SUSE-SU-2026:4391-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-20264391-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4391-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/SUSE-SU-2026:4391-1
Upstream
CVE (30)
Related
Published
2026-09-29T11:47:41Z
Modified
2026-09-30T12:00:04Z
Summary
Security update for netty, netty-tcnative
Details

This update for netty, netty-tcnative fixes the following issues:

  • CVE-2026-59902: Netty: Memory Exhaustion in SctpMessageCompletionHandler (bsc#1275501).
  • CVE-2026-59903: Netty Vulnerable to Cache Poisoning and Information Disclosure via CORS Vary Header Overwrite (bsc#1275500).
  • CVE-2026-62243: TLS hostname verification bypass in Netty OpenSSL client path (bsc#1276455).
  • CVE-2026-62380: null byte and CRLF injection in Socks4ClientEncoder and Socks5ClientEncoder (bsc#1276456).
  • CVE-2026-75595: fragmented TLS ClientHello causes fallback to default SslContext and allows for SNI routing and mTLS requirement bypass (bsc#1276420).
  • CVE-2026-75596: fragmented ClientHellorecords can trigger quadratic pre-handshake reassembly in default SNI parsing (bsc#1276421).
  • CVE-2026-76816: missing input validation in MqttEncoder allows for null-byte injection, topic hijacking, and ACL bypassing (bsc#1277243).
  • CVE-2026-89044: HTTP request smuggling in Netty via improper validation of final Transfer-Encoding coding (bsc#1280048).
  • CVE-2026-93488: Denial of Service via unbounded concurrent SPDY streams (bsc#1282084).
  • CVE-2026-93491: Denial of Service via unbounded HttpServerCodec HTTP/1.1 pipeline queue (bsc#1282085).
  • CVE-2026-93492: HTTP/2 HpackEncoder DoS with large table size (bsc#1282132).
  • CVE-2026-93493: missing nextUpdate field in OCSP responses leads to silent validation bypass (bsc#1281431).
  • CVE-2026-93494: ByteBuf Leak in StompSubframeDecoder When a Frame Body Is Never Terminated (bsc#1282506).
  • CVE-2026-93558: Unbounded Per-Connection Queue Growth in WebSocketServerExtensionHandler Leads to Denial of Service (bsc#1282140).
  • CVE-2026-93560: STOMP codec content-length long-to-int truncation causes infinite decode loop DoS (bsc#1282141).
  • CVE-2026-93562: Incomplete validation of malformed Transfer-Encoding allows HTTP request smuggling (bsc#1282362).
  • CVE-2026-93563: unbounded multi-line response accumulation in SmtpResponseDecoder leads to memory exhaustion and a DoS (bsc#1281432).
  • CVE-2026-93564: HAProxy PROXY-v2 nested-TLV grandchild ByteBuf reference-count leak (bsc#1282363).
  • CVE-2026-93565: RtspDecoder Method-Token Smuggling via Trailing Control Byte (bsc#1282364).
  • CVE-2026-93566: HTTP Request Smuggling due to control characters in the chunk-size line (bsc#1282366).
  • CVE-2026-93567: HTTP/1 authority-form CONNECT is translated to malformed HTTP/2 CONNECT with Host-controlled :authority (bsc#1282367).
  • CVE-2026-93568: HTTP/2 and HTTP/3 Extended CONNECT requests are downgraded as regular CONNECT requests (bsc#1282370).
  • CVE-2026-93569: HTTP/1 absolute-form Host mismatch is translated to HTTP/2 :authority, overriding the request-target authority (bsc#1282372).
  • CVE-2026-93572: multiplication of patched preallocation limits in RedisArrayAggregator nested RESP headers can lead to denial of service (bsc#1281433).
  • CVE-2026-93573: Incomplete validation of malformed Transfer-Encoding allows HTTP request smuggling (bsc#1282373).
  • CVE-2026-93574: HTTP request smuggling via post-digit whitespace in chunk-size parsing (bsc#1282374).
  • CVE-2026-93575: missing validations in the MqttDecoder can lead to excessive resource consumption and a DoS (bsc#1281434).
  • CVE-2026-93576: netty-codec-smtp -- SMTP command-name field is not CRLF-validated (bsc#1282507).
  • CVE-2026-93578: missing Extended Key Usage (EKU) check in OCSP client allows certificate revocation bypass (bsc#1281435).
  • CVE-2026-93579: HTTP/2 header field values are not validated by default (bsc#1282378).

Changes for netty:

  • Upgrade to upstream version 4.1.138

Changes for netty-tcnative:

  • Upgrade to version 2.0.84 Final
References

Affected packages

SUSE:Linux Enterprise High Performance Computing 15 SP4-ESPOS
netty-tcnative

Package

Name
netty-tcnative
Purl
pkg:rpm/suse/netty-tcnative&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-ESPOS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.0.84-150200.3.51.1

Ecosystem specific

{
    "binaries": [
        {
            "netty-tcnative": "2.0.84-150200.3.51.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4391-1.json"
SUSE:Linux Enterprise High Performance Computing 15 SP4-LTSS
netty-tcnative

Package

Name
netty-tcnative
Purl
pkg:rpm/suse/netty-tcnative&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.0.84-150200.3.51.1

Ecosystem specific

{
    "binaries": [
        {
            "netty-tcnative": "2.0.84-150200.3.51.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4391-1.json"
SUSE:Linux Enterprise High Performance Computing 15 SP5-ESPOS
netty-tcnative

Package

Name
netty-tcnative
Purl
pkg:rpm/suse/netty-tcnative&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-ESPOS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.0.84-150200.3.51.1

Ecosystem specific

{
    "binaries": [
        {
            "netty-tcnative": "2.0.84-150200.3.51.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4391-1.json"
SUSE:Linux Enterprise High Performance Computing 15 SP5-LTSS
netty-tcnative

Package

Name
netty-tcnative
Purl
pkg:rpm/suse/netty-tcnative&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.0.84-150200.3.51.1

Ecosystem specific

{
    "binaries": [
        {
            "netty-tcnative": "2.0.84-150200.3.51.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4391-1.json"
SUSE:Linux Enterprise Module for Development Tools 15 SP7
netty-tcnative

Package

Name
netty-tcnative
Purl
pkg:rpm/suse/netty-tcnative&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Development%20Tools%2015%20SP7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.0.84-150200.3.51.1

Ecosystem specific

{
    "binaries": [
        {
            "netty-tcnative": "2.0.84-150200.3.51.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4391-1.json"
SUSE:Linux Enterprise Module for Package Hub 15 SP7
netty

Package

Name
netty
Purl
pkg:rpm/suse/netty&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
4.1.138-150200.4.56.1

Ecosystem specific

{
    "binaries": [
        {
            "netty": "4.1.138-150200.4.56.1",
            "netty-javadoc": "4.1.138-150200.4.56.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4391-1.json"
SUSE:Linux Enterprise Server 15 SP4-LTSS
netty-tcnative

Package

Name
netty-tcnative
Purl
pkg:rpm/suse/netty-tcnative&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP4-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.0.84-150200.3.51.1

Ecosystem specific

{
    "binaries": [
        {
            "netty-tcnative": "2.0.84-150200.3.51.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4391-1.json"
SUSE:Linux Enterprise Server 15 SP5-LTSS
netty-tcnative

Package

Name
netty-tcnative
Purl
pkg:rpm/suse/netty-tcnative&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP5-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.0.84-150200.3.51.1

Ecosystem specific

{
    "binaries": [
        {
            "netty-tcnative": "2.0.84-150200.3.51.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4391-1.json"
SUSE:Linux Enterprise Server 15 SP6-LTSS
netty-tcnative

Package

Name
netty-tcnative
Purl
pkg:rpm/suse/netty-tcnative&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP6-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.0.84-150200.3.51.1

Ecosystem specific

{
    "binaries": [
        {
            "netty-tcnative": "2.0.84-150200.3.51.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4391-1.json"
SUSE:Linux Enterprise Server for SAP Applications 15 SP4
netty-tcnative

Package

Name
netty-tcnative
Purl
pkg:rpm/suse/netty-tcnative&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.0.84-150200.3.51.1

Ecosystem specific

{
    "binaries": [
        {
            "netty-tcnative": "2.0.84-150200.3.51.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4391-1.json"
SUSE:Linux Enterprise Server for SAP Applications 15 SP5
netty-tcnative

Package

Name
netty-tcnative
Purl
pkg:rpm/suse/netty-tcnative&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.0.84-150200.3.51.1

Ecosystem specific

{
    "binaries": [
        {
            "netty-tcnative": "2.0.84-150200.3.51.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4391-1.json"
SUSE:Linux Enterprise Server for SAP Applications 15 SP6
netty-tcnative

Package

Name
netty-tcnative
Purl
pkg:rpm/suse/netty-tcnative&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.0.84-150200.3.51.1

Ecosystem specific

{
    "binaries": [
        {
            "netty-tcnative": "2.0.84-150200.3.51.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4391-1.json"