{"id":"SUSE-SU-2026:3482-1","summary":"Security update for netty, netty-tcnative","details":"This update for netty, netty-tcnative fixes the following issues:\n\nUpgrade netty to upstream version 4.1.136 and netty-tcnative to version 2.0.80 Final.\n\nSecurity issues fixed\n\n- CVE-2026-44891: memory exhaustion in `io.netty:netty-codec-stomp` (bsc#1271435).\n- CVE-2026-55831: resource exhaustion/DoS in `io.netty:netty-codec-http` (bsc#1271960).\n- CVE-2026-55833: zip bomb in `io.netty:netty-codec-http` (bsc#1271961).\n- CVE-2026-55851: memory exhaustion in `io.netty:netty-codec-haproxy` (bsc#1272253).\n- CVE-2026-56745: memory exhaustion in `io.netty:netty-codec-http` (bsc#1272254).\n- CVE-2026-56746: improper access control in `io.netty:netty-codec-http` (CORS) (bsc#1272255).\n- CVE-2026-56817: insecure defaults in XML parsing in `io.netty:netty-codec-xml` (bsc#1272257).\n- CVE-2026-56818: memory leak in `io.netty:netty-codec-redis` (bsc#1272603).\n- CVE-2026-56819: memory leak in `io.netty:netty-codec-http2` (bsc#1272258).\n- CVE-2026-56820: improper certificate validation in `io.netty:netty-handler-ssl-ocsp` (bsc#1272259).\n- CVE-2026-56821: improper certificate revocation check in `io.netty:netty-handler-ssl-ocsp` (bsc#1272299).\n- CVE-2026-56822: time-of-check/time-of-use in `io.netty:netty-handler-ssl-ocsp` (bsc#1272300).\n- CVE-2026-59898: protocol version confusion in `io.netty:netty-codec-http` (websocket) (bsc#1272302).\n- CVE-2026-59899: memory exhaustion in `io.netty:netty-codec-http` (bsc#1272301).\n- CVE-2026-59900: improper header neutralization in `io.netty:netty-codec-http2` (bsc#1272303).\n- CVE-2026-59901: infinite loop in `io.netty:netty-codec-compression` (bzip2) (bsc#1272304).\n- CVE-2026-59919: improper CR/LF neutralization in `io.netty:netty-codec-haproxy` (bsc#1272305).\n- CVE-2026-59920: improper CR/LF neutrolization in `io.netty:netty-codec-stomp` (bsc#1272306).\n- CVE-2026-59921: improper CR/LF neutralization in `io.netty:netty-codec-http` (multipart) (bsc#1272307).\n- Memory leak in `io.netty:netty-codec-dns`  (bsc#1272519).\n- Uncontrolled resource consumption in `io.netty:netty-codec-xml` (bsc#1272518).\n\nOther updates and bugfixes:\n\n- Upgrade to upstream version 4.1.136:\n  + SingleThreadEventExecutor: document Throwable safety contract\n    on run()\n  + Make HTTP/2 frame hashCode consistent with equals\n  + Add BlockHound exception for DnsQueryIdSpace (#16896)\n  + FlowControlHandler: Fix autoRead behavior\n  + Fix incorrect bounds in error message of\n    HpackDecoder.setMaxHeaderListSize\n  + MQTT: Fix MQTT decoder size check after variable header replay\n  + MQTT: Make the decodeProperties early-REPLAY check actually\n    fire\n  + Reject control characters at the boundary of HTTP method names\n    (#16723)\n  + Update to latest tcnative release\n  + Fix HTTP 2 PUSH_PROMISE stream association validation\n  + Fix GZIP FEXTRA extra-field handling in JdkZlibDecoder\n  + Add opt-in validation of mandatory pseudo-header fields for\n    HTTP/2\n  + Strictly validate MQTT UTF-8 Encoded String (#16939)\n  + Stop DateFormatter trailing token from running past the parse\n    end\n  + IpFilter: Deprecate constructor which use accept by default\n  + Add RFC 10008 QUERY Method support (#16966)\n  + Correctly release and fail queued traffic-shaping writes on\n    close (#16959)\n  + FlowControlHandler: respect auto-read when toggled while\n    dequeueing\n  + IdleStateHandler: reset firstWriter/ReaderIdleEvent in\n    resetWriteTimeout/resetReadTimeout (#16982)\n  + Fix typo in AbstractSniHandler Javadoc\n  + Reconcile AbstractCoalescingBufferQueue readableBytes when it\n    drains, and fail stuck HTTP/2 streams instead of spinning\n    empty DATA frames\n  + Reject control characters at the boundary of the HTTP version\n    token (#16971)\n  + Reset UTF-8 decode state on CR in StompSubframeDecoder\n  + HTTP2: Pass the correct number of arguments when logging\n    goaway\n  + FastLz: Guard decompression against truncated input (#17000)\n  + Fix propagation of startTls for client SslContext handler\n  + Reject non-token characters in HTTP/2 header names\n  + Update lz4-java to 1.11.1\n  + Pin github actions to reduce risk (#17043)\n  + Merge branches from forks (#17063)\n","modified":"2026-08-05T18:23:48.157302386Z","published":"2026-08-04T11:46:42Z","related":["CVE-2026-44891","CVE-2026-55831","CVE-2026-55833","CVE-2026-55851","CVE-2026-56745","CVE-2026-56746","CVE-2026-56817","CVE-2026-56818","CVE-2026-56819","CVE-2026-56820","CVE-2026-56821","CVE-2026-56822","CVE-2026-59898","CVE-2026-59899","CVE-2026-59900","CVE-2026-59901","CVE-2026-59919","CVE-2026-59920","CVE-2026-59921"],"upstream":["CVE-2026-44891","CVE-2026-55831","CVE-2026-55833","CVE-2026-55851","CVE-2026-56745","CVE-2026-56746","CVE-2026-56817","CVE-2026-56818","CVE-2026-56819","CVE-2026-56820","CVE-2026-56821","CVE-2026-56822","CVE-2026-59898","CVE-2026-59899","CVE-2026-59900","CVE-2026-59901","CVE-2026-59919","CVE-2026-59920","CVE-2026-59921"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20263482-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271435"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271960"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271961"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272253"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272254"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272255"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272257"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272258"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272259"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272299"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272300"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272301"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272302"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272303"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272304"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272305"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272306"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272307"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272518"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272519"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272603"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-44891"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-55831"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-55833"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-55851"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-56745"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-56746"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-56817"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-56818"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-56819"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-56820"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-56821"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-56822"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-59898"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-59899"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-59900"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-59901"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-59919"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-59920"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-59921"}],"affected":[{"package":{"name":"netty-tcnative","ecosystem":"SUSE:Linux Enterprise Module for Development Tools 15 SP7","purl":"pkg:rpm/suse/netty-tcnative&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Development%20Tools%2015%20SP7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.0.80-150200.3.48.1"}]}],"ecosystem_specific":{"binaries":[{"netty-tcnative":"2.0.80-150200.3.48.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3482-1.json"}},{"package":{"name":"netty","ecosystem":"SUSE:Linux Enterprise Module for Package Hub 15 SP7","purl":"pkg:rpm/suse/netty&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.1.136-150200.4.53.1"}]}],"ecosystem_specific":{"binaries":[{"netty-javadoc":"4.1.136-150200.4.53.1","netty":"4.1.136-150200.4.53.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3482-1.json"}},{"package":{"name":"netty-tcnative","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15 SP4-ESPOS","purl":"pkg:rpm/suse/netty-tcnative&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-ESPOS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.0.80-150200.3.48.1"}]}],"ecosystem_specific":{"binaries":[{"netty-tcnative":"2.0.80-150200.3.48.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3482-1.json"}},{"package":{"name":"netty-tcnative","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15 SP4-LTSS","purl":"pkg:rpm/suse/netty-tcnative&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.0.80-150200.3.48.1"}]}],"ecosystem_specific":{"binaries":[{"netty-tcnative":"2.0.80-150200.3.48.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3482-1.json"}},{"package":{"name":"netty-tcnative","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15 SP5-ESPOS","purl":"pkg:rpm/suse/netty-tcnative&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-ESPOS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.0.80-150200.3.48.1"}]}],"ecosystem_specific":{"binaries":[{"netty-tcnative":"2.0.80-150200.3.48.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3482-1.json"}},{"package":{"name":"netty-tcnative","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15 SP5-LTSS","purl":"pkg:rpm/suse/netty-tcnative&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.0.80-150200.3.48.1"}]}],"ecosystem_specific":{"binaries":[{"netty-tcnative":"2.0.80-150200.3.48.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3482-1.json"}},{"package":{"name":"netty-tcnative","ecosystem":"SUSE:Linux Enterprise Server 15 SP4-LTSS","purl":"pkg:rpm/suse/netty-tcnative&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP4-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.0.80-150200.3.48.1"}]}],"ecosystem_specific":{"binaries":[{"netty-tcnative":"2.0.80-150200.3.48.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3482-1.json"}},{"package":{"name":"netty-tcnative","ecosystem":"SUSE:Linux Enterprise Server 15 SP5-LTSS","purl":"pkg:rpm/suse/netty-tcnative&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP5-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.0.80-150200.3.48.1"}]}],"ecosystem_specific":{"binaries":[{"netty-tcnative":"2.0.80-150200.3.48.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3482-1.json"}},{"package":{"name":"netty-tcnative","ecosystem":"SUSE:Linux Enterprise Server 15 SP6-LTSS","purl":"pkg:rpm/suse/netty-tcnative&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP6-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.0.80-150200.3.48.1"}]}],"ecosystem_specific":{"binaries":[{"netty-tcnative":"2.0.80-150200.3.48.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3482-1.json"}},{"package":{"name":"netty-tcnative","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 15 SP4","purl":"pkg:rpm/suse/netty-tcnative&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.0.80-150200.3.48.1"}]}],"ecosystem_specific":{"binaries":[{"netty-tcnative":"2.0.80-150200.3.48.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3482-1.json"}},{"package":{"name":"netty-tcnative","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 15 SP5","purl":"pkg:rpm/suse/netty-tcnative&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.0.80-150200.3.48.1"}]}],"ecosystem_specific":{"binaries":[{"netty-tcnative":"2.0.80-150200.3.48.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3482-1.json"}},{"package":{"name":"netty-tcnative","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 15 SP6","purl":"pkg:rpm/suse/netty-tcnative&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.0.80-150200.3.48.1"}]}],"ecosystem_specific":{"binaries":[{"netty-tcnative":"2.0.80-150200.3.48.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3482-1.json"}}],"schema_version":"1.8.0"}