CVE-2016-9840
HighAdvisory
Published 23 May 2017In the index since 6 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 8.8
- base score, highest
- EPSS
- 0.048
- 91st percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 133
- of 17,781 indexed, latest versions
- Container images
- 131
- deployed by those charts
- Fix available
- 6 of 6
- affected packages
Red Hat Security Advisory: rsync security update
Carried by container images the latest versions of 133 of 17,781 indexed charts deploy, on 131 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| zlibdeb | 1:1.2.8.dfsg-1ubuntu1, 1:1.2.8.dfsg-1ubuntu1.1, 1:1.2.8.dfsg-2ubuntu4, 1:1.2.8.dfsg-2ubuntu4.1 | 1:1.2.8.dfsg-2ubuntu4.3 | 64 |
| rsyncrpm | 3.1.3-7.el8, 3.1.3-7.el8_2.2, 3.1.3-12.el8, 3.1.3-12.el8_4.2+4 more | 0:3.1.3-7.el8_2.5, 0:3.1.3-12.el8_4.5, 0:3.1.3-14.el8_6.8, 0:3.1.3-20.el8_8.3+1 more | 29 |
| zlibrpm | 1.2.7-18.el7, 1.2.7-19.el7_9, 1.2.7-20.el7_9 | 0:1.2.7-21.el7_9.1 | 28 |
| rsyncdeb | 3.1.1-3ubuntu1.1, 3.1.1-3ubuntu1.2, 3.1.2-2.1ubuntu1 | 3.1.1-3ubuntu1.3, 3.1.2-2.1ubuntu1.1 | 13 |
| zlibapk | 1.2.8-r2 | 1.2.11-r0 | 9 |
| klibcdeb | 2.0.3-0ubuntu1, 2.0.3-0ubuntu1.14.04.3 | 2.0.3-0ubuntu1.14.04.3+esm3 | 7 |
- OSV records
- ALPINE-CVE-2016-9840RHSA-2025:10541RHSA-2025:11048RHSA-2025:12013RHSA-2025:13947RHSA-2025:8314RHSA-2025:8395UBUNTU-CVE-2016-9840
- Also known as
- USN-4246-1, USN-4292-1, USN-6736-1
Charts affected
133 by stars
Container images carrying it
131 by charts deploying them
A fixed version is listed for 6 of the 6 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| voltha/ | c4e41e92f046 | zlib | 1:1.2.8.dfsg-2ubuntu4.3 | 1 |
| voltha/ | 59ab2a00f712 | klibc zlib | 2.0.3-0ubuntu1.14.04.3+esm3 no fix listed | 1 |
| voltha/ | 37f80524c207 | zlib | 1:1.2.8.dfsg-2ubuntu4.3 | 1 |
| voltha/ | 9ee8c1f4428c | zlib | 1:1.2.8.dfsg-2ubuntu4.3 | 1 |
| voltha/ | 655c3048a602 | zlib | 1:1.2.8.dfsg-2ubuntu4.3 | 1 |
| voltha/ | ff596b62de59 | zlib | 1:1.2.8.dfsg-2ubuntu4.3 | 1 |
| weaveworks/ | bb113953e19f | zlib | 1.2.11-r0 | 1 |
| gcr.io/ | e225fe7eaa55 | zlib | 0:1.2.7-21.el7_9.1 | 1 |
| gcr.io/ | 10f4dbc8eeeb | zlib | 1:1.2.8.dfsg-2ubuntu4.3 | 1 |
| gcr.io/ | cb5c1bddd1b5 | zlib | 1:1.2.8.dfsg-2ubuntu4.3 | 1 |
| gcr.io/ | 8b1a0831e889 | zlib | 1.2.11-r0 | 1 |
| gcr.io/ | 55877a3866a2 | zlib | 1.2.11-r0 | 1 |
| gcr.io/ | 5ea7b7f3632a | zlib | 1:1.2.8.dfsg-2ubuntu4.3 | 1 |
| gcr.io/ | 8f9ff98fdbef | zlib | 1:1.2.8.dfsg-2ubuntu4.3 | 1 |
| gcr.io/ | e8bc6cf08613 | zlib | 1:1.2.8.dfsg-2ubuntu4.3 | 1 |
| public.ecr.aws/ | 849e235e2d3e | rsync | 0:3.1.3-23.el8_10 | 1 |
| quay.io/ | 3b036692d546 | rsync | 0:3.1.3-23.el8_10 | 1 |
| quay.io/ | a3b9a07648b6 | rsync | 0:3.1.3-12.el8_4.5 | 1 |
| quay.io/ | 55330b1b60c1 | rsync | 0:3.1.3-14.el8_6.8 | 1 |
| quay.io/ | bb40472e4ff5 | rsync | 0:3.1.3-23.el8_10 | 1 |
| quay.io/ | 2bcfcf874451 | rsync | 0:3.1.3-23.el8_10 | 1 |
| quay.io/ | f2fbced76da8 | rsync | 0:3.1.3-23.el8_10 | 1 |
| quay.io/ | 0dc38a87b844 | rsync | 0:3.1.3-14.el8_6.8 | 1 |
| quay.io/ | a8a9ec461034 | rsync | 0:3.1.3-14.el8_6.8 | 1 |
| quay.io/ | 7a4b9fedc724 | rsync | 0:3.1.3-7.el8_2.5 | 1 |
| quay.io/ | e383ba3e0966 | rsync | 0:3.1.3-23.el8_10 | 1 |
| quay.io/ | 6722d5041b47 | rsync | 0:3.1.3-7.el8_2.5 | 1 |
| quay.io/ | c241c971aef8 | rsync | 0:3.1.3-14.el8_6.8 | 1 |
| quay.io/ | c6a934439421 | zlib | 1:1.2.8.dfsg-2ubuntu4.3 | 1 |
| quay.io/ | be844c750c7e | rsync | 0:3.1.3-23.el8_10 | 1 |
| quay.io/ | 8e928db29ee1 | rsync | 0:3.1.3-23.el8_10 | 1 |