Описание
Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, netty_unix_socket_recvFd sets msg_control to char control[CMSG_SPACE(sizeof(int))] (line 940) — 24 bytes on 64-bit Linux. A peer-sent SCM_RIGHTS cmsg carrying two ints has cmsg_len = CMSG_LEN(8) = 24, which fits exactly with no MSG_CTRUNC, so the kernel installs both fds in the receiving process. The subsequent check cmsg->cmsg_len == CMSG_LEN(sizeof(int)) (line 972, expected 20) fails, the branch that would read the fd is skipped, and neither installed fd is closed. The for(;;) loop calls recvmsg again (non-blocking → EAGAIN → Java maps to 0 → read loop exits normally), leaving two leaked fds per message. There is no MSG_CTRUNC handling. Reachable via Epoll/KQueue DomainSocketChannel when the application opts into DomainSocketReadMode.FILE_DESCRIPTORS (non-default). Versions 4.1.135.Final and 4.2.15.Final patch the issue.
A flaw was found in Netty, a network application framework. A local attacker could exploit a vulnerability in the netty_unix_socket_recvFd function when handling SCM_RIGHTS messages in Epoll or KQueue DomainSocketChannel with DomainSocketReadMode.FILE_DESCRIPTORS enabled. Incorrect handling of file descriptors could lead to a resource leak, resulting in a Denial of Service (DoS) due to exhaustion of available file descriptors.
Отчет
This Moderate impact flaw in Netty can lead to a denial of service due to file descriptor exhaustion. The vulnerability requires a local attacker and is only exploitable when applications explicitly enable DomainSocketReadMode.FILE_DESCRIPTORS in Epoll or KQueue DomainSocketChannel, which is not a default configuration in Red Hat products. This significantly reduces the attack surface to specific, custom deployments.
Меры по смягчению последствий
To mitigate this issue, ensure that DomainSocketReadMode.FILE_DESCRIPTORS is not enabled in applications utilizing Netty's Epoll or KQueue DomainSocketChannel. This feature is not enabled by default, and disabling it prevents the file descriptor leak that could lead to a Denial of Service.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Cryostat 4 | netty-transport-native-epoll | Fix deferred | ||
| Red Hat AMQ Broker 7 | netty-transport-native-epoll | Fix deferred | ||
| Red Hat AMQ Broker 7 | netty-transport-native-kqueue | Fix deferred | ||
| Red Hat AMQ Clients | netty-transport-native-epoll | Fix deferred | ||
| Red Hat AMQ Clients | netty-transport-native-kqueue | Fix deferred | ||
| Red Hat build of Apache Camel 4 for Quarkus 3 | netty-transport-native-epoll | Fix deferred | ||
| Red Hat build of Apache Camel 4 for Quarkus 3 | netty-transport-native-kqueue | Fix deferred | ||
| Red Hat build of Apache Camel for Spring Boot 4 | netty-transport-native-epoll | Fix deferred | ||
| Red Hat build of Apache Camel for Spring Boot 4 | netty-transport-native-kqueue | Fix deferred | ||
| Red Hat build of Apache Camel - HawtIO 4 | netty-transport-native-epoll | Fix deferred |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
EPSS
4 Medium
CVSS3
Связанные уязвимости
Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, netty_unix_socket_recvFd sets msg_control to `char control[CMSG_SPACE(sizeof(int))]` (line 940) — 24 bytes on 64-bit Linux. A peer-sent SCM_RIGHTS cmsg carrying two ints has cmsg_len = CMSG_LEN(8) = 24, which fits exactly with no MSG_CTRUNC, so the kernel installs both fds in the receiving process. The subsequent check `cmsg->cmsg_len == CMSG_LEN(sizeof(int))` (line 972, expected 20) fails, the branch that would read the fd is skipped, and neither installed fd is closed. The for(;;) loop calls recvmsg again (non-blocking → EAGAIN → Java maps to 0 → read loop exits normally), leaving two leaked fds per message. There is no MSG_CTRUNC handling. Reachable via Epoll/KQueue DomainSocketChannel when the application opts into DomainSocketReadMode.FILE_DESCRIPTORS (non-default). Versions 4.1.135.Final and 4.2.15.Final patch the issue.
Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, netty_unix_socket_recvFd sets msg_control to `char control[CMSG_SPACE(sizeof(int))]` (line 940) — 24 bytes on 64-bit Linux. A peer-sent SCM_RIGHTS cmsg carrying two ints has cmsg_len = CMSG_LEN(8) = 24, which fits exactly with no MSG_CTRUNC, so the kernel installs both fds in the receiving process. The subsequent check `cmsg->cmsg_len == CMSG_LEN(sizeof(int))` (line 972, expected 20) fails, the branch that would read the fd is skipped, and neither installed fd is closed. The for(;;) loop calls recvmsg again (non-blocking → EAGAIN → Java maps to 0 → read loop exits normally), leaving two leaked fds per message. There is no MSG_CTRUNC handling. Reachable via Epoll/KQueue DomainSocketChannel when the application opts into DomainSocketReadMode.FILE_DESCRIPTORS (non-default). Versions 4.1.135.Final and 4.2.15.Final patch the issue.
Netty is a network application framework for development of protocol s ...
Netty: Unix-socket fd receive leaks descriptors when peer sends two at once
EPSS
4 Medium
CVSS3