{"id":"SUSE-SU-2026:1353-1","summary":"Security update for netty, netty-tcnative","details":"This update for netty, netty-tcnative fixes the following issues:\n\nUpidate to 4.1.132:\n\n- CVE-2026-33870: incorrectly parses quoted strings in HTTP/1.1 can lead to request smuggling (bsc#1261031).\n- CVE-2026-33871: sending a flood of CONTINUATION frames can lead to a denial of service (bsc#1261043).\n\nChangelog:\n\n- Upgrade to upstream version 4.1.132\n * Fixes:\n + Fix Incorrect nanos-to-millis conversion in epoll_wait EINTR\n retry loop\n + Make RefCntOpenSslContext.deallocate more robust\n + HTTP2: Correctly account for padding when decompress\n + Fix high-order bit aliasing in HttpUtil.validateToken\n + fix: the precedence of + is higher than \u003e\u003e\n + AdaptiveByteBufAllocator: make sure byteBuf.capacity() not\n greater than byteBuf.maxCapacity()\n + AdaptivePoolingAllocator: call unreserveMatchingBuddy(...)\n if byteBuf initialization failed\n + Don't assume CertificateFactory is thread-safe\n + Fix HttpObjectAggregator leaving connection stuck after 413\n with AUTO_READ=false\n + HTTP2: Ensure preface is flushed in all cases\n + Fix UnsupportedOperationException in readTrailingHeaders\n + Fix client_max_window_bits parameter handling in\n permessage-deflate extension\n + Native transports: Fix possible fd leak when fcntl fails.\n + Kqueue: Fix undefined behaviour when GetStringUTFChars fails\n and SO_ACCEPTFILTER is supported\n + Kqueue: Possible overflow when using\n netty_kqueue_bsdsocket_setAcceptFilter(...)\n + Native transports: Fix undefined behaviour when\n GetStringUTFChars fails while open FD\n + Epoll: Add null checks for safety reasons\n + Epoll: Use correct value to initialize mmsghdr.msg_namelen\n + Epoll: Fix support for IP_RECVORIGDSTADDR\n + AdaptivePoolingAllocator: remove ensureAccessible() call in\n capacity(int) method\n + Epoll: setTcpMg5Sig(...) might overflow\n + JdkZlibDecoder: accumulate decompressed output before firing\n channelRead\n + Limit the number of Continuation frames per HTTP2 Headers\n (bsc#1261043, CVE-2026-33871)\n + Stricter HTTP/1.1 chunk extension parsing (bsc#1261031,\n CVE-2026-33870)\n + rediff\n- Upgrade to upstream version 4.1.131\n + NioDatagramChannel.block(...) does not early return on failure\n + Support for AWS Libcrypto (AWS-LC) netty-tcnative build\n + codec-dns: Decompress MX RDATA exchange domain names during\n DNS record decoding\n + Buddy allocation for large buffers in adaptive allocator\n + SslHandler: Only resume on EventLoop if EventLoop is not\n shutting down already\n + Wrap ECONNREFUSED in PortUnreachableException for UDP\n + Bump com.ning:compress-lzf (4.1)\n + Fix adaptive allocator bug from not noticing failed allocation\n + Avoid loosing original read exception\n + Backport multiple adaptive allocator changes\n- Upgrade to version 4.1.130\n- Upgrade to version 2.0.75 Final\n * No formal changelog present\n * Needed by netty \u003e= 4.2.11\n","modified":"2026-04-16T08:31:24.144882Z","published":"2026-04-15T13:37:19Z","related":["CVE-2026-33870","CVE-2026-33871"],"upstream":["CVE-2026-33870","CVE-2026-33871"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20261353-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261031"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261043"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33870"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33871"}],"affected":[{"package":{"name":"netty-tcnative","ecosystem":"SUSE:Linux Enterprise Module for Development Tools 15 SP7","purl":"pkg:rpm/suse/netty-tcnative&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Development%20Tools%2015%20SP7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.0.75-150200.3.36.1"}]}],"ecosystem_specific":{"binaries":[{"netty-tcnative":"2.0.75-150200.3.36.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:1353-1.json"}},{"package":{"name":"netty","ecosystem":"SUSE:Linux Enterprise Module for Package Hub 15 SP7","purl":"pkg:rpm/suse/netty&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.1.132-150200.4.43.1"}]}],"ecosystem_specific":{"binaries":[{"netty-javadoc":"4.1.132-150200.4.43.1","netty":"4.1.132-150200.4.43.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:1353-1.json"}},{"package":{"name":"netty","ecosystem":"openSUSE:Leap 15.6","purl":"pkg:rpm/opensuse/netty&distro=openSUSE%20Leap%2015.6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.1.132-150200.4.43.1"}]}],"ecosystem_specific":{"binaries":[{"netty-javadoc":"4.1.132-150200.4.43.1","netty-tcnative-javadoc":"2.0.75-150200.3.36.1","netty-tcnative":"2.0.75-150200.3.36.1","netty":"4.1.132-150200.4.43.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:1353-1.json"}},{"package":{"name":"netty-tcnative","ecosystem":"openSUSE:Leap 15.6","purl":"pkg:rpm/opensuse/netty-tcnative&distro=openSUSE%20Leap%2015.6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.0.75-150200.3.36.1"}]}],"ecosystem_specific":{"binaries":[{"netty-javadoc":"4.1.132-150200.4.43.1","netty-tcnative-javadoc":"2.0.75-150200.3.36.1","netty-tcnative":"2.0.75-150200.3.36.1","netty":"4.1.132-150200.4.43.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:1353-1.json"}}],"schema_version":"1.7.5"}