SUSE-SU-2026:1353-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-20261353-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:1353-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/SUSE-SU-2026:1353-1
Upstream
CVE (2)
Related
Published
2026-04-15T13:37:19Z
Modified
2026-04-16T08:31:24Z
Summary
Security update for netty, netty-tcnative
Details

This update for netty, netty-tcnative fixes the following issues:

Upidate to 4.1.132:

  • CVE-2026-33870: incorrectly parses quoted strings in HTTP/1.1 can lead to request smuggling (bsc#1261031).
  • CVE-2026-33871: sending a flood of CONTINUATION frames can lead to a denial of service (bsc#1261043).

Changelog:

  • Upgrade to upstream version 4.1.132
  • Fixes:
  • Fix Incorrect nanos-to-millis conversion in epoll_wait EINTR retry loop
  • Make RefCntOpenSslContext.deallocate more robust
  • HTTP2: Correctly account for padding when decompress
  • Fix high-order bit aliasing in HttpUtil.validateToken
  • fix: the precedence of + is higher than >>
  • AdaptiveByteBufAllocator: make sure byteBuf.capacity() not greater than byteBuf.maxCapacity()
  • AdaptivePoolingAllocator: call unreserveMatchingBuddy(...) if byteBuf initialization failed
  • Don't assume CertificateFactory is thread-safe
  • Fix HttpObjectAggregator leaving connection stuck after 413 with AUTO_READ=false
  • HTTP2: Ensure preface is flushed in all cases
  • Fix UnsupportedOperationException in readTrailingHeaders
  • Fix client_max_window_bits parameter handling in permessage-deflate extension
  • Native transports: Fix possible fd leak when fcntl fails.
  • Kqueue: Fix undefined behaviour when GetStringUTFChars fails and SO_ACCEPTFILTER is supported
  • Kqueue: Possible overflow when using netty_kqueue_bsdsocket_setAcceptFilter(...)
  • Native transports: Fix undefined behaviour when GetStringUTFChars fails while open FD
  • Epoll: Add null checks for safety reasons
  • Epoll: Use correct value to initialize mmsghdr.msg_namelen
  • Epoll: Fix support for IP_RECVORIGDSTADDR
  • AdaptivePoolingAllocator: remove ensureAccessible() call in capacity(int) method
  • Epoll: setTcpMg5Sig(...) might overflow
  • JdkZlibDecoder: accumulate decompressed output before firing channelRead
  • Limit the number of Continuation frames per HTTP2 Headers (bsc#1261043, CVE-2026-33871)
  • Stricter HTTP/1.1 chunk extension parsing (bsc#1261031, CVE-2026-33870)
  • rediff
  • Upgrade to upstream version 4.1.131
  • NioDatagramChannel.block(...) does not early return on failure
  • Support for AWS Libcrypto (AWS-LC) netty-tcnative build
  • codec-dns: Decompress MX RDATA exchange domain names during DNS record decoding
  • Buddy allocation for large buffers in adaptive allocator
  • SslHandler: Only resume on EventLoop if EventLoop is not shutting down already
  • Wrap ECONNREFUSED in PortUnreachableException for UDP
  • Bump com.ning:compress-lzf (4.1)
  • Fix adaptive allocator bug from not noticing failed allocation
  • Avoid loosing original read exception
  • Backport multiple adaptive allocator changes
  • Upgrade to version 4.1.130
  • Upgrade to version 2.0.75 Final
  • No formal changelog present
  • Needed by netty >= 4.2.11
References

Affected packages

openSUSE:Leap 15.6
netty

Package

Name
netty
Purl
pkg:rpm/opensuse/netty&distro=openSUSE%20Leap%2015.6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
4.1.132-150200.4.43.1

Ecosystem specific

{
    "binaries":  [
        {
            "netty":  "4.1.132-150200.4.43.1",
            "netty-javadoc":  "4.1.132-150200.4.43.1",
            "netty-tcnative":  "2.0.75-150200.3.36.1",
            "netty-tcnative-javadoc":  "2.0.75-150200.3.36.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:1353-1.json"
netty-tcnative

Package

Name
netty-tcnative
Purl
pkg:rpm/opensuse/netty-tcnative&distro=openSUSE%20Leap%2015.6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.0.75-150200.3.36.1

Ecosystem specific

{
    "binaries":  [
        {
            "netty":  "4.1.132-150200.4.43.1",
            "netty-javadoc":  "4.1.132-150200.4.43.1",
            "netty-tcnative":  "2.0.75-150200.3.36.1",
            "netty-tcnative-javadoc":  "2.0.75-150200.3.36.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:1353-1.json"
SUSE:Linux Enterprise Module for Development Tools 15 SP7
netty-tcnative

Package

Name
netty-tcnative
Purl
pkg:rpm/suse/netty-tcnative&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Development%20Tools%2015%20SP7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.0.75-150200.3.36.1

Ecosystem specific

{
    "binaries":  [
        {
            "netty-tcnative":  "2.0.75-150200.3.36.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:1353-1.json"
SUSE:Linux Enterprise Module for Package Hub 15 SP7
netty

Package

Name
netty
Purl
pkg:rpm/suse/netty&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
4.1.132-150200.4.43.1

Ecosystem specific

{
    "binaries":  [
        {
            "netty":  "4.1.132-150200.4.43.1",
            "netty-javadoc":  "4.1.132-150200.4.43.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:1353-1.json"