SUSE-SU-2026:2802-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-20262802-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2802-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/SUSE-SU-2026:2802-1
Upstream
Related
Published
2026-07-08T19:06:43Z
Modified
2026-07-09T10:00:05Z
Summary
Security update for netty, netty-tcnative
Details

This update for netty, netty-tcnative fixes the following issue

This update for netty, netty-tcnative fixes the following issues

Upgrade netty to upstream version 4.1.135, netty-tcnative to upstream version 2.0.79:

  • CVE-2026-44249: IPv6 Subnet Filter Bypass via Incorrect Comparator Masking (bsc#1268165).
  • CVE-2026-44250: Memory Exhaustion in RedisArrayAggregator due to Deeply Nested Arrays (bsc#1268169).
  • CVE-2026-44890: Unbounded Direct Memory Consumption in RedisDecoder (bsc#1268170).
  • CVE-2026-44893: netty-codec-haproxy: Denial of Service via malformed HAProxy message (bsc#1268244).
  • CVE-2026-45416: SNI handler pre-allocates up to 16 MiB from nine attacker bytes (bsc#1268246).
  • CVE-2026-45536: Unix-socket fd receive leaks descriptors when peer sends two at once (bsc#1268247).
  • CVE-2026-45673: netty-resolver-dns: DNS Cache Poisoning via predictable transaction IDs (bsc#1268248).
  • CVE-2026-45674: DNS Cache Poisoning via Missing Bailiwick Checks in CNAME Records (bsc#1268249).
  • CVE-2026-46340: netty-transport-sctp: Denial of Service due to unbounded memory growth from SctpMessage fragments (bsc#1268250).
  • CVE-2026-47244: HTTP/2: Advertised MAX_CONCURRENT_STREAMS not enforced (bsc#1268251).
  • CVE-2026-47691: Insufficient Bailiwick Validation for NS Records (bsc#1268252).
  • CVE-2026-48006: netty-codec-redis: Netty's Lack of Lifecycle Cleanup Leads to Pooled ByteBuf Leak in RedisArrayAggregator (bsc#1268255).
  • CVE-2026-48043: netty-codec-http2: Denial of Service due to resource leak (bsc#1268257).
  • CVE-2026-48059: netty-codec-haproxy: Denial of Service via memory leak from crafted PROXY protocol headers (bsc#1268258).
  • CVE-2026-50010: Wrapping plain trust manager silently disables hostname verification (bsc#1268259).
  • CVE-2026-50011: Unbounded pre-allocation in RedisArrayAggregator from RESP array length (bsc#1268260).
  • CVE-2026-50020: HttpObjectDecoder skips arbitrary initial control characters when only initial CRLF characters are permitted (bsc#1268261).
  • CVE-2026-50560: Netty susceptible to HTTP/2 Reset Attack with different on-the-wire signature (bsc#1268262).

Changes:

  • MQTT: Allow MQTT 5 CONNECT with password only
  • ChannelInitializer: correct misleading comment on exceptionCaught route
  • HTTP/2: Parse request-target path like Vert.x (4.1 backport)
  • HttpObjectDecoder skips arbitrary initial control characters when only initial CRLF characters are permitted
  • IpSubnetFilter: Correctly handle ipv6
  • Configurable bound on RedisArrayAggregator
  • Redis: Limit decoded length
  • DNS: Ensure query id is not predictible
  • Wrapping plain trust manager silently disables hostname verification
  • MQTT: Reject malformed no-payload packets with non-zero Remaining Length
  • HAProxy: Reject HAProxyMessages with malformated TLV and not leak memory
  • SSL: Use sane defaults as limits for the client hello length and timeout
  • DNS: Only cache CNAME if part of the queried domain
  • HTTP/2: Enforce max concurrent streams for misbehaving clients
  • Dns: Insufficient Bailiwick Validation for NS Records
  • HTTP2: DelegatingDecompressorFrameListener must release memory in all cases
  • Pass maxAllocation to Brotli and Zstd decoders
  • HTTP/2: Treat clients MAX_HEADER_LIST_SIZE as advisory
  • Add maxWindowLog parameter to ZstdDecoder to bound memory allocation
  • HAProxy: Fix ByteBuf leak when parsing nested SSL TLVs
  • Epoll / Kqueue: Correctly handle receive of FD
  • SCTP: Limit the number of inflight incomplete SCTP messages and the number of fragments
  • Redis: Correctly release incomplete message on removal when using RedisArrayAggregator
  • Redis: Limit the maximum number of nested arrays
  • HTTP: Re-add constructor to HttpProxyHandler that was removed by mistake
  • Marshalling: Explicit document security requirements
  • Pin HTTP/RTSP version + method normalization to Locale.US
  • Adaptive: Fix concurrency issue in adaptive allocator
  • Pin multipart Content-Type / Content-Transfer-Encoding case folding to Locale.US
  • Remove dead native declarations
  • Avoid re-parsing openssl key material with non-cached provider
  • IpFilter: Fix ClassCastException caused by IpSubnetFilter if only ipv6 rules are configured but remote peer is using ipv4
  • Resolve all localhost addresses without querying DNS servers
  • HTTP2: Use 100 as default max concurrent streams setting
  • Route synchronous onLookupComplete exceptions via fireExceptionCaught
  • Fix MQTT decoder size check after variable header replay
References

Affected packages

SUSE:Linux Enterprise High Performance Computing 15 SP4-ESPOS
netty-tcnative

Package

Name
netty-tcnative
Purl
pkg:rpm/suse/netty-tcnative&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-ESPOS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.0.79-150200.3.45.1

Ecosystem specific

{
    "binaries":  [
        {
            "netty-tcnative":  "2.0.79-150200.3.45.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2802-1.json"
SUSE:Linux Enterprise High Performance Computing 15 SP4-LTSS
netty-tcnative

Package

Name
netty-tcnative
Purl
pkg:rpm/suse/netty-tcnative&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.0.79-150200.3.45.1

Ecosystem specific

{
    "binaries":  [
        {
            "netty-tcnative":  "2.0.79-150200.3.45.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2802-1.json"
SUSE:Linux Enterprise High Performance Computing 15 SP5-ESPOS
netty-tcnative

Package

Name
netty-tcnative
Purl
pkg:rpm/suse/netty-tcnative&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-ESPOS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.0.79-150200.3.45.1

Ecosystem specific

{
    "binaries":  [
        {
            "netty-tcnative":  "2.0.79-150200.3.45.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2802-1.json"
SUSE:Linux Enterprise High Performance Computing 15 SP5-LTSS
netty-tcnative

Package

Name
netty-tcnative
Purl
pkg:rpm/suse/netty-tcnative&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.0.79-150200.3.45.1

Ecosystem specific

{
    "binaries":  [
        {
            "netty-tcnative":  "2.0.79-150200.3.45.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2802-1.json"
SUSE:Linux Enterprise Module for Development Tools 15 SP7
netty-tcnative

Package

Name
netty-tcnative
Purl
pkg:rpm/suse/netty-tcnative&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Development%20Tools%2015%20SP7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.0.79-150200.3.45.1

Ecosystem specific

{
    "binaries":  [
        {
            "netty-tcnative":  "2.0.79-150200.3.45.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2802-1.json"
SUSE:Linux Enterprise Module for Package Hub 15 SP7
netty

Package

Name
netty
Purl
pkg:rpm/suse/netty&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
4.1.135-150200.4.50.1

Ecosystem specific

{
    "binaries":  [
        {
            "netty":  "4.1.135-150200.4.50.1",
            "netty-javadoc":  "4.1.135-150200.4.50.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2802-1.json"
SUSE:Linux Enterprise Server 15 SP4-LTSS
netty-tcnative

Package

Name
netty-tcnative
Purl
pkg:rpm/suse/netty-tcnative&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP4-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.0.79-150200.3.45.1

Ecosystem specific

{
    "binaries":  [
        {
            "netty-tcnative":  "2.0.79-150200.3.45.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2802-1.json"
SUSE:Linux Enterprise Server 15 SP5-LTSS
netty-tcnative

Package

Name
netty-tcnative
Purl
pkg:rpm/suse/netty-tcnative&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP5-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.0.79-150200.3.45.1

Ecosystem specific

{
    "binaries":  [
        {
            "netty-tcnative":  "2.0.79-150200.3.45.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2802-1.json"
SUSE:Linux Enterprise Server 15 SP6-LTSS
netty-tcnative

Package

Name
netty-tcnative
Purl
pkg:rpm/suse/netty-tcnative&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP6-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.0.79-150200.3.45.1

Ecosystem specific

{
    "binaries":  [
        {
            "netty-tcnative":  "2.0.79-150200.3.45.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2802-1.json"
SUSE:Linux Enterprise Server for SAP Applications 15 SP4
netty-tcnative

Package

Name
netty-tcnative
Purl
pkg:rpm/suse/netty-tcnative&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.0.79-150200.3.45.1

Ecosystem specific

{
    "binaries":  [
        {
            "netty-tcnative":  "2.0.79-150200.3.45.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2802-1.json"
SUSE:Linux Enterprise Server for SAP Applications 15 SP5
netty-tcnative

Package

Name
netty-tcnative
Purl
pkg:rpm/suse/netty-tcnative&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.0.79-150200.3.45.1

Ecosystem specific

{
    "binaries":  [
        {
            "netty-tcnative":  "2.0.79-150200.3.45.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2802-1.json"
SUSE:Linux Enterprise Server for SAP Applications 15 SP6
netty-tcnative

Package

Name
netty-tcnative
Purl
pkg:rpm/suse/netty-tcnative&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.0.79-150200.3.45.1

Ecosystem specific

{
    "binaries":  [
        {
            "netty-tcnative":  "2.0.79-150200.3.45.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2802-1.json"