{"id":"SUSE-SU-2026:4391-1","summary":"Security update for netty, netty-tcnative","details":"This update for netty, netty-tcnative fixes the following issues:\n\n- CVE-2026-59902: Netty: Memory Exhaustion in SctpMessageCompletionHandler (bsc#1275501).\n- CVE-2026-59903: Netty Vulnerable to Cache Poisoning and Information Disclosure via CORS Vary Header Overwrite\n  (bsc#1275500).\n- CVE-2026-62243: TLS hostname verification bypass in Netty OpenSSL client path (bsc#1276455).\n- CVE-2026-62380: null byte and CRLF injection in Socks4ClientEncoder and Socks5ClientEncoder (bsc#1276456).\n- CVE-2026-75595: fragmented TLS `ClientHello` causes fallback to default `SslContext` and allows for SNI routing and\n  mTLS requirement bypass (bsc#1276420).\n- CVE-2026-75596: fragmented `ClientHello`records can trigger quadratic pre-handshake reassembly in default SNI parsing\n  (bsc#1276421).\n- CVE-2026-76816: missing input validation in `MqttEncoder` allows for null-byte injection, topic hijacking, and ACL\n  bypassing (bsc#1277243).\n- CVE-2026-89044: HTTP request smuggling in Netty via improper validation of final Transfer-Encoding coding\n  (bsc#1280048).\n- CVE-2026-93488: Denial of Service via unbounded concurrent SPDY streams (bsc#1282084).\n- CVE-2026-93491: Denial of Service via unbounded HttpServerCodec HTTP/1.1 pipeline queue (bsc#1282085).\n- CVE-2026-93492: HTTP/2 HpackEncoder DoS with large table size (bsc#1282132).\n- CVE-2026-93493: missing `nextUpdate` field in OCSP responses leads to silent validation bypass (bsc#1281431).\n- CVE-2026-93494: ByteBuf Leak in StompSubframeDecoder When a Frame Body Is Never Terminated (bsc#1282506).\n- CVE-2026-93558: Unbounded Per-Connection Queue Growth in WebSocketServerExtensionHandler Leads to Denial of Service\n  (bsc#1282140).\n- CVE-2026-93560: STOMP codec content-length long-to-int truncation causes infinite decode loop DoS (bsc#1282141).\n- CVE-2026-93562: Incomplete validation of malformed Transfer-Encoding allows HTTP request smuggling (bsc#1282362).\n- CVE-2026-93563: unbounded multi-line response accumulation in `SmtpResponseDecoder` leads to memory exhaustion and a\n  DoS (bsc#1281432).\n- CVE-2026-93564: HAProxy PROXY-v2 nested-TLV grandchild ByteBuf reference-count leak (bsc#1282363).\n- CVE-2026-93565: RtspDecoder Method-Token Smuggling via Trailing Control Byte (bsc#1282364).\n- CVE-2026-93566: HTTP Request Smuggling due to control characters in the chunk-size line (bsc#1282366).\n- CVE-2026-93567: HTTP/1 authority-form CONNECT is translated to malformed HTTP/2 CONNECT with Host-controlled\n  :authority (bsc#1282367).\n- CVE-2026-93568: HTTP/2 and HTTP/3 Extended CONNECT requests are downgraded as regular CONNECT requests (bsc#1282370).\n- CVE-2026-93569: HTTP/1 absolute-form Host mismatch is translated to HTTP/2 :authority, overriding the request-target\n  authority (bsc#1282372).\n- CVE-2026-93572: multiplication of patched preallocation limits in `RedisArrayAggregator` nested RESP headers can lead\n  to denial of service (bsc#1281433).\n- CVE-2026-93573: Incomplete validation of malformed Transfer-Encoding allows HTTP request smuggling (bsc#1282373).\n- CVE-2026-93574: HTTP request smuggling via post-digit whitespace in chunk-size parsing (bsc#1282374).\n- CVE-2026-93575: missing validations in the `MqttDecoder` can lead to excessive resource consumption and a DoS\n  (bsc#1281434).\n- CVE-2026-93576: netty-codec-smtp -- SMTP command-name field is not CRLF-validated (bsc#1282507).\n- CVE-2026-93578: missing Extended Key Usage (EKU) check in OCSP client allows certificate revocation bypass\n  (bsc#1281435).\n- CVE-2026-93579: HTTP/2 header field values are not validated by default (bsc#1282378).\n\nChanges for netty:\n\n- Upgrade to upstream version 4.1.138\n\nChanges for netty-tcnative:\n\n- Upgrade to version 2.0.84 Final\n","modified":"2026-09-30T12:00:04.046398071Z","published":"2026-09-29T11:47:41Z","related":["CVE-2026-59902","CVE-2026-59903","CVE-2026-62243","CVE-2026-62380","CVE-2026-75595","CVE-2026-75596","CVE-2026-76816","CVE-2026-89044","CVE-2026-93488","CVE-2026-93491","CVE-2026-93492","CVE-2026-93493","CVE-2026-93494","CVE-2026-93558","CVE-2026-93560","CVE-2026-93562","CVE-2026-93563","CVE-2026-93564","CVE-2026-93565","CVE-2026-93566","CVE-2026-93567","CVE-2026-93568","CVE-2026-93569","CVE-2026-93572","CVE-2026-93573","CVE-2026-93574","CVE-2026-93575","CVE-2026-93576","CVE-2026-93578","CVE-2026-93579"],"upstream":["CVE-2026-59902","CVE-2026-59903","CVE-2026-62243","CVE-2026-62380","CVE-2026-75595","CVE-2026-75596","CVE-2026-76816","CVE-2026-89044","CVE-2026-93488","CVE-2026-93491","CVE-2026-93492","CVE-2026-93493","CVE-2026-93494","CVE-2026-93558","CVE-2026-93560","CVE-2026-93562","CVE-2026-93563","CVE-2026-93564","CVE-2026-93565","CVE-2026-93566","CVE-2026-93567","CVE-2026-93568","CVE-2026-93569","CVE-2026-93572","CVE-2026-93573","CVE-2026-93574","CVE-2026-93575","CVE-2026-93576","CVE-2026-93578","CVE-2026-93579"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20264391-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1275500"},{"type":"REPORT","url":"https://bugzilla.suse.com/1275501"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276420"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276421"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276455"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276456"},{"type":"REPORT","url":"https://bugzilla.suse.com/1277243"},{"type":"REPORT","url":"https://bugzilla.suse.com/1280048"},{"type":"REPORT","url":"https://bugzilla.suse.com/1281431"},{"type":"REPORT","url":"https://bugzilla.suse.com/1281432"},{"type":"REPORT","url":"https://bugzilla.suse.com/1281433"},{"type":"REPORT","url":"https://bugzilla.suse.com/1281434"},{"type":"REPORT","url":"https://bugzilla.suse.com/1281435"},{"type":"REPORT","url":"https://bugzilla.suse.com/1282084"},{"type":"REPORT","url":"https://bugzilla.suse.com/1282085"},{"type":"REPORT","url":"https://bugzilla.suse.com/1282132"},{"type":"REPORT","url":"https://bugzilla.suse.com/1282140"},{"type":"REPORT","url":"https://bugzilla.suse.com/1282141"},{"type":"REPORT","url":"https://bugzilla.suse.com/1282362"},{"type":"REPORT","url":"https://bugzilla.suse.com/1282363"},{"type":"REPORT","url":"https://bugzilla.suse.com/1282364"},{"type":"REPORT","url":"https://bugzilla.suse.com/1282366"},{"type":"REPORT","url":"https://bugzilla.suse.com/1282367"},{"type":"REPORT","url":"https://bugzilla.suse.com/1282370"},{"type":"REPORT","url":"https://bugzilla.suse.com/1282372"},{"type":"REPORT","url":"https://bugzilla.suse.com/1282373"},{"type":"REPORT","url":"https://bugzilla.suse.com/1282374"},{"type":"REPORT","url":"https://bugzilla.suse.com/1282378"},{"type":"REPORT","url":"https://bugzilla.suse.com/1282506"},{"type":"REPORT","url":"https://bugzilla.suse.com/1282507"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-59902"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-59903"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-62243"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-62380"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-75595"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-75596"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-76816"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-89044"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-93488"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-93491"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-93492"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-93493"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-93494"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-93558"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-93560"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-93562"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-93563"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-93564"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-93565"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-93566"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-93567"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-93568"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-93569"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-93572"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-93573"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-93574"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-93575"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-93576"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-93578"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-93579"}],"affected":[{"package":{"name":"netty-tcnative","ecosystem":"SUSE:Linux Enterprise Module for Development Tools 15 SP7","purl":"pkg:rpm/suse/netty-tcnative&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Development%20Tools%2015%20SP7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.0.84-150200.3.51.1"}]}],"ecosystem_specific":{"binaries":[{"netty-tcnative":"2.0.84-150200.3.51.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4391-1.json"}},{"package":{"name":"netty","ecosystem":"SUSE:Linux Enterprise Module for Package Hub 15 SP7","purl":"pkg:rpm/suse/netty&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.1.138-150200.4.56.1"}]}],"ecosystem_specific":{"binaries":[{"netty":"4.1.138-150200.4.56.1","netty-javadoc":"4.1.138-150200.4.56.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4391-1.json"}},{"package":{"name":"netty-tcnative","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15 SP4-ESPOS","purl":"pkg:rpm/suse/netty-tcnative&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-ESPOS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.0.84-150200.3.51.1"}]}],"ecosystem_specific":{"binaries":[{"netty-tcnative":"2.0.84-150200.3.51.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4391-1.json"}},{"package":{"name":"netty-tcnative","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15 SP4-LTSS","purl":"pkg:rpm/suse/netty-tcnative&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.0.84-150200.3.51.1"}]}],"ecosystem_specific":{"binaries":[{"netty-tcnative":"2.0.84-150200.3.51.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4391-1.json"}},{"package":{"name":"netty-tcnative","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15 SP5-ESPOS","purl":"pkg:rpm/suse/netty-tcnative&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-ESPOS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.0.84-150200.3.51.1"}]}],"ecosystem_specific":{"binaries":[{"netty-tcnative":"2.0.84-150200.3.51.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4391-1.json"}},{"package":{"name":"netty-tcnative","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15 SP5-LTSS","purl":"pkg:rpm/suse/netty-tcnative&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.0.84-150200.3.51.1"}]}],"ecosystem_specific":{"binaries":[{"netty-tcnative":"2.0.84-150200.3.51.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4391-1.json"}},{"package":{"name":"netty-tcnative","ecosystem":"SUSE:Linux Enterprise Server 15 SP4-LTSS","purl":"pkg:rpm/suse/netty-tcnative&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP4-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.0.84-150200.3.51.1"}]}],"ecosystem_specific":{"binaries":[{"netty-tcnative":"2.0.84-150200.3.51.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4391-1.json"}},{"package":{"name":"netty-tcnative","ecosystem":"SUSE:Linux Enterprise Server 15 SP5-LTSS","purl":"pkg:rpm/suse/netty-tcnative&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP5-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.0.84-150200.3.51.1"}]}],"ecosystem_specific":{"binaries":[{"netty-tcnative":"2.0.84-150200.3.51.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4391-1.json"}},{"package":{"name":"netty-tcnative","ecosystem":"SUSE:Linux Enterprise Server 15 SP6-LTSS","purl":"pkg:rpm/suse/netty-tcnative&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP6-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.0.84-150200.3.51.1"}]}],"ecosystem_specific":{"binaries":[{"netty-tcnative":"2.0.84-150200.3.51.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4391-1.json"}},{"package":{"name":"netty-tcnative","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 15 SP4","purl":"pkg:rpm/suse/netty-tcnative&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.0.84-150200.3.51.1"}]}],"ecosystem_specific":{"binaries":[{"netty-tcnative":"2.0.84-150200.3.51.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4391-1.json"}},{"package":{"name":"netty-tcnative","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 15 SP5","purl":"pkg:rpm/suse/netty-tcnative&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.0.84-150200.3.51.1"}]}],"ecosystem_specific":{"binaries":[{"netty-tcnative":"2.0.84-150200.3.51.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4391-1.json"}},{"package":{"name":"netty-tcnative","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 15 SP6","purl":"pkg:rpm/suse/netty-tcnative&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.0.84-150200.3.51.1"}]}],"ecosystem_specific":{"binaries":[{"netty-tcnative":"2.0.84-150200.3.51.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4391-1.json"}}],"schema_version":"1.9.0"}