{"id":"USN-8654-1","summary":"netty vulnerabilities","details":"It was discovered that Netty did not properly handle malformed HTTP/2\ncontrol frames. An attacker could use this to cause a denial of service\nvia resource exhaustion. This issue only affects Ubuntu 18.04 LTS,\nUbuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 24.04 LTS. (CVE-2025-55163)\n\nIt was discovered that Netty did not properly validate the request URI\nfor line-break characters. An attacker could use this to perform CRLF\ninjection and request smuggling. (CVE-2025-67735)","modified":"2026-08-20T23:07:31.367090778Z","published":"2026-08-20T13:57:14Z","upstream":["CVE-2025-55163","CVE-2025-67735","UBUNTU-CVE-2025-55163","UBUNTU-CVE-2025-67735"],"references":[{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-8654-1"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2025-55163"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2025-67735"}],"affected":[{"package":{"name":"netty","ecosystem":"Ubuntu:Pro:16.04:LTS","purl":"pkg:deb/ubuntu/netty?arch=source&distro=esm-apps-legacy%2Fxenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:4.0.34-1ubuntu0.1~esm5"}]}],"versions":["1:3.2.6.Final-2","1:4.0.32-1","1:4.0.33-1","1:4.0.34-1","1:4.0.34-1ubuntu0.1~esm1","1:4.0.34-1ubuntu0.1~esm2","1:4.0.34-1ubuntu0.1~esm3","1:4.0.34-1ubuntu0.1~esm4"],"ecosystem_specific":{"binaries":[{"binary_name":"libnetty-java","binary_version":"1:4.0.34-1ubuntu0.1~esm5"}],"availability":"Available with Ubuntu Pro with Legacy support add-on: https://ubuntu.com/pro"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8654-1.json","cves_map":{"ecosystem":"Ubuntu:Pro:16.04:LTS","cves":[]}}},{"package":{"name":"netty","ecosystem":"Ubuntu:Pro:18.04:LTS","purl":"pkg:deb/ubuntu/netty?arch=source&distro=esm-apps%2Fbionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:4.1.7-4ubuntu0.1+esm7"}]}],"versions":["1:4.1.7-4","1:4.1.7-4ubuntu0.1~esm1","1:4.1.7-4ubuntu0.1","1:4.1.7-4ubuntu0.1+esm1","1:4.1.7-4ubuntu0.1+esm2","1:4.1.7-4ubuntu0.1+esm3","1:4.1.7-4ubuntu0.1+esm4","1:4.1.7-4ubuntu0.1+esm5","1:4.1.7-4ubuntu0.1+esm6"],"ecosystem_specific":{"binaries":[{"binary_name":"libnetty-java","binary_version":"1:4.1.7-4ubuntu0.1+esm7"}],"availability":"Available with Ubuntu Pro: https://ubuntu.com/pro"},"database_specific":{"cves_map":{"cves":[],"ecosystem":"Ubuntu:Pro:18.04:LTS"},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8654-1.json"}},{"package":{"name":"netty","ecosystem":"Ubuntu:Pro:20.04:LTS","purl":"pkg:deb/ubuntu/netty?arch=source&distro=esm-apps%2Ffocal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:4.1.45-1ubuntu0.1~esm7"}]}],"versions":["1:4.1.33-1","1:4.1.33-2","1:4.1.33-3","1:4.1.45-1","1:4.1.45-1ubuntu0.1~esm1","1:4.1.45-1ubuntu0.1~esm2","1:4.1.45-1ubuntu0.1~esm3","1:4.1.45-1ubuntu0.1~esm4","1:4.1.45-1ubuntu0.1~esm6"],"ecosystem_specific":{"availability":"Available with Ubuntu Pro: https://ubuntu.com/pro","binaries":[{"binary_name":"libnetty-java","binary_version":"1:4.1.45-1ubuntu0.1~esm7"}]},"database_specific":{"cves_map":{"ecosystem":"Ubuntu:Pro:20.04:LTS","cves":[]},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8654-1.json"}},{"package":{"name":"netty","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/netty?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:4.1.48-4+deb11u2ubuntu0.2"}]}],"versions":["1:4.1.48-4","1:4.1.48-4+deb11u1build0.22.04.1","1:4.1.48-4+deb11u2build0.22.04.1","1:4.1.48-4+deb11u2ubuntu0.1"],"ecosystem_specific":{"binaries":[{"binary_name":"libnetty-java","binary_version":"1:4.1.48-4+deb11u2ubuntu0.2"}],"availability":"No subscription required"},"database_specific":{"cves_map":{"cves":[],"ecosystem":"Ubuntu:22.04:LTS"},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8654-1.json"}},{"package":{"name":"netty","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/netty?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:4.1.48-9ubuntu0.2"}]}],"versions":["1:4.1.48-7","1:4.1.48-8","1:4.1.48-9","1:4.1.48-9ubuntu0.1"],"ecosystem_specific":{"binaries":[{"binary_name":"libnetty-java","binary_version":"1:4.1.48-9ubuntu0.2"}],"availability":"No subscription required"},"database_specific":{"cves_map":{"ecosystem":"Ubuntu:24.04:LTS","cves":[]},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8654-1.json"}}],"schema_version":"1.9.0"}