Several security vulnerabilities have been discovered in Netty, a Java NIO
client/server socket framework. It was found that Netty was vulnerable to the
MadeYouReset DDoS attack, a logical vulnerability in the HTTP/2 protocol
itself and programming errors which enabled request smuggling attacks.
Additionally Netty contained an SMTP command injection vulnerability due to
insufficient input validation potentially allowing remote attackers to forge
arbitrary emails from trusted servers.
The security update also contains the fix for CVE-2024-29025.
Julien Viet discovered that Netty was vulnerable to allocation of resources
without limits or throttling due to the accumulation of data in the
HttpPostRequestDecoder. This would allow an attacker to cause a denial of
service.
For Debian 11 bullseye, these problems have been fixed in version
1:4.1.48-4+deb11u3.
We recommend that you upgrade your netty packages.
For the detailed security status of netty please refer to
its security tracker page at:
Get the latest Linux and open source security news straight to your inbox.