Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Debian 11 Netty Important DDoS Request Smuggling Crash Advisory DLA-4519-1

debian lts
Calendar Grey March 31, 2026
Dist Debian Esm H88
Several vulnerabilities in Netty reveal risks including DDoS attacks and SMTP command injection. Upgrade recommended for fixes.
Several security vulnerabilities have been discovered in Netty, a Java NIO client/server socket framework

Summary

Several security vulnerabilities have been discovered in Netty, a Java NIO
client/server socket framework. It was found that Netty was vulnerable to the
MadeYouReset DDoS attack, a logical vulnerability in the HTTP/2 protocol
itself and programming errors which enabled request smuggling attacks.
Additionally Netty contained an SMTP command injection vulnerability due to
insufficient input validation potentially allowing remote attackers to forge
arbitrary emails from trusted servers.

The security update also contains the fix for CVE-2024-29025.
Julien Viet discovered that Netty was vulnerable to allocation of resources
without limits or throttling due to the accumulation of data in the
HttpPostRequestDecoder. This would allow an attacker to cause a denial of
service.

For Debian 11 bullseye, these problems have been fixed in version
1:4.1.48-4+deb11u3.

We recommend that you upgrade your netty packages.

For the detailed security status of netty please refer to
its security tracker page at:

Read the Full Advisory


Severity
important
Lowest
Low
Medium
High
Critical

Package: netty
Version: 1:4.1.48-4+deb11u3
CVE ID: CVE-2024-29025 CVE-2025-55163 CVE-2025-58056 CVE-2025-58057
Debian Bug: 1068110 1111105 1113994 1118282 1123606

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here