{"id":"SUSE-SU-2026:2802-1","summary":"Security update for netty, netty-tcnative","details":"This update for netty, netty-tcnative fixes the following issue\n\nThis update for netty, netty-tcnative fixes the following issues\n\nUpgrade netty to upstream version 4.1.135, netty-tcnative to upstream version 2.0.79:\n\n- CVE-2026-44249: IPv6 Subnet Filter Bypass via Incorrect Comparator Masking (bsc#1268165).\n- CVE-2026-44250: Memory Exhaustion in RedisArrayAggregator due to Deeply Nested Arrays (bsc#1268169).\n- CVE-2026-44890: Unbounded Direct Memory Consumption in RedisDecoder (bsc#1268170).\n- CVE-2026-44893: netty-codec-haproxy: Denial of Service via malformed HAProxy message (bsc#1268244).\n- CVE-2026-45416: SNI handler pre-allocates up to 16 MiB from nine attacker bytes (bsc#1268246).\n- CVE-2026-45536: Unix-socket fd receive leaks descriptors when peer sends two at once (bsc#1268247).\n- CVE-2026-45673: netty-resolver-dns: DNS Cache Poisoning via predictable transaction IDs (bsc#1268248).\n- CVE-2026-45674: DNS Cache Poisoning via Missing Bailiwick Checks in CNAME Records (bsc#1268249).\n- CVE-2026-46340: netty-transport-sctp: Denial of Service due to unbounded memory growth from SctpMessage fragments\n  (bsc#1268250).\n- CVE-2026-47244: HTTP/2: Advertised MAX_CONCURRENT_STREAMS not enforced (bsc#1268251).\n- CVE-2026-47691: Insufficient Bailiwick Validation for NS Records (bsc#1268252).\n- CVE-2026-48006: netty-codec-redis: Netty's Lack of Lifecycle Cleanup Leads to Pooled ByteBuf Leak in\n  RedisArrayAggregator (bsc#1268255).\n- CVE-2026-48043: netty-codec-http2: Denial of Service due to resource leak (bsc#1268257).\n- CVE-2026-48059: netty-codec-haproxy: Denial of Service via memory leak from crafted PROXY protocol headers\n  (bsc#1268258).\n- CVE-2026-50010: Wrapping plain trust manager silently disables hostname verification (bsc#1268259).\n- CVE-2026-50011: Unbounded pre-allocation in RedisArrayAggregator from RESP array length (bsc#1268260).\n- CVE-2026-50020: HttpObjectDecoder skips arbitrary initial control characters when only initial CRLF characters are\n  permitted (bsc#1268261).\n- CVE-2026-50560: Netty susceptible to HTTP/2 Reset Attack with different on-the-wire signature (bsc#1268262).\n\nChanges:\n\n + MQTT: Allow MQTT 5 CONNECT with password only\n + ChannelInitializer: correct misleading comment on\n exceptionCaught route\n + HTTP/2: Parse request-target path like Vert.x (4.1 backport)\n + HttpObjectDecoder skips arbitrary initial control characters\n when only initial CRLF characters are permitted\n + IpSubnetFilter: Correctly handle ipv6\n + Configurable bound on RedisArrayAggregator\n + Redis: Limit decoded length\n + DNS: Ensure query id is not predictible\n + Wrapping plain trust manager silently disables hostname\n verification\n + MQTT: Reject malformed no-payload packets with non-zero\n Remaining Length\n + HAProxy: Reject HAProxyMessages with malformated TLV and not\n leak memory\n + SSL: Use sane defaults as limits for the client hello length\n and timeout\n + DNS: Only cache CNAME if part of the queried domain\n + HTTP/2: Enforce max concurrent streams for misbehaving clients\n + Dns: Insufficient Bailiwick Validation for NS Records\n + HTTP2: DelegatingDecompressorFrameListener must release memory\n in all cases\n + Pass maxAllocation to Brotli and Zstd decoders\n + HTTP/2: Treat clients MAX_HEADER_LIST_SIZE as advisory\n + Add maxWindowLog parameter to ZstdDecoder to bound memory\n allocation\n + HAProxy: Fix ByteBuf leak when parsing nested SSL TLVs\n + Epoll / Kqueue: Correctly handle receive of FD\n + SCTP: Limit the number of inflight incomplete SCTP messages\n and the number of fragments\n + Redis: Correctly release incomplete message on removal when\n using RedisArrayAggregator\n + Redis: Limit the maximum number of nested arrays\n + HTTP: Re-add constructor to HttpProxyHandler that was removed\n by mistake\n + Marshalling: Explicit document security requirements\n + Pin HTTP/RTSP version + method normalization to Locale.US\n + Adaptive: Fix concurrency issue in adaptive allocator\n + Pin multipart Content-Type / Content-Transfer-Encoding case\n folding to Locale.US\n + Remove dead native declarations\n + Avoid re-parsing openssl key material with non-cached provider\n + IpFilter: Fix ClassCastException caused by IpSubnetFilter if\n only ipv6 rules are configured but remote peer is using ipv4\n + Resolve all localhost addresses without querying DNS servers\n + HTTP2: Use 100 as default max concurrent streams setting\n + Route synchronous onLookupComplete exceptions via\n fireExceptionCaught\n + Fix MQTT decoder size check after variable header replay\n","modified":"2026-07-09T10:00:05.109576708Z","published":"2026-07-08T19:06:43Z","related":["CVE-2026-44249","CVE-2026-44250","CVE-2026-44890","CVE-2026-44893","CVE-2026-45416","CVE-2026-45536","CVE-2026-45673","CVE-2026-45674","CVE-2026-46340","CVE-2026-47244","CVE-2026-47691","CVE-2026-48006","CVE-2026-48043","CVE-2026-48059","CVE-2026-50010","CVE-2026-50011","CVE-2026-50020","CVE-2026-50560"],"upstream":["CVE-2026-44249","CVE-2026-44250","CVE-2026-44890","CVE-2026-44893","CVE-2026-45416","CVE-2026-45536","CVE-2026-45673","CVE-2026-45674","CVE-2026-46340","CVE-2026-47244","CVE-2026-47691","CVE-2026-48006","CVE-2026-48043","CVE-2026-48059","CVE-2026-50010","CVE-2026-50011","CVE-2026-50020","CVE-2026-50560"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20262802-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268165"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268169"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268170"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268244"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268246"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268247"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268248"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268249"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268250"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268251"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268252"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268255"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268257"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268258"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268259"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268260"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268261"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268262"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-44249"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-44250"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-44890"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-44893"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-45416"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-45536"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-45673"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-45674"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46340"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-47244"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-47691"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-48006"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-48043"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-48059"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-50010"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-50011"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-50020"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-50560"}],"affected":[{"package":{"name":"netty-tcnative","ecosystem":"SUSE:Linux Enterprise Module for Development Tools 15 SP7","purl":"pkg:rpm/suse/netty-tcnative&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Development%20Tools%2015%20SP7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.0.79-150200.3.45.1"}]}],"ecosystem_specific":{"binaries":[{"netty-tcnative":"2.0.79-150200.3.45.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2802-1.json"}},{"package":{"name":"netty","ecosystem":"SUSE:Linux Enterprise Module for Package Hub 15 SP7","purl":"pkg:rpm/suse/netty&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.1.135-150200.4.50.1"}]}],"ecosystem_specific":{"binaries":[{"netty":"4.1.135-150200.4.50.1","netty-javadoc":"4.1.135-150200.4.50.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2802-1.json"}},{"package":{"name":"netty-tcnative","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15 SP4-ESPOS","purl":"pkg:rpm/suse/netty-tcnative&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-ESPOS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.0.79-150200.3.45.1"}]}],"ecosystem_specific":{"binaries":[{"netty-tcnative":"2.0.79-150200.3.45.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2802-1.json"}},{"package":{"name":"netty-tcnative","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15 SP4-LTSS","purl":"pkg:rpm/suse/netty-tcnative&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.0.79-150200.3.45.1"}]}],"ecosystem_specific":{"binaries":[{"netty-tcnative":"2.0.79-150200.3.45.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2802-1.json"}},{"package":{"name":"netty-tcnative","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15 SP5-ESPOS","purl":"pkg:rpm/suse/netty-tcnative&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-ESPOS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.0.79-150200.3.45.1"}]}],"ecosystem_specific":{"binaries":[{"netty-tcnative":"2.0.79-150200.3.45.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2802-1.json"}},{"package":{"name":"netty-tcnative","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15 SP5-LTSS","purl":"pkg:rpm/suse/netty-tcnative&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.0.79-150200.3.45.1"}]}],"ecosystem_specific":{"binaries":[{"netty-tcnative":"2.0.79-150200.3.45.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2802-1.json"}},{"package":{"name":"netty-tcnative","ecosystem":"SUSE:Linux Enterprise Server 15 SP4-LTSS","purl":"pkg:rpm/suse/netty-tcnative&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP4-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.0.79-150200.3.45.1"}]}],"ecosystem_specific":{"binaries":[{"netty-tcnative":"2.0.79-150200.3.45.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2802-1.json"}},{"package":{"name":"netty-tcnative","ecosystem":"SUSE:Linux Enterprise Server 15 SP5-LTSS","purl":"pkg:rpm/suse/netty-tcnative&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP5-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.0.79-150200.3.45.1"}]}],"ecosystem_specific":{"binaries":[{"netty-tcnative":"2.0.79-150200.3.45.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2802-1.json"}},{"package":{"name":"netty-tcnative","ecosystem":"SUSE:Linux Enterprise Server 15 SP6-LTSS","purl":"pkg:rpm/suse/netty-tcnative&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP6-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.0.79-150200.3.45.1"}]}],"ecosystem_specific":{"binaries":[{"netty-tcnative":"2.0.79-150200.3.45.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2802-1.json"}},{"package":{"name":"netty-tcnative","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 15 SP4","purl":"pkg:rpm/suse/netty-tcnative&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.0.79-150200.3.45.1"}]}],"ecosystem_specific":{"binaries":[{"netty-tcnative":"2.0.79-150200.3.45.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2802-1.json"}},{"package":{"name":"netty-tcnative","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 15 SP5","purl":"pkg:rpm/suse/netty-tcnative&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.0.79-150200.3.45.1"}]}],"ecosystem_specific":{"binaries":[{"netty-tcnative":"2.0.79-150200.3.45.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2802-1.json"}},{"package":{"name":"netty-tcnative","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 15 SP6","purl":"pkg:rpm/suse/netty-tcnative&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.0.79-150200.3.45.1"}]}],"ecosystem_specific":{"binaries":[{"netty-tcnative":"2.0.79-150200.3.45.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2802-1.json"}}],"schema_version":"1.7.5"}