018.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
1 other source (Red Hat) ▾
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:N/I:N/A:P
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
PoCAutomatable
YesTechnical Impact
PartialDecision
n/aAssessed Apr 23, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (25 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 51.73% (0.51733) | 98.91th | v5 (v2026.06.15) |
| Jun 15, 2026 | 51.73% (0.51733) | 98.80th | v5 (v2026.06.15) |
| Nov 21, 2025 | 0.09% (0.00089) | 25.92th | v4 (v2025.03.14) |
| Nov 18, 2025 | 11.52% (0.11520) | 92.91th | v4 (v2025.03.14) |
| Mar 17, 2025 | 0.07% (0.00075) | 20.13th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.37% (0.00370) | 73.46th | v3 (v2023.03.01) |
| Feb 8, 2024 | 0.28% (0.00278) | 67.35th | v3 (v2023.03.01) |
| Nov 14, 2023 | 0.28% (0.00278) | 64.75th | v3 (v2023.03.01) |
| Nov 8, 2023 | 0.26% (0.00262) | 63.67th | v3 (v2023.03.01) |
| Sep 5, 2023 | 0.17% (0.00171) | 53.63th | v3 (v2023.03.01) |
| Jul 8, 2023 | 0.14% (0.00144) | 49.30th | v3 (v2023.03.01) |
| Jun 30, 2023 | 0.19% (0.00189) | 55.22th | v3 (v2023.03.01) |
| May 8, 2023 | 0.18% (0.00180) | 53.67th | v3 (v2023.03.01) |
| Apr 27, 2023 | 0.19% (0.00189) | 54.93th | v3 (v2023.03.01) |
| Apr 1, 2023 | 0.16% (0.00158) | 50.77th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.14% (0.00136) | 47.19th | v3 (v2023.03.01) |
| Mar 6, 2023 | 23.44% (0.23437) | 96.70th | v2 (v2022.01.01) |
| Sep 30, 2022 | 23.44% (0.23437) | 96.57th | v2 (v2022.01.01) |
| May 7, 2022 | 2.69% (0.02686) | 81.35th | v2 (v2022.01.01) |
| Apr 2, 2022 | 1.54% (0.01537) | 72.40th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.18% (0.01183) | 58.77th | v2 (v2022.01.01) |
| Mar 31, 2022 | 1.18% (0.01183) | 36.39th | v2 (v2022.01.01) |
| Mar 30, 2022 | 1.10% (0.01104) | 30.11th | v2 (v2022.01.01) |
| Mar 27, 2022 | 0.95% (0.00950) | 14.59th | v2 (v2022.01.01) |
| Mar 26, 2022 | 0.89% (0.00890) | 13.15th | v2 (v2022.01.01) |
References (48)
- http://seclists.org/fulldisclosure/2022/May/33 mailing-listMailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2022/May/35 mailing-listMailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2022/May/38 mailing-listMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2022/03/25/2 mailing-listMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2022/03/26/1 mailing-listExploitMailing ListThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2018-25032 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2067945 Issue Tracking
- https://cert-portal.siemens.com/productcert/html/ssa-333517.html
- https://cert-portal.siemens.com/productcert/html/ssa-398330.html
- https://cert-portal.siemens.com/productcert/html/ssa-419740.html
- https://cert-portal.siemens.com/productcert/html/ssa-470355.html
- https://cert-portal.siemens.com/productcert/html/ssa-565386.html
- https://cert-portal.siemens.com/productcert/html/ssa-942865.html
- https://cert-portal.siemens.com/productcert/pdf/ssa-333517.pdf Third Party Advisory
- https://github.com/advisories/GHSA-jc36-42cf-vqwj Advisory
- https://github.com/madler/zlib/commit/5c44459c3b28a9bd3283aaceab7c615f8020c531 PatchThird Party Advisory
- https://github.com/madler/zlib/compare/v1.2.11...v1.2.12 PatchThird Party Advisory
- https://github.com/madler/zlib/issues/605 Issue TrackingPatchThird Party Advisory
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/nokogiri/CVE-2018-25032.yml
- https://github.com/sparklemotion/nokogiri/security/advisories/GHSA-v6gp-9mmm-c6p5
- https://lists.debian.org/debian-lts-announce/2022/04/msg00000.html mailing-listMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2022/05/msg00008.html mailing-listMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2022/09/msg00023.html mailing-listMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DCZFIJBJTZ7CL5QXBFKTQ22Q26VINRUF/ vendor-advisoryThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DF62MVMH3QUGMBDCB3DY2ERQ6EBHTADB/ vendor-advisoryThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JZZPTWRYQULAOL3AW7RZJNVZ2UONXCV4/ vendor-advisoryThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NS2D2GFPFGOJUL4WQ3DUAY7HF4VWQ77F/ vendor-advisoryThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VOKNP2L734AEL47NRYGVZIKEFOUBQY5Y/ vendor-advisoryThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XOKFMSNQ5D5WGMALBNBXU3GE442V74WU/ vendor-advisoryThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DCZFIJBJTZ7CL5QXBFKTQ22Q26VINRUF/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DF62MVMH3QUGMBDCB3DY2ERQ6EBHTADB/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JZZPTWRYQULAOL3AW7RZJNVZ2UONXCV4/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NS2D2GFPFGOJUL4WQ3DUAY7HF4VWQ77F/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VOKNP2L734AEL47NRYGVZIKEFOUBQY5Y/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XOKFMSNQ5D5WGMALBNBXU3GE442V74WU/
- https://nvd.nist.gov/vuln/detail/CVE-2018-25032
- https://security.gentoo.org/glsa/202210-42 vendor-advisoryThird Party Advisory
- https://security.netapp.com/advisory/ntap-20220526-0009/ Third Party Advisory
- https://security.netapp.com/advisory/ntap-20220729-0004/ Third Party Advisory
- https://support.apple.com/kb/HT213255 Third Party Advisory
- https://support.apple.com/kb/HT213256 Third Party Advisory
- https://support.apple.com/kb/HT213257 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2018-25032
- https://www.debian.org/security/2022/dsa-5111 vendor-advisoryPatchThird Party Advisory
- https://www.openwall.com/lists/oss-security/2022/03/24/1 Mailing ListThird Party Advisory
- https://www.openwall.com/lists/oss-security/2022/03/28/1 ExploitMailing ListThird Party Advisory
- https://www.openwall.com/lists/oss-security/2022/03/28/3 Mailing ListThird Party Advisory
- https://www.oracle.com/security-alerts/cpujul2022.html PatchThird Party Advisory
Change history (0)
No recorded changes yet.