Back

HIGH

zlib: A flaw found in zlib when compressing (not decompressing) certain inputs

Published Mar 25, 2022

Description

zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.

Affected products

Remediation

Red Hat statement

This bug was introduced in zlib v1.2.2.2 through zlib v1.2.11, with the addition of the Z_FIXED option, which forces the use of fixed Huffman codes, rather than dynamic Huffman codes, allowing for a simpler decoder for special applications. This bug is difficult to trigger, as Z_FIXED is usually only used in special circumstances. Rsync does the compression in-transit using zlib. As rsync uses vulnerable zlib v1.2.8 package, which incorrectly handles memory when performing certain zlib compressing or deflating operations. This results in rsync to crash. Note - The issue wasn't publicly labelled as security vulnerability until 2022, but the fix was public since 2018.

Metrics

References (48)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Mar 25, 2022
Updated Jul 14, 2026
Reserved Mar 25, 2022
CISA Vulnrichment
Updated Apr 23, 2025
NVD
Status Modified
Modified Jul 14, 2026
Red Hat
Severity Important
Public date Apr 20, 2018
GHSA-JC36-42CF-VQWJ