gpp_maybe
Security update for netty, netty-tcnative
SUSE-SLE-Module-Development-Tools-15-SP7-2026-3482
This update for netty, netty-tcnative fixes the following issues: Upgrade netty to upstream version 4.1.136 and netty-tcnative to version 2.0.80 Final. Security issues fixed - CVE-2026-44891: memory exhaustion in `io.netty:netty-codec-stomp` (bsc#1271435). - CVE-2026-55831: resource exhaustion/DoS in `io.netty:netty-codec-http` (bsc#1271960). - CVE-2026-55833: zip bomb in `io.netty:netty-codec-http` (bsc#1271961). - CVE-2026-55851: memory exhaustion in `io.netty:netty-codec-haproxy` (bsc#1272253). - CVE-2026-56745: memory exhaustion in `io.netty:netty-codec-http` (bsc#1272254). - CVE-2026-56746: improper access control in `io.netty:netty-codec-http` (CORS) (bsc#1272255). - CVE-2026-56817: insecure defaults in XML parsing in `io.netty:netty-codec-xml` (bsc#1272257). - CVE-2026-56818: memory leak in `io.netty:netty-codec-redis` (bsc#1272603). - CVE-2026-56819: memory leak in `io.netty:netty-codec-http2` (bsc#1272258). - CVE-2026-56820: improper certificate validation in `io.netty:netty-handler-ssl-ocsp` (bsc#1272259). - CVE-2026-56821: improper certificate revocation check in `io.netty:netty-handler-ssl-ocsp` (bsc#1272299). - CVE-2026-56822: time-of-check/time-of-use in `io.netty:netty-handler-ssl-ocsp` (bsc#1272300). - CVE-2026-59898: protocol version confusion in `io.netty:netty-codec-http` (websocket) (bsc#1272302). - CVE-2026-59899: memory exhaustion in `io.netty:netty-codec-http` (bsc#1272301). - CVE-2026-59900: improper header neutralization in `io.netty:netty-codec-http2` (bsc#1272303). - CVE-2026-59901: infinite loop in `io.netty:netty-codec-compression` (bzip2) (bsc#1272304). - CVE-2026-59919: improper CR/LF neutralization in `io.netty:netty-codec-haproxy` (bsc#1272305). - CVE-2026-59920: improper CR/LF neutrolization in `io.netty:netty-codec-stomp` (bsc#1272306). - CVE-2026-59921: improper CR/LF neutralization in `io.netty:netty-codec-http` (multipart) (bsc#1272307). - Memory leak in `io.netty:netty-codec-dns` (bsc#1272519). - Uncontrolled resource consumption in `io.netty:netty-codec-xml` (bsc#1272518). Other updates and bugfixes: - Upgrade to upstream version 4.1.136: + SingleThreadEventExecutor: document Throwable safety contract on run() + Make HTTP/2 frame hashCode consistent with equals + Add BlockHound exception for DnsQueryIdSpace (#16896) + FlowControlHandler: Fix autoRead behavior + Fix incorrect bounds in error message of HpackDecoder.setMaxHeaderListSize + MQTT: Fix MQTT decoder size check after variable header replay + MQTT: Make the decodeProperties early-REPLAY check actually fire + Reject control characters at the boundary of HTTP method names (#16723) + Update to latest tcnative release + Fix HTTP 2 PUSH_PROMISE stream association validation + Fix GZIP FEXTRA extra-field handling in JdkZlibDecoder + Add opt-in validation of mandatory pseudo-header fields for HTTP/2 + Strictly validate MQTT UTF-8 Encoded String (#16939) + Stop DateFormatter trailing token from running past the parse end + IpFilter: Deprecate constructor which use accept by default + Add RFC 10008 QUERY Method support (#16966) + Correctly release and fail queued traffic-shaping writes on close (#16959) + FlowControlHandler: respect auto-read when toggled while dequeueing + IdleStateHandler: reset firstWriter/ReaderIdleEvent in resetWriteTimeout/resetReadTimeout (#16982) + Fix typo in AbstractSniHandler Javadoc + Reconcile AbstractCoalescingBufferQueue readableBytes when it drains, and fail stuck HTTP/2 streams instead of spinning empty DATA frames + Reject control characters at the boundary of the HTTP version token (#16971) + Reset UTF-8 decode state on CR in StompSubframeDecoder + HTTP2: Pass the correct number of arguments when logging goaway + FastLz: Guard decompression against truncated input (#17000) + Fix propagation of startTls for client SslContext handler + Reject non-token characters in HTTP/2 header names + Update lz4-java to 1.11.1 + Pin github actions to reduce risk (#17043) + Merge branches from forks (#17063)
-
Release DateAug 4 2026
-
ReferencesBugzilla: 1271435, 1271960, 1271961, 1272253, 1272254, 1272255, 1272257, 1272258, 1272259, 1272299, 1272300, 1272301, 1272302, 1272303, 1272304, 1272305, 1272306, 1272307, 1272518, 1272519, 1272603
CVEs: CVE-2026-44891, CVE-2026-55831, CVE-2026-55833, CVE-2026-55851, CVE-2026-56745, CVE-2026-56746, CVE-2026-56817, CVE-2026-56818, CVE-2026-56819, CVE-2026-56820, CVE-2026-56821, CVE-2026-56822, CVE-2026-59898, CVE-2026-59899, CVE-2026-59900, CVE-2026-59901, CVE-2026-59919, CVE-2026-59920, CVE-2026-59921 -
Typesecurity
-
Severityimportant
cloud_download Downloads
Development Tools Module 15.7 aarch64
-
Packagesnetty-tcnative
Fork of Tomcat Native with improved OpenSSL and mavenized build2.0.80-150200.3.48.1 lock rpm lock src
Development Tools Module 15.7 ppc64le
-
Packagesnetty-tcnative
Fork of Tomcat Native with improved OpenSSL and mavenized build2.0.80-150200.3.48.1 lock rpm lock src
Development Tools Module 15.7 s390x
-
Packagesnetty-tcnative
Fork of Tomcat Native with improved OpenSSL and mavenized build2.0.80-150200.3.48.1 lock rpm lock src
Development Tools Module 15.7 x86_64
-
Packagesnetty-tcnative
Fork of Tomcat Native with improved OpenSSL and mavenized build2.0.80-150200.3.48.1 lock rpm lock src