zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHeader are affected. Some common applications bundle the affected zlib source code but may be unable to call inflateGetHeader (e.g., see the nodejs/node reference).
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HApple iPadOS
OSApple< 15.7.1Apple iOS
OSApple16.0 – 16.1 (excl.)< 15.7.1Apple macOS
OSApple12.0.0 – 12.6.1 (excl.)11.0 – 11.7.1 (excl.)Apple watchOS
OSApple< 9.1Debian
OSDebian10.0Fedora Project Fedora
OSFedoraproject353637Netapp Active Iq Unified Manager
APPNetappall versionsNetapp H300s
HWNetappall versionsNetapp H300s Firmware
OSNetappall versionsNetapp H500s
HWNetappall versionsNetapp H500s Firmware
OSNetappall versionsNetapp H700s
HWNetappall versionsNetapp H700s Firmware
OSNetappall versionsNetapp Hci
APPNetappall versionsNetapp Hci Compute Node
HWNetappall versionsNetapp Management Services For Element Software
APPNetappall versionsNetapp Oncommand Workflow Automation
APPNetappall versionsNetapp Ontap Select Deploy Administration Utility
APPNetappall versionsNetapp Storagegrid
APPNetappall versionsStormshield Network Security
APPStormshield4.6.0 – 4.6.3 (excl.)3.7.31 – 3.7.34 (excl.)3.11.0 – 3.11.22 (excl.)4.3.0 – 4.3.16 (excl.)Zlib
APPZlib≤ 1.2.12
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
Memory
References
Related vulnerabilities
CVE-2026-65400CRITICAL9.8⚠ KEVPL ✓same product
Pominięcie uwierzytelniania w Screen Sharing na macOS
CVE-2026-24061CRITICAL9.8⚠ KEVPL ✓same product
GNU Inetutils telnetd: ominięcie uwierzytelnienia przez zmienną USER
CVE-2025-10585CRITICAL9.8⚠ KEVPL ✓same product
Type confusion w V8 (Google Chrome) — zdalne uszkodzenie sterty
CVE-2025-43300CRITICAL10.0⚠ KEVPL ✓same product
Apple iOS/iPadOS/macOS — out-of-bounds write przy przetwarzaniu obrazu
CVE-2025-32463CRITICAL9.3⚠ KEVPL ✓same product
Sudo: eskalacja uprawnień do root poprzez opcję --chroot (CVE-2025-32463)