gpp_maybe
Security update for netty, netty-tcnative
SUSE-SLE-Module-Development-Tools-15-SP7-2026-2308
This update for netty, netty-tcnative fixes the following issues - CVE-2026-41417: missing validations leads to HTTP request smuggling and RTSP request injection via start-line injection in `DefaultHttpRequest.setUri()` (bsc#1264350). - CVE-2026-42578: HTTP Header Injection via HttpProxyHandler Disabled Validation in Netty (bsc#1265243). - CVE-2026-42579: DNS codec does not enforce RFC 1035 domain name constraints during either encoding or decoding (bsc#1265272). - CVE-2026-42580: chunk size parser silently overflows int and enables request smuggling attacks (bsc#1265273). - CVE-2026-42581: TE+CL header coexistence in HTTP/1.0 requests bypasses smuggling sanitization (bsc#1265277). - CVE-2026-42583: resource exhaustion and possible denial of service via `Lz4FrameDecoder` (bsc#1265279). - CVE-2026-42584: improper handling of inbound responses in `HttpClientCodec` can lead to response desynchronization (bsc#1265280). - CVE-2026-42585: Netty is an asynchronous, event-driven network application framework (bsc#1265292). - CVE-2026-42586: CRLF Injection in Netty Redis Codec Encoder (bsc#1265245). - CVE-2026-42587: HttpContentDecompressor maxAllocation bypass via Content-Encoding: br/zstd/snappy enables decompression bomb DoS (bsc#1265246). - CVE-2026-44248: Netty is an asynchronous, event-driven network application framework (bsc#1265294). - CVE-2026-42582: HTTP/3 QPACK literal unbounded allocation (bsc#1265318). Changes for netty: - Upgrade to upstream version 4.1.133
-
Release DateJun 9 2026
-
ReferencesBugzilla: 1264350, 1265243, 1265245, 1265246, 1265272, 1265273, 1265277, 1265279, 1265280, 1265292, 1265294, 1265318
CVEs: CVE-2026-42582, CVE-2026-42583, CVE-2026-42584, CVE-2026-41417, CVE-2026-42578, CVE-2026-42579, CVE-2026-42580, CVE-2026-42581, CVE-2026-42585, CVE-2026-42586, CVE-2026-42587, CVE-2026-44248 -
Typesecurity
-
Severityimportant
cloud_download Downloads
Development Tools Module 15.7 s390x
-
Packagesnetty-tcnative
Fork of Tomcat Native with improved OpenSSL and mavenized build2.0.77-150200.3.39.1 lock rpm lock src
Development Tools Module 15.7 aarch64
-
Packagesnetty-tcnative
Fork of Tomcat Native with improved OpenSSL and mavenized build2.0.77-150200.3.39.1 lock rpm lock src
Development Tools Module 15.7 x86_64
-
Packagesnetty-tcnative
Fork of Tomcat Native with improved OpenSSL and mavenized build2.0.77-150200.3.39.1 lock rpm lock src
Development Tools Module 15.7 ppc64le
-
Packagesnetty-tcnative
Fork of Tomcat Native with improved OpenSSL and mavenized build2.0.77-150200.3.39.1 lock rpm lock src