QID 982253
QID 982253: Java (maven) Security Update for io.netty:netty-handler (GHSA-mm9x-g8pc-w292)
The ZlibDecoders in Netty 4.1.x before 4.1.46 allow for unbounded memory allocation while decoding a ZlibEncoded byte stream. An attacker could send a large ZlibEncoded byte stream to the Netty server, forcing the server to allocate all of its free memory to a single decoder.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-mm9x-g8pc-w292 for updates pertaining to this vulnerability.
Vendor References
- GHSA-mm9x-g8pc-w292 -
github.com/advisories/GHSA-mm9x-g8pc-w292
CVEs related to QID 982253
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-mm9x-g8pc-w292 | io.netty:netty-handler |
|