CVE-2022-41881
Summary
| CVE | CVE-2022-41881 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-12-12 18:15:00 UTC |
| Updated | 2023-03-01 15:08:00 UTC |
| Description | Netty project is an event-driven asynchronous network application framework. In versions prior to 4.1.86.Final, a StackOverflowError can be raised when parsing a malformed crafted message due to an infinite recursion. This issue is patched in version 4.1.86.Final. There is no workaround, except using a custom HaProxyMessageDecoder. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] [DLA 3268-1] netty security update |
MLIST |
lists.debian.org |
|
| Debian -- Security Information -- DSA-5316-1 netty |
DEBIAN |
www.debian.org |
|
| HAProxyMessageDecoder Stack Exhaustion DoS · Advisory · netty/netty · GitHub |
MISC |
github.com |
|
| December 2022 Apache Netty Vulnerabilities in NetApp Products | NetApp Product Security |
CONFIRM |
security.netapp.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 181469 Debian Security Update for netty (DLA 3268-1)
- 181471 Debian Security Update for netty (DSA 5316-1)
- 182291 Debian Security Update for netty (CVE-2022-41881)
- 199574 Ubuntu Security Notification for Netty Vulnerabilities (USN-6049-1)
- 241301 Red Hat Update for JBoss Enterprise Application Platform 7.4.1 on RHEL 7 (RHSA-2023:1512)
- 241302 Red Hat Update for JBoss Enterprise Application Platform 7.4.1 on RHEL 8 (RHSA-2023:1513)
- 241303 Red Hat Update for JBoss Enterprise Application Platform 7.4.1 on RHEL 9 (RHSA-2023:1514)
- 378427 Oracle PeopleSoft Enterprise PeopleTools Product Multiple Vulnerabilities (CPUAPR2023)
- 378429 Oracle Coherence April 2023 Critical Patch Update (CPUAPR2023)
- 753971 SUSE Enterprise Linux Security Update for netty, netty-tcnative (SUSE-SU-2023:2096-1)