{"cves":[{"id":"CVE-2026-44168","published":"2026-06-12T18:16:00","updated_at":"2026-07-16T09:55:53.302982+00:00","description":"\nMariaDB server is a community developed fork of MySQL server. From versions\n10.6.1 to before 10.6.26, 10.11.1 to before 10.11.17, 11.4.1 to before\n11.4.11, 11.8.1 to before 11.8.7, and 12.3.1, during the SST the donor node\nis interpolating parameters that the joiner sent into the command line. Not\nall parameters were properly validated which could allow a malicious joiner\nto execute arbitrary shell commands on the donor side via the mariabackup\nSST method. This issue has been patched in versions 10.6.26, 10.11.17,\n11.4.11, 11.8.7, and 12.3.2.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.0,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.0,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-44168","https://mariadb.com/docs/release-notes/community-server/11.8/11.8.7","https://ubuntu.com/security/notices/USN-8536-1"],"bugs":["https://jira.mariadb.org/browse/MDEV-39413"],"patches":{"mariadb":["upstream: https://github.com/MariaDB/server/commit/3e3c5d72c8fbff5994edcb43d3cf387628de2d32"],"mariadb-10.0":[],"mariadb-10.1":[],"mariadb-10.3":[],"mariadb-10.6":[]},"tags":{},"packages":[{"name":"mariadb","source":"https://ubuntu.com/security/cve?package=mariadb","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mariadb","debian":"https://tracker.debian.org/pkg/mariadb","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"1:11.8.6-5ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mariadb-10.0","source":"https://ubuntu.com/security/cve?package=mariadb-10.0","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mariadb-10.0","debian":"https://tracker.debian.org/pkg/mariadb-10.0","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mariadb-10.1","source":"https://ubuntu.com/security/cve?package=mariadb-10.1","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mariadb-10.1","debian":"https://tracker.debian.org/pkg/mariadb-10.1","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mariadb-10.3","source":"https://ubuntu.com/security/cve?package=mariadb-10.3","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mariadb-10.3","debian":"https://tracker.debian.org/pkg/mariadb-10.3","statuses":[{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mariadb-10.6","source":"https://ubuntu.com/security/cve?package=mariadb-10.6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mariadb-10.6","debian":"https://tracker.debian.org/pkg/mariadb-10.6","statuses":[{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-8536-1"],"notices":[{"id":"USN-8536-1","title":"MariaDB vulnerabilities","summary":"Several security issues were fixed in MariaDB.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-07-14T11:45:03.813587","description":"It was discovered that MariaDB did not properly validate parameters\nsupplied by a joiner node during a State Snapshot Transfer using the\nmariabackup method. An attacker could possibly use this issue to execute\narbitrary shell commands on the donor node. (CVE-2026-44168)\n\nIt was discovered that MariaDB did not properly enforce the SHOW CREATE\nROUTINE privilege when a user obtained access to a stored routine via a\nrole. An authenticated user could possibly use this issue to obtain\nsensitive information. (CVE-2026-44169)\n\nIt was discovered that MariaDB's mbstream utility did not properly validate\npaths when unpacking archives. An attacker could possibly use this issue to\nwrite files outside of the intended target directory. (CVE-2026-44171)\n\nIt was discovered that MariaDB's mysql_real_escape_string() function\nincorrectly handled the big5 character set. An attacker could possibly use\nthis issue to perform SQL injection attacks. (CVE-2026-44172)\n\nIt was discovered that MariaDB did not properly check the FILE privilege\nwhen the FROM clause of a SELECT ... INTO OUTFILE or SELECT ... INTO\nDUMPFILE statement contained only subqueries. An authenticated user could\npossibly use this issue to write files to unintended locations.\n(CVE-2026-44173)\n\nIt was discovered that MariaDB did not properly validate parameters\nsupplied by a joiner node during a State Snapshot Transfer using the rsync\nmethod. An attacker could possibly use this issue to execute arbitrary\nshell commands on the donor node. (CVE-2026-48163)\n\nIt was discovered that MariaDB allowed a high-privileged user to set\ncertain Galera system variables to values containing shell commands, which\nwere then executed by the server process. An authenticated user could\npossibly use this issue to execute arbitrary shell commands.\n(CVE-2026-48165)\n\nIt was discovered that MariaDB executed shell commands embedded in the name\nof a joiner node when wsrep_notify_cmd was enabled. A remote attacker could\npossibly use this issue to execute arbitrary shell commands.\n(CVE-2026-49261)","is_hidden":false,"release_packages":{"resolute":[{"name":"mariadb","version":"1:11.8.6-5ubuntu0.1","description":"MariaDB database","is_source":true},{"name":"libmariadb-dev","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"libmariadb-dev-compat","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"libmariadb3","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"libmariadbd-dev","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"libmariadbd19t64","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-backup","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-client","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-client-compat","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-client-core","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-common","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-plugin-connect","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-plugin-connect-jdbc","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-plugin-cracklib-password-check","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-plugin-gssapi-client","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-plugin-gssapi-server","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-plugin-hashicorp-key-management","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-plugin-mroonga","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-plugin-oqgraph","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-plugin-provider-bzip2","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-plugin-provider-lz4","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-plugin-provider-lzma","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-plugin-provider-lzo","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-plugin-provider-snappy","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-plugin-rocksdb","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-plugin-s3","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-plugin-spider","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-server","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-server-compat","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-server-core","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-test","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"},{"name":"mariadb-test-data","version":"1:11.8.6-5ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mariadb","version_link":"https://launchpad.net/ubuntu/+source/mariadb/1:11.8.6-5ubuntu0.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-49261","CVE-2026-44168","CVE-2026-44169","CVE-2026-48163","CVE-2026-44172","CVE-2026-44173","CVE-2026-48165","CVE-2026-44171"]}]},{"id":"CVE-2026-9641","published":"2026-06-12T16:16:00","updated_at":"2026-06-19T08:57:27.623541+00:00","description":"\nCrypt::PBKDF2 versions before 0.261630 for Perl have a weak default\nalgorithm and number of iterations.\nThe default algorithm is HMAC-SHA1, which should only be used for legacy\nsystems.\nThese versions default to using 1000 iterations.\nDepending on the chosen algorithm, 220,000 to 1,400,000 iterations should\nbe used.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-9641","https://lists.security.metacpan.org/cve-announce/msg/40933040/","https://cheatsheetseries.owasp.org/cheatsheets/Password_Storage_Cheat_Sheet.html#pbkdf2","https://metacpan.org/release/ARODLAND/Crypt-PBKDF2-0.261630/changes","http://www.openwall.com/lists/oss-security/2026/06/12/5","http://www.openwall.com/lists/oss-security/2026/06/13/1"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1139867"],"patches":{"libcrypt-pbkdf2-perl":[]},"tags":{},"packages":[{"name":"libcrypt-pbkdf2-perl","source":"https://ubuntu.com/security/cve?package=libcrypt-pbkdf2-perl","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libcrypt-pbkdf2-perl","debian":"https://tracker.debian.org/pkg/libcrypt-pbkdf2-perl","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.261630-1","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-9638","published":"2026-06-12T16:16:00","updated_at":"2026-06-19T08:57:27.623541+00:00","description":"\nCrypt::PBKDF2 versions before 0.261630 for Perl generate insecure random\nvalues for salts.\nThese versions use the built-in rand function, which is predictable and\nunsuitable for cryptography.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-9638","https://lists.security.metacpan.org/cve-announce/msg/40932643/","https://metacpan.org/dist/Crypt-PBKDF2/source/lib/Crypt/PBKDF2.pm#L86-93","https://metacpan.org/release/ARODLAND/Crypt-PBKDF2-0.261630/changes","http://www.openwall.com/lists/oss-security/2026/06/12/4"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1139867"],"patches":{"libcrypt-pbkdf2-perl":[]},"tags":{},"packages":[{"name":"libcrypt-pbkdf2-perl","source":"https://ubuntu.com/security/cve?package=libcrypt-pbkdf2-perl","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libcrypt-pbkdf2-perl","debian":"https://tracker.debian.org/pkg/libcrypt-pbkdf2-perl","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.261630-1","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-50560","published":"2026-06-12T16:16:00","updated_at":"2026-06-19T08:57:05.170444+00:00","description":"\nNetty is a network application framework for development of protocol\nservers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final,\nNetty HTTP/2 max header size handling produces an attack similar to HTTP/2\nRapid Reset. There is a setting in the http2 specification called\n`SETTINGS_MAX_HEADER_LIST_SIZE`. When a client sends that setting to Netty,\nit appears that Netty will behave as follows: read the request; proxy the\nrequest to the origin; attempt to produce a response; and create an\nexception while writing the headers for the response. Functionally, this\nshould be similar to the http2 reset attack, but with a different\non-the-wire signature. Versions 4.1.135.Final and 4.2.15.Final patch the\nissue.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":5.3,"baseSeverity":"MEDIUM"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":6.9,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-50560","https://github.com/netty/netty/security/advisories/GHSA-563q-j3cm-6jxm","https://github.com/netty/netty/releases/tag/netty-4.1.135.Final","https://github.com/netty/netty/releases/tag/netty-4.2.15.Final","https://www.rfc-editor.org/rfc/rfc9113.html#name-defined-settings"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1139914"],"patches":{"netty":[]},"tags":{},"packages":[{"name":"netty","source":"https://ubuntu.com/security/cve?package=netty","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=netty","debian":"https://tracker.debian.org/pkg/netty","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-50020","published":"2026-06-12T16:16:00","updated_at":"2026-06-19T08:57:05.170444+00:00","description":"\nNetty is a network application framework for development of protocol\nservers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final,\nbefore reading the first request-line, `HttpObjectDecoder` skips every byte\nfor which `Character.isISOControl(b)` is `true` (0x00–0x1F and 0x7F) as\nwell as all whitespace. RFC 9112 §2.2 only asks servers to ignore empty\nCRLF lines preceding the request-line — a carefully scoped robustness\nallowance intended to handle HTTP/1.0 POST workarounds. Silently absorbing\nNUL bytes, SOH, STX, and other non-CRLF control characters goes\nsignificantly beyond this, and can be exploited for request-boundary\nconfusion in pipelined or multiplexed transports where a front-end\ncomponent treats those bytes differently. Versions 4.1.135.Final and\n4.2.15.Final patch the issue.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-50020","https://github.com/netty/netty/security/advisories/GHSA-hvcg-qmg6-jm4c","https://github.com/netty/netty/releases/tag/netty-4.1.135.Final","https://github.com/netty/netty/releases/tag/netty-4.2.15.Final"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1139914"],"patches":{"netty":[]},"tags":{},"packages":[{"name":"netty","source":"https://ubuntu.com/security/cve?package=netty","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=netty","debian":"https://tracker.debian.org/pkg/netty","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-50011","published":"2026-06-12T16:16:00","updated_at":"2026-06-19T08:57:05.170444+00:00","description":"\nNetty is a network application framework for development of protocol\nservers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final,\nRedisArrayAggregator pre-allocates ArrayList with initial capacity equal to\nthe RESP array element count declared in an array header. That count is\ntaken from the wire before the corresponding child messages exist. A small\nmalicious header can claim a huge initial capacity. Versions 4.1.135.Final\nand 4.2.15.Final patch the issue.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-50011","https://github.com/netty/netty/security/advisories/GHSA-5w86-c3rq-vjj7","https://github.com/netty/netty/releases/tag/netty-4.1.135.Final","https://github.com/netty/netty/releases/tag/netty-4.2.15.Final"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1139914"],"patches":{"netty":[]},"tags":{},"packages":[{"name":"netty","source":"https://ubuntu.com/security/cve?package=netty","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=netty","debian":"https://tracker.debian.org/pkg/netty","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-50010","published":"2026-06-12T16:16:00","updated_at":"2026-06-19T08:57:05.170444+00:00","description":"\nNetty is a network application framework for development of protocol\nservers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final,\nSimpleTrustManagerFactory.engineGetTrustManagers() and related paths wrap\nany user-supplied plain X509TrustManager in X509TrustManagerWrapper, which\nextends X509ExtendedTrustManager but implements the 3-arg\ncheckServerTrusted(chain, authType, SSLEngine) by discarding the SSLEngine\nand calling the 2-arg delegate. Because the object now IS an\nX509ExtendedTrustManager, neither SunJSSE's internal\nAbstractTrustManagerWrapper nor Netty's own OpenSslX509TrustManagerWrapper\nwill re-wrap it to add endpoint-identification. Consequently, even though\nNetty 4.2 sets endpointIdentificationAlgorithm=\"HTTPS\" by default, a client\nbuilt with\n`SslContextBuilder.forClient().trustManager(somePlainX509TrustManager)`\nperforms no hostname verification at all. Versions 4.1.135.Final and\n4.2.15.Final patch the issue.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-50010","https://github.com/netty/netty/security/advisories/GHSA-c653-97m9-rcg9","https://github.com/netty/netty/releases/tag/netty-4.1.135.Final","https://github.com/netty/netty/releases/tag/netty-4.2.15.Final"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1139914"],"patches":{"netty":[]},"tags":{},"packages":[{"name":"netty","source":"https://ubuntu.com/security/cve?package=netty","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=netty","debian":"https://tracker.debian.org/pkg/netty","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-50009","published":"2026-06-12T16:16:00","updated_at":"2026-06-19T08:57:05.170444+00:00","description":"\nNetty is a network application framework for development of protocol\nservers and clients. Prior to version 4.2.15.Final, Netty QUIC exposes the\nstateless reset token on the network path when using the default HMAC-based\nconnection-ID and stateless-reset-token generators. The reset token for the\nserver's current source connection ID can be derived from bytes that appear\nas the connection ID in QUIC headers after a source-CID rotation. An\non-path attacker observing the headers can use the token to perform a\nDenial of Service by sending a spoofed Stateless Reset packet. Version\n4.2.15.Final patches the issue.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":4.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":4.8,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-50009","https://github.com/netty/netty/security/advisories/GHSA-cq4q-cv5g-r8q5","https://github.com/netty/netty/releases/tag/netty-4.2.15.Final"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1139914"],"patches":{"netty":[]},"tags":{},"packages":[{"name":"netty","source":"https://ubuntu.com/security/cve?package=netty","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=netty","debian":"https://tracker.debian.org/pkg/netty","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-48748","published":"2026-06-12T16:16:00","updated_at":"2026-08-07T17:27:06.629668+00:00","description":"\nNetty is a network application framework for development of protocol\nservers and clients. Starting in version 4.2.0.Final and prior to version\n4.2.15.Final, a memory exhaustion vulnerability in the Netty HTTP/3 codec\nallows the creation of an infinite number of blocked streams, which can\ncause OOM error. Version 4.2.15.Final patches the issue.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-48748","https://github.com/netty/netty/security/advisories/GHSA-4grm-h2qv-h6w6","https://github.com/netty/netty/releases/tag/netty-4.2.15.Final"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1139914"],"patches":{"netty":[]},"tags":{},"packages":[{"name":"netty","source":"https://ubuntu.com/security/cve?package=netty","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=netty","debian":"https://tracker.debian.org/pkg/netty","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-48059","published":"2026-06-12T16:16:00","updated_at":"2026-06-19T08:56:55.971208+00:00","description":"\nNetty is a network application framework for development of protocol\nservers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, the\nHAProxy PROXY protocol v2 codec in netty leaks native or heap memory on\nevery connection when a client sends a syntactically valid header\ncontaining nested `PP2_TYPE_SSL` TLVs (type-length-value records) at depth\ntwo or greater. The leak occurs on the successful parse path — no exception\nis thrown, the message fires downstream, the decoder removes itself, and\nthe application releases the `HAProxyMessage` normally. Yet the underlying\ncumulation buffer (a pooled, potentially direct `ByteBuf` allocated by the\nchannel) remains permanently pinned. Versions 4.1.135.Final and\n4.2.15.Final patch the issue.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":8.7,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-48059","https://github.com/netty/netty/security/advisories/GHSA-h2qv-fj59-j46j","https://github.com/netty/netty/releases/tag/netty-4.1.135.Final","https://github.com/netty/netty/releases/tag/netty-4.2.15.Final"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1139914"],"patches":{"netty":[]},"tags":{},"packages":[{"name":"netty","source":"https://ubuntu.com/security/cve?package=netty","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=netty","debian":"https://tracker.debian.org/pkg/netty","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-48043","published":"2026-06-12T16:16:00","updated_at":"2026-06-19T08:56:55.971208+00:00","description":"\nNetty is a network application framework for development of protocol\nservers and clients. In netty-codec-http2 prior to versions 4.1.135.Final\nand 4.2.15.Final, the `DelegatingDecompressorFrameListener` class\norchestrates HTTP/2 decompression by embedding a per-stream\n`EmbeddedChannel` that runs the appropriate decompression codec (gzip,\ndeflate, zstd) and forwards decompressed chunks to a wrapped listener. Each\ndecompressed chunk is a pooled `ByteBuf` handed to an anonymous\n`ChannelInboundHandlerAdapter` tail handler, which becomes the sole owner\nresponsible for releasing it. A remote peer could send frames that would\nresult in the flow-controller throwing and so trigger a resource leak which\nat the end might take down the whole JVM due OOME. Versions 4.1.135.Final\nand 4.2.15.Final patch the issue.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":5.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-48043","https://github.com/netty/netty/security/advisories/GHSA-c2gf-v879-257j","https://github.com/netty/netty/releases/tag/netty-4.1.135.Final","https://github.com/netty/netty/releases/tag/netty-4.2.15.Final"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1139914"],"patches":{"netty":[]},"tags":{},"packages":[{"name":"netty","source":"https://ubuntu.com/security/cve?package=netty","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=netty","debian":"https://tracker.debian.org/pkg/netty","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-48006","published":"2026-06-12T16:16:00","updated_at":"2026-06-19T08:56:55.971208+00:00","description":"\nNetty is a network application framework for development of protocol\nservers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, the\nRedisArrayAggregator handler permanently leaks pooled direct-memory buffers\nwhen a Redis pipeline connection closes before a RESP array aggregate\ncompletes. The handler retains child messages in per-handler state\n(`depths` field) but defines no `channelInactive`, `handlerRemoved`, or\n`exceptionCaught` method to release them when the pipeline tears down.\nBecause the leaked buffers are slices of `PooledByteBufAllocator` chunks,\nthey prevent those chunks from being returned to the JVM-wide direct-memory\npool. Repeated connection churn by any network peer monotonically drains\nthis shared pool, eventually causing allocation failures on all Netty\nchannels in the process. Versions 4.1.135.Final and 4.2.15.Final patch the\nissue.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":8.7,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-48006","https://github.com/netty/netty/security/advisories/GHSA-6jv9-x5w9-2ccm","https://github.com/netty/netty/releases/tag/netty-4.1.135.Final","https://github.com/netty/netty/releases/tag/netty-4.2.15.Final"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1139914"],"patches":{"netty":[]},"tags":{},"packages":[{"name":"netty","source":"https://ubuntu.com/security/cve?package=netty","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=netty","debian":"https://tracker.debian.org/pkg/netty","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-47691","published":"2026-06-12T16:16:00","updated_at":"2026-06-19T08:56:55.971208+00:00","description":"\nNetty is a network application framework for development of protocol\nservers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final,\nNetty's `DnsResolveContext` insufficiently validates the bailiwick of NS\nrecords, enabling DNS Cache Poisoning. An attacker controlling an\nauthoritative name server for a subdomain can poison the cache for parent\ndomains (like `.co.uk`). In\n`io.netty.resolver.dns.DnsResolveContext.AuthoritativeNameServerList#add`\nmethod accepts any NS record from the AUTHORITY section as long as the\nrecord's name is a suffix of the questionName. Subsequently, the\n`handleWithAdditional` method caches the associated A records from the\nADDITIONAL section directly into the `authoritativeDnsServerCache` under\nthe parent domain's key. This bypasses standard bailiwick rules, where a\nserver authoritative for a subdomain should not be trusted to provide\nauthoritative records for its parent. The poisoned cache is then used for\nall future resolutions under the parent domain's key. Versions\n4.1.135.Final and 4.2.15.Final patch the issue.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.7,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":8.7,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-47691","https://github.com/netty/netty/security/advisories/GHSA-5pvg-856g-cp85","https://github.com/netty/netty/releases/tag/netty-4.1.135.Final","https://github.com/netty/netty/releases/tag/netty-4.2.15.Final"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1139914"],"patches":{"netty":[]},"tags":{},"packages":[{"name":"netty","source":"https://ubuntu.com/security/cve?package=netty","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=netty","debian":"https://tracker.debian.org/pkg/netty","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-8742-1"],"notices":[{"id":"USN-8742-1","title":"Netty vulnerability","summary":"Netty could be exposed to cache poisoning.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-09-10T09:01:53.849713","description":"It was discovered that Netty incorrectly validates the bailiwick of NS\nrecords. An attacker could possibly use this issue to facilitate DNS\ncache poisoning attacks.","is_hidden":false,"release_packages":{"noble":[{"name":"netty","version":"1:4.1.48-9ubuntu0.2+esm2","description":"event-driven asynchronous network application framework","is_source":true},{"name":"libnetty-java","version":"1:4.1.48-9ubuntu0.2+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/netty","version_link":null,"pocket":"esm-apps"}]},"type":"USN","cves_ids":["CVE-2026-47691"]}]},{"id":"CVE-2026-44967","published":"2026-06-12T16:16:00","updated_at":"2026-06-19T08:56:07.397447+00:00","description":"\nOpenTelemetry-cpp is the C++ implementation of OpenTelemetry. Prior to\nrelease 1.27.0, the OTLP HTTP exporters (traces/metrics/logs) read the full\nHTTP response into an in-memory vector of bytes without a size cap. This is\nexploitable for memory exhaustion when the configured collector endpoint is\nattacker-controlled (or a network attacker can MITM the exporter\nconnection). This vulnerability is fixed in opentelemetry-cpp release\n1.27.0.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"ADJACENT","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-44967","https://github.com/open-telemetry/opentelemetry-cpp/security/advisories/GHSA-5qhm-4rfp-qqvj","https://github.com/open-telemetry/opentelemetry-cpp/issues/3958","https://github.com/open-telemetry/opentelemetry-cpp/pull/4078","https://github.com/open-telemetry/opentelemetry-go/security/advisories/GHSA-w8rr-5gcm-pp58"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1139879"],"patches":{"opentelemetry-cpp":[]},"tags":{},"packages":[{"name":"opentelemetry-cpp","source":"https://ubuntu.com/security/cve?package=opentelemetry-cpp","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=opentelemetry-cpp","debian":"https://tracker.debian.org/pkg/opentelemetry-cpp","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-47244","published":"2026-06-12T15:16:00","updated_at":"2026-06-19T08:56:55.971208+00:00","description":"\nNetty is a network application framework for development of protocol\nservers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final,\nDefaultHttp2Connection.DefaultEndpoint initialises\nmaxActiveStreams/maxStreams to Integer.MAX_VALUE, and Http2Settings never\ninserts SETTINGS_MAX_CONCURRENT_STREAMS by default\n(Http2Settings.java:305-307 only clamps a user-supplied value). Unless the\napplication explicitly calls initialSettings().maxConcurrentStreams(n), a\nNetty HTTP/2 server advertises no limit and enforces none locally. Each\nopen stream allocates a DefaultStream object, PropertyMap slots,\nflow-controller state and IntObjectHashMap entry; with ~2^30 permissible\nodd stream IDs a single TCP connection can create hundreds of thousands of\nlong-lived stream objects. This is also the precondition for\nCVE-2023-44487-style Rapid-Reset amplification, where the absence of a low\nconcurrent cap multiplies backend work. Versions 4.1.135.Final and\n4.2.15.Final patch the issue.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":5.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-47244","https://github.com/netty/netty/security/advisories/GHSA-5x3r-wrvg-rp6q","https://github.com/netty/netty/releases/tag/netty-4.1.135.Final","https://github.com/netty/netty/releases/tag/netty-4.2.15.Final"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1139914"],"patches":{"netty":[]},"tags":{},"packages":[{"name":"netty","source":"https://ubuntu.com/security/cve?package=netty","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=netty","debian":"https://tracker.debian.org/pkg/netty","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-46340","published":"2026-06-12T15:16:00","updated_at":"2026-06-19T08:56:55.971208+00:00","description":"\nNetty is a network application framework for development of protocol\nservers and clients. In versions of netty-transport-sctp prior to\n4.1.135.Final and 4.2.15.Final, for each non-complete SctpMessage fragment\nthe handler does `fragments.put(streamId, Unpooled.wrappedBuffer(frag,\nbyteBuf))`, wrapping the previous accumulator and the new slice into a\n*new* CompositeByteBuf every time. After N fragments the accumulator is an\nN-deep chain of composites, each holding references and component arrays;\nreadableBytes()/getBytes() on the final buffer recurse N levels. There is\nno limit on N, on total bytes, or on the number of streamIdentifiers an\nattacker can open (each gets its own map entry). A peer that never sets the\n`complete` flag can grow this structure indefinitely from tiny 1-byte DATA\nchunks. Versions 4.1.135.Final and 4.2.15.Final patch the issue.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-46340","https://github.com/netty/netty/security/advisories/GHSA-5xrh-qmmq-w6ch","https://github.com/netty/netty/releases/tag/netty-4.1.135.Final","https://github.com/netty/netty/releases/tag/netty-4.2.15.Final"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1139914"],"patches":{"netty":[]},"tags":{},"packages":[{"name":"netty","source":"https://ubuntu.com/security/cve?package=netty","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=netty","debian":"https://tracker.debian.org/pkg/netty","statuses":[{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-45674","published":"2026-06-12T15:16:00","updated_at":"2026-06-19T08:56:19.869572+00:00","description":"\nNetty is a network application framework for development of protocol\nservers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final,\nNetty's DnsResolveContext fails to validate the origin (bailiwick) of CNAME\nrecords in DNS responses. Versions 4.1.135.Final and 4.2.15.Final patch the\nissue.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.7,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":8.7,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-45674","https://github.com/netty/netty/security/advisories/GHSA-676x-f7gg-47vc","https://github.com/netty/netty/releases/tag/netty-4.1.135.Final","https://github.com/netty/netty/releases/tag/netty-4.2.15.Final"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1139914"],"patches":{"netty":[]},"tags":{},"packages":[{"name":"netty","source":"https://ubuntu.com/security/cve?package=netty","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=netty","debian":"https://tracker.debian.org/pkg/netty","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-45673","published":"2026-06-12T15:16:00","updated_at":"2026-06-19T08:56:19.869572+00:00","description":"\nNetty is a network application framework for development of protocol\nservers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final,\nNetty's DNS resolver uses a predictable PRNG for generating DNS transaction\nIDs and defaults to a static UDP source port. This combination reduces the\nentropy of DNS queries, enabling DNS Cache Poisoning (Kaminsky attack).\nVersions 4.1.135.Final and 4.2.15.Final patch the issue.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":6.8,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-45673","https://github.com/netty/netty/security/advisories/GHSA-xmv7-r254-6q78","https://github.com/netty/netty/releases/tag/netty-4.1.135.Final","https://github.com/netty/netty/releases/tag/netty-4.2.15.Final"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1139914"],"patches":{"netty":[]},"tags":{},"packages":[{"name":"netty","source":"https://ubuntu.com/security/cve?package=netty","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=netty","debian":"https://tracker.debian.org/pkg/netty","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-45536","published":"2026-06-12T15:16:00","updated_at":"2026-06-19T08:56:19.869572+00:00","description":"\nNetty is a network application framework for development of protocol\nservers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final,\nnetty_unix_socket_recvFd sets msg_control to `char\ncontrol[CMSG_SPACE(sizeof(int))]` (line 940) — 24 bytes on 64-bit Linux. A\npeer-sent SCM_RIGHTS cmsg carrying two ints has cmsg_len = CMSG_LEN(8) =\n24, which fits exactly with no MSG_CTRUNC, so the kernel installs both fds\nin the receiving process. The subsequent check `cmsg->cmsg_len ==\nCMSG_LEN(sizeof(int))` (line 972, expected 20) fails, the branch that would\nread the fd is skipped, and neither installed fd is closed. The for(;;)\nloop calls recvmsg again (non-blocking → EAGAIN → Java maps to 0 → read\nloop exits normally), leaving two leaked fds per message. There is no\nMSG_CTRUNC handling. Reachable via Epoll/KQueue DomainSocketChannel when\nthe application opts into DomainSocketReadMode.FILE_DESCRIPTORS\n(non-default). Versions 4.1.135.Final and 4.2.15.Final patch the issue.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":4.0,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":4.0,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-45536","https://github.com/netty/netty/security/advisories/GHSA-w573-9ffj-6ff9","https://github.com/netty/netty/releases/tag/netty-4.1.135.Final","https://github.com/netty/netty/releases/tag/netty-4.2.15.Final"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1139914"],"patches":{"netty":[]},"tags":{},"packages":[{"name":"netty","source":"https://ubuntu.com/security/cve?package=netty","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=netty","debian":"https://tracker.debian.org/pkg/netty","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-45416","published":"2026-06-12T15:16:00","updated_at":"2026-06-19T08:56:19.869572+00:00","description":"\nNetty is a network application framework for development of protocol\nservers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final,\nSslClientHelloHandler.decode() reads the 24-bit TLS handshake length and,\nwhen the ClientHello does not fit in the first record, eagerly allocates\n`ctx.alloc().buffer(handshakeLength)` (line 161). The guard at line 140 is\n`handshakeLength > maxClientHelloLength && maxClientHelloLength != 0`, and\nthe commonly-used SniHandler/AbstractSniHandler constructors\n(SniHandler(Mapping), SniHandler(AsyncMapping), AbstractSniHandler()) pass\nmaxClientHelloLength=0 and handshakeTimeoutMillis=0, so the length guard is\ndisabled and no timeout is scheduled. A 16 MiB request exceeds the default\npooled chunk size and becomes a huge/unpooled allocation performed\nimmediately. The buffer is retained in the handler until the channel\ncloses. Versions 4.1.135.Final and 4.2.15.Final patch the issue.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-45416","https://github.com/netty/netty/security/advisories/GHSA-x4gw-5cx5-pgmh","https://github.com/netty/netty/releases/tag/netty-4.1.135.Final","https://github.com/netty/netty/releases/tag/netty-4.2.15.Final"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1139914"],"patches":{"netty":[]},"tags":{},"packages":[{"name":"netty","source":"https://ubuntu.com/security/cve?package=netty","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=netty","debian":"https://tracker.debian.org/pkg/netty","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":9680,"limit":20,"total_results":79316}