Skip to content

frmts/zlib/contrib/infback9/inftree9.c: Fix potential vulnerable cloned functions.#12244

Merged
rouault merged 2 commits into
OSGeo:masterfrom
npt-1707:fix-CVE-2016-9840
May 1, 2025
Merged

frmts/zlib/contrib/infback9/inftree9.c: Fix potential vulnerable cloned functions.#12244
rouault merged 2 commits into
OSGeo:masterfrom
npt-1707:fix-CVE-2016-9840

Conversation

@npt-1707
Copy link
Copy Markdown
Contributor

@npt-1707 npt-1707 commented May 1, 2025

What does this PR do?

Dear Development team,

I identified vulnerabilities in a clone function sourced from madler/zlib. These issues, originally reported in CVE-2016-9840, were resolved in the zlib repository via this commit madler/zlib@6a04314.

This PR applies the corresponding patch to fix the vulnerabilities in this codebase.

Please review at your convenience. Thank you for your time and attention!

Comment thread frmts/zlib/contrib/infback9/inftree9.c Outdated
@rouault rouault added this to the 3.11.0 milestone May 1, 2025
@coveralls
Copy link
Copy Markdown
Collaborator

Coverage Status

coverage: 70.776% (+0.02%) from 70.759%
when pulling e85a6ee on npt-1707:fix-CVE-2016-9840
into 489e7be on OSGeo:master.

@rouault rouault merged commit 7f3406e into OSGeo:master May 1, 2025
37 checks passed
@npt-1707
Copy link
Copy Markdown
Contributor Author

Thanks for merging my PR, @rouault!

Just wanted to let you know that I plan to report this as a CVE. Please let me know if you have any concern. Thanks!

@CrossVR
Copy link
Copy Markdown

CrossVR commented Apr 27, 2026

@npt-1707 Shouldn't this CVE also be addressed in the upstream zlib repository?

@Neustradamus
Copy link
Copy Markdown

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants