SUSE-SU-2026:3482-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-20263482-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3482-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/SUSE-SU-2026:3482-1
Upstream
Related
Published
2026-08-04T11:46:42Z
Modified
2026-08-05T18:23:48.157302386Z
Summary
Security update for netty, netty-tcnative
Details

This update for netty, netty-tcnative fixes the following issues:

Upgrade netty to upstream version 4.1.136 and netty-tcnative to version 2.0.80 Final.

Security issues fixed

  • CVE-2026-44891: memory exhaustion in io.netty:netty-codec-stomp (bsc#1271435).
  • CVE-2026-55831: resource exhaustion/DoS in io.netty:netty-codec-http (bsc#1271960).
  • CVE-2026-55833: zip bomb in io.netty:netty-codec-http (bsc#1271961).
  • CVE-2026-55851: memory exhaustion in io.netty:netty-codec-haproxy (bsc#1272253).
  • CVE-2026-56745: memory exhaustion in io.netty:netty-codec-http (bsc#1272254).
  • CVE-2026-56746: improper access control in io.netty:netty-codec-http (CORS) (bsc#1272255).
  • CVE-2026-56817: insecure defaults in XML parsing in io.netty:netty-codec-xml (bsc#1272257).
  • CVE-2026-56818: memory leak in io.netty:netty-codec-redis (bsc#1272603).
  • CVE-2026-56819: memory leak in io.netty:netty-codec-http2 (bsc#1272258).
  • CVE-2026-56820: improper certificate validation in io.netty:netty-handler-ssl-ocsp (bsc#1272259).
  • CVE-2026-56821: improper certificate revocation check in io.netty:netty-handler-ssl-ocsp (bsc#1272299).
  • CVE-2026-56822: time-of-check/time-of-use in io.netty:netty-handler-ssl-ocsp (bsc#1272300).
  • CVE-2026-59898: protocol version confusion in io.netty:netty-codec-http (websocket) (bsc#1272302).
  • CVE-2026-59899: memory exhaustion in io.netty:netty-codec-http (bsc#1272301).
  • CVE-2026-59900: improper header neutralization in io.netty:netty-codec-http2 (bsc#1272303).
  • CVE-2026-59901: infinite loop in io.netty:netty-codec-compression (bzip2) (bsc#1272304).
  • CVE-2026-59919: improper CR/LF neutralization in io.netty:netty-codec-haproxy (bsc#1272305).
  • CVE-2026-59920: improper CR/LF neutrolization in io.netty:netty-codec-stomp (bsc#1272306).
  • CVE-2026-59921: improper CR/LF neutralization in io.netty:netty-codec-http (multipart) (bsc#1272307).
  • Memory leak in io.netty:netty-codec-dns (bsc#1272519).
  • Uncontrolled resource consumption in io.netty:netty-codec-xml (bsc#1272518).

Other updates and bugfixes:

  • Upgrade to upstream version 4.1.136:
    • SingleThreadEventExecutor: document Throwable safety contract on run()
    • Make HTTP/2 frame hashCode consistent with equals
    • Add BlockHound exception for DnsQueryIdSpace (#16896)
    • FlowControlHandler: Fix autoRead behavior
    • Fix incorrect bounds in error message of HpackDecoder.setMaxHeaderListSize
    • MQTT: Fix MQTT decoder size check after variable header replay
    • MQTT: Make the decodeProperties early-REPLAY check actually fire
    • Reject control characters at the boundary of HTTP method names (#16723)
    • Update to latest tcnative release
    • Fix HTTP 2 PUSH_PROMISE stream association validation
    • Fix GZIP FEXTRA extra-field handling in JdkZlibDecoder
    • Add opt-in validation of mandatory pseudo-header fields for HTTP/2
    • Strictly validate MQTT UTF-8 Encoded String (#16939)
    • Stop DateFormatter trailing token from running past the parse end
    • IpFilter: Deprecate constructor which use accept by default
    • Add RFC 10008 QUERY Method support (#16966)
    • Correctly release and fail queued traffic-shaping writes on close (#16959)
    • FlowControlHandler: respect auto-read when toggled while dequeueing
    • IdleStateHandler: reset firstWriter/ReaderIdleEvent in resetWriteTimeout/resetReadTimeout (#16982)
    • Fix typo in AbstractSniHandler Javadoc
    • Reconcile AbstractCoalescingBufferQueue readableBytes when it drains, and fail stuck HTTP/2 streams instead of spinning empty DATA frames
    • Reject control characters at the boundary of the HTTP version token (#16971)
    • Reset UTF-8 decode state on CR in StompSubframeDecoder
    • HTTP2: Pass the correct number of arguments when logging goaway
    • FastLz: Guard decompression against truncated input (#17000)
    • Fix propagation of startTls for client SslContext handler
    • Reject non-token characters in HTTP/2 header names
    • Update lz4-java to 1.11.1
    • Pin github actions to reduce risk (#17043)
    • Merge branches from forks (#17063)
References

Affected packages

SUSE:Linux Enterprise High Performance Computing 15 SP4-ESPOS
netty-tcnative

Package

Name
netty-tcnative
Purl
pkg:rpm/suse/netty-tcnative&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-ESPOS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.0.80-150200.3.48.1

Ecosystem specific

{
    "binaries": [
        {
            "netty-tcnative": "2.0.80-150200.3.48.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3482-1.json"
SUSE:Linux Enterprise High Performance Computing 15 SP4-LTSS
netty-tcnative

Package

Name
netty-tcnative
Purl
pkg:rpm/suse/netty-tcnative&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.0.80-150200.3.48.1

Ecosystem specific

{
    "binaries": [
        {
            "netty-tcnative": "2.0.80-150200.3.48.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3482-1.json"
SUSE:Linux Enterprise High Performance Computing 15 SP5-ESPOS
netty-tcnative

Package

Name
netty-tcnative
Purl
pkg:rpm/suse/netty-tcnative&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-ESPOS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.0.80-150200.3.48.1

Ecosystem specific

{
    "binaries": [
        {
            "netty-tcnative": "2.0.80-150200.3.48.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3482-1.json"
SUSE:Linux Enterprise High Performance Computing 15 SP5-LTSS
netty-tcnative

Package

Name
netty-tcnative
Purl
pkg:rpm/suse/netty-tcnative&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.0.80-150200.3.48.1

Ecosystem specific

{
    "binaries": [
        {
            "netty-tcnative": "2.0.80-150200.3.48.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3482-1.json"
SUSE:Linux Enterprise Module for Development Tools 15 SP7
netty-tcnative

Package

Name
netty-tcnative
Purl
pkg:rpm/suse/netty-tcnative&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Development%20Tools%2015%20SP7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.0.80-150200.3.48.1

Ecosystem specific

{
    "binaries": [
        {
            "netty-tcnative": "2.0.80-150200.3.48.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3482-1.json"
SUSE:Linux Enterprise Module for Package Hub 15 SP7
netty

Package

Name
netty
Purl
pkg:rpm/suse/netty&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.1.136-150200.4.53.1

Ecosystem specific

{
    "binaries": [
        {
            "netty-javadoc": "4.1.136-150200.4.53.1",
            "netty": "4.1.136-150200.4.53.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3482-1.json"
SUSE:Linux Enterprise Server 15 SP4-LTSS
netty-tcnative

Package

Name
netty-tcnative
Purl
pkg:rpm/suse/netty-tcnative&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP4-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.0.80-150200.3.48.1

Ecosystem specific

{
    "binaries": [
        {
            "netty-tcnative": "2.0.80-150200.3.48.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3482-1.json"
SUSE:Linux Enterprise Server 15 SP5-LTSS
netty-tcnative

Package

Name
netty-tcnative
Purl
pkg:rpm/suse/netty-tcnative&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP5-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.0.80-150200.3.48.1

Ecosystem specific

{
    "binaries": [
        {
            "netty-tcnative": "2.0.80-150200.3.48.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3482-1.json"
SUSE:Linux Enterprise Server 15 SP6-LTSS
netty-tcnative

Package

Name
netty-tcnative
Purl
pkg:rpm/suse/netty-tcnative&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP6-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.0.80-150200.3.48.1

Ecosystem specific

{
    "binaries": [
        {
            "netty-tcnative": "2.0.80-150200.3.48.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3482-1.json"
SUSE:Linux Enterprise Server for SAP Applications 15 SP4
netty-tcnative

Package

Name
netty-tcnative
Purl
pkg:rpm/suse/netty-tcnative&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.0.80-150200.3.48.1

Ecosystem specific

{
    "binaries": [
        {
            "netty-tcnative": "2.0.80-150200.3.48.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3482-1.json"
SUSE:Linux Enterprise Server for SAP Applications 15 SP5
netty-tcnative

Package

Name
netty-tcnative
Purl
pkg:rpm/suse/netty-tcnative&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.0.80-150200.3.48.1

Ecosystem specific

{
    "binaries": [
        {
            "netty-tcnative": "2.0.80-150200.3.48.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3482-1.json"
SUSE:Linux Enterprise Server for SAP Applications 15 SP6
netty-tcnative

Package

Name
netty-tcnative
Purl
pkg:rpm/suse/netty-tcnative&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.0.80-150200.3.48.1

Ecosystem specific

{
    "binaries": [
        {
            "netty-tcnative": "2.0.80-150200.3.48.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3482-1.json"