CVE-2022-37434: Buffer Overflow
A security vulnerability was found in zlib. The flaw triggered a heap-based buffer in inflate in the inflate.c function via a large gzip header extra field. This flaw is only applicable in the call inflateGetHeader.
Other sources
Accelerate Framework. A memory consumption issue was addressed with improved memory handling.
— Apple
APFS. An access issue was addressed with improved access restrictions.
— Apple
Apple Neural Engine. The issue was addressed with improved memory handling.
— Apple
Apple TV. The issue was addressed with improved handling of caches.
— Apple
AppleAVD. A memory corruption issue was addressed with improved state management.
— Apple
Credit
Affected Software
Remediation
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2022-42825
- CVE-2022-42798
- CVE-2022-42860
- CVE-2022-46723
- CVE-2022-32944
- CVE-2022-46713
- CVE-2022-32941
- CVE-2022-28739
- CVE-2022-32862
- CVE-2022-37434
- CVE-2022-42800
- CVE-2022-32932
- CVE-2022-32940
- CVE-2022-42813
- CVE-2022-32947
- CVE-2022-46712
- CVE-2022-32924
- CVE-2022-42808
- CVE-2022-42803
- CVE-2022-32926
- CVE-2022-42801
- CVE-2022-42817
- CVE-2022-42811
- CVE-2022-42799
- CVE-2022-42823
- CVE-2022-42824
- CVE-2022-32923
- CVE-2022-42795
- CVE-2022-48577
- CVE-2022-32858
- CVE-2022-32898
- CVE-2022-32899
- CVE-2022-46721
- CVE-2022-47915
- CVE-2022-47965
- CVE-2022-32889
- CVE-2022-32907
- CVE-2022-32827
- CVE-2022-32877
- CVE-2022-42789
- CVE-2022-46722
- CVE-2022-32902
- CVE-2022-32904
- CVE-2022-32890
- CVE-2022-42796
- CVE-2022-42816
- CVE-2022-42821
- CVE-2022-42819
- CVE-2022-26730
- CVE-2022-32945
- CVE-2022-42838
- CVE-2022-48683
- CVE-2022-22663
- CVE-2022-32867
- CVE-2022-32205
- CVE-2022-32206
- CVE-2022-32207
- CVE-2022-32208
- CVE-2022-42814
- CVE-2022-32865
- CVE-2022-32915
- CVE-2022-32928
- CVE-2022-22643
- CVE-2022-32935
- CVE-2022-42788
- CVE-2022-48504
- CVE-2022-32905
- CVE-2022-42833
- CVE-2022-42809
- CVE-2022-3437
- CVE-2022-32849
- CVE-2022-32913
- CVE-2022-32809
- CVE-2022-1622
- CVE-2022-32936
- CVE-2022-42820
- CVE-2022-42806
- CVE-2022-32864
- CVE-2022-32866
- CVE-2022-32911
- CVE-2022-32914
- CVE-2022-42815
- CVE-2022-42834
- CVE-2022-46707
- CVE-2022-32883
- CVE-2022-32908
- CVE-2022-42810
- CVE-2021-39537
- CVE-2022-29458
- CVE-2022-42818
- CVE-2022-32879
- CVE-2022-32895
- CVE-2022-42807
- CVE-2022-32918
- CVE-2022-42829
- CVE-2022-42830
- CVE-2022-42831
- CVE-2022-42832
- CVE-2022-32881
- CVE-2022-32931
- CVE-2022-42793
- CVE-2022-32876
- CVE-2022-32938
- CVE-2022-42790
- CVE-2022-32870
- CVE-2022-32934
- CVE-2022-42791
- CVE-2021-36690
- CVE-2022-48505
- CVE-2022-26699
- CVE-2022-0261
- CVE-2022-0318
- CVE-2022-0319
- CVE-2022-0351
- CVE-2022-0359
- CVE-2022-0361
- CVE-2022-0368
- CVE-2022-0392
- CVE-2022-0554
- CVE-2022-0572
- CVE-2022-0629
- CVE-2022-0685
- CVE-2022-0696
- CVE-2022-0714
- CVE-2022-0729
- CVE-2022-0943
- CVE-2022-1381
- CVE-2022-1420
- CVE-2022-1725
- CVE-2022-1616
- CVE-2022-1619
- CVE-2022-1620
- CVE-2022-1621
- CVE-2022-1629
- CVE-2022-1674
- CVE-2022-1733
- CVE-2022-1735
- CVE-2022-1769
- CVE-2022-1927
- CVE-2022-1942
- CVE-2022-1968
- CVE-2022-1851
- CVE-2022-1897
- CVE-2022-1898
- CVE-2022-1720
- CVE-2022-2000
- CVE-2022-2042
- CVE-2022-2124
- CVE-2022-2125
- CVE-2022-2126
- CVE-2022-42828
- CVE-2022-32875
- CVE-2022-42826
- CVE-2022-32886
- CVE-2022-32888
- CVE-2022-32912
- CVE-2022-32922
- CVE-2022-32892
- CVE-2022-32833
- CVE-2022-46709
- CVE-2022-32909
- CVE-2022-32929
- CVE-2022-32946
- CVE-2022-32939
- CVE-2022-42827
- CVE-2022-46715
- CVE-2022-42792
- CVE-2022-32927
- CVE-2022-32949
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-37434.
What is the severity of CVE-2022-37434?
The severity of CVE-2022-37434 is critical with a severity value of 9.8.
Which software versions are affected by CVE-2022-37434?
Software versions including Zlib Zlib up to and including 1.2.12, Apple macOS Monterey up to and including 12.6.1, Apple iOS up to and including 16.1, Apple iPadOS up to and including 16, Apple watchOS up to and including 9.1, Redhat zlib up to and including 1.2.7-21.el7_9 and 1.2.11-19.el8_6, Redhat rsync up to and including 3.1.3-19.el8 and 3.2.3-18.el9, Fedora up to and including version 37, Debian Debian Linux up to and including 10.0, Stormshield Stormshield Network Security up to and including 4.6.3, and IBM Security Guardium up to and including 11.3 are affected by CVE-2022-37434.
How can I fix CVE-2022-37434?
To fix CVE-2022-37434, update to the following versions: Zlib Zlib 1.2.12 or later, Apple macOS Monterey 12.6.1 or later, Apple iOS 16.1 or later, Apple iPadOS 16 or later, Apple watchOS 9.1 or later, Redhat zlib 1.2.7-21.el7_9 or 1.2.11-19.el8_6, Redhat rsync 3.1.3-19.el8 or 3.2.3-18.el9, Fedora 38 or later, Debian Debian Linux 10.1 or later, Stormshield Stormshield Network Security 4.6.4 or later, and IBM Security Guardium 12 or later.
Are there any references available for more information about CVE-2022-37434?
Yes, you can find more information about CVE-2022-37434 at the following references: [Link 1](https://github.com/nodejs/node/blob/75b68c6e4db515f76df73af476eccf382bbcb00a/deps/zlib/inflate.c#L762-L764), [Link 2](https://github.com/ivd38/zlib_overflow), [Link 3](https://github.com/madler/zlib/commit/eff308af425b67093bab25f80f1ae950166bece1).