This update for netty, netty-tcnative fixes the following issues:
Upgrade to upstream version 4.1.126.
Security issues fixed:
* CVE-2025-58057: decompression codecs allocating a large number of buffers
after processing specially crafted input can cause a denial of service
(bsc#1249134).
* CVE-2025-58056: incorrect parsing of chunk extensions can lead to request
smuggling (bsc#1249116).
* CVE-2025-55163: "MadeYouReset" denial of serivce attack in the HTTP/2
protocol (bsc#1247991).
Other issues fixed:
* Fixes from version 4.1.126
* Fix IllegalReferenceCountException on invalid upgrade response.
* Drop unknown frame on missing stream.
* Don't try to handle incomplete upgrade request.
* Update to netty-tcnative 2.0.73Final.
* Fixes from version 4.1.124
* Fix NPE and AssertionErrors when many tasks are scheduled and cancelled.
* HTTP2: Http2ConnectionHandler should always use Http2ConnectionEncoder.
* Epoll: Correctly handle UDP packets with...
Read the Full Advisory## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5
zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2025-3114=1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5
zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2025-3114=1
* SUSE Linux Enterprise Server 15 SP3 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP3-LTSS-2025-3114=1
* SUSE Linux Enterprise Server 15 SP4 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2025-3114=1
* SUSE Linux Enterprise Server 15 SP5 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2025-3114=1
* SUSE Linux Enterprise Server for SAP Applications 15 SP3
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP3-2025-3114=1
* SUSE Linux Enterprise Server for SAP Applications 15 SP4
zypper in -t patch...
Read the Full Advisory* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64
x86_64)
* netty-tcnative-2.0.73-150200.3.30.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64
x86_64)
* netty-tcnative-2.0.73-150200.3.30.1
* SUSE Linux Enterprise Server 15 SP3 LTSS (aarch64 ppc64le s390x x86_64)
* netty-tcnative-2.0.73-150200.3.30.1
* SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64)
* netty-tcnative-2.0.73-150200.3.30.1
* SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64)
* netty-tcnative-2.0.73-150200.3.30.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP3 (ppc64le x86_64)
* netty-tcnative-2.0.73-150200.3.30.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64)
* netty-tcnative-2.0.73-150200.3.30.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64)
* netty-tcnative-2.0.73-150200.3.30.1
* SUSE Enterprise Storage 7.1 (aarch64 x86_64)
* netty-tcnative-2.0.73-150200.3.30.1
* openSUSE Leap...
Read the Full Advisory* bsc#1247991
* bsc#1249116
* bsc#1249134
## References:
* https://www.suse.com/security/cve/CVE-2025-55163.html
* https://www.suse.com/security/cve/CVE-2025-58056.html
* https://www.suse.com/security/cve/CVE-2025-58057.html
* https://bugzilla.suse.com/show_bug.cgi?id=1247991
* https://bugzilla.suse.com/show_bug.cgi?id=1249116
* https://bugzilla.suse.com/show_bug.cgi?id=1249134
Get the latest Linux and open source security news straight to your inbox.