Updated: 2026-02-27 03:07:43.051527
Description:
zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.
| Links | NIST | CIRCL | RHEL | Ubuntu |
| Severity | Score | |
|---|---|---|
| CVSS Version 2.x | MEDIUM | 5.0 |
| CVSS Version 3.x | HIGH | 7.5 |
| OS name | Project name | Version | Score | Severity | Status | Errata | Last updated | Statement |
|---|---|---|---|---|---|---|---|---|
| Oracle Linux 6 ELS | minizip | 1.2.3 | 7.5 | HIGH | Already Fixed | 2026-01-09 01:31:17 | ||
| Oracle Linux 6 ELS | python | 2.6.6 | 7.5 | HIGH | Not Vulnerable | 2022-12-05 19:55:47 | ||
| Oracle Linux 6 ELS | rsync | 3.0.6 | 7.5 | HIGH | Released | CLSA-2022:1652986558 | 2022-05-13 08:22:41 | |
| Oracle Linux 7 ELS | rsync | 3.1.2 | 7.5 | HIGH | Already Fixed | 2025-09-25 04:24:18 | ||
| Oracle Linux 7 ELS | zlib | 1.2.7 | 7.5 | HIGH | Already Fixed | 2025-09-20 03:35:57 | ||
| RHEL 7 ELS | rsync | 3.1.2 | 7.5 | HIGH | Already Fixed | 2025-09-22 20:34:47 | ||
| RHEL 7 ELS | zlib | 1.2.7 | 7.5 | HIGH | Already Fixed | 2025-09-20 03:35:56 | ||
| Ubuntu 16.04 ELS | minizip | 1.1-8 | 7.5 | HIGH | Not Vulnerable | 2026-01-12 01:26:14 | Not vulnerable: CVE-2018-25032 is a flaw in zlib’s deflate implementation (<1.2.12), not in minizi... | |
| Ubuntu 16.04 ELS | rsync | 3.1.1-3 | 7.5 | HIGH | Released | CLSA-2022:1652986439 | 2022-05-13 08:22:42 | Not vulnerable: CVE-2018-25032 is a flaw in zlib’s deflate implementation (<1.2.12), not in minizi... |
| Ubuntu 16.04 ELS | python3.5 | 3.5.2 | 7.5 | HIGH | Not Vulnerable | 2024-04-25 22:00:40 | Not vulnerable: CVE-2018-25032 is a flaw in zlib’s deflate implementation (<1.2.12), not in minizi... |