Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-45536

Опубликовано: 12 июн. 2026
Источник: redhat
CVSS3: 4
EPSS Низкий

Описание

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, netty_unix_socket_recvFd sets msg_control to char control[CMSG_SPACE(sizeof(int))] (line 940) — 24 bytes on 64-bit Linux. A peer-sent SCM_RIGHTS cmsg carrying two ints has cmsg_len = CMSG_LEN(8) = 24, which fits exactly with no MSG_CTRUNC, so the kernel installs both fds in the receiving process. The subsequent check cmsg->cmsg_len == CMSG_LEN(sizeof(int)) (line 972, expected 20) fails, the branch that would read the fd is skipped, and neither installed fd is closed. The for(;;) loop calls recvmsg again (non-blocking → EAGAIN → Java maps to 0 → read loop exits normally), leaving two leaked fds per message. There is no MSG_CTRUNC handling. Reachable via Epoll/KQueue DomainSocketChannel when the application opts into DomainSocketReadMode.FILE_DESCRIPTORS (non-default). Versions 4.1.135.Final and 4.2.15.Final patch the issue.

A flaw was found in Netty, a network application framework. A local attacker could exploit a vulnerability in the netty_unix_socket_recvFd function when handling SCM_RIGHTS messages in Epoll or KQueue DomainSocketChannel with DomainSocketReadMode.FILE_DESCRIPTORS enabled. Incorrect handling of file descriptors could lead to a resource leak, resulting in a Denial of Service (DoS) due to exhaustion of available file descriptors.

Отчет

This Moderate impact flaw in Netty can lead to a denial of service due to file descriptor exhaustion. The vulnerability requires a local attacker and is only exploitable when applications explicitly enable DomainSocketReadMode.FILE_DESCRIPTORS in Epoll or KQueue DomainSocketChannel, which is not a default configuration in Red Hat products. This significantly reduces the attack surface to specific, custom deployments.

Меры по смягчению последствий

To mitigate this issue, ensure that DomainSocketReadMode.FILE_DESCRIPTORS is not enabled in applications utilizing Netty's Epoll or KQueue DomainSocketChannel. This feature is not enabled by default, and disabling it prevents the file descriptor leak that could lead to a Denial of Service.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Cryostat 4netty-transport-native-epollFix deferred
Red Hat AMQ Broker 7netty-transport-native-epollFix deferred
Red Hat AMQ Broker 7netty-transport-native-kqueueFix deferred
Red Hat AMQ Clientsnetty-transport-native-epollFix deferred
Red Hat AMQ Clientsnetty-transport-native-kqueueFix deferred
Red Hat build of Apache Camel 4 for Quarkus 3netty-transport-native-epollFix deferred
Red Hat build of Apache Camel 4 for Quarkus 3netty-transport-native-kqueueFix deferred
Red Hat build of Apache Camel for Spring Boot 4netty-transport-native-epollFix deferred
Red Hat build of Apache Camel for Spring Boot 4netty-transport-native-kqueueFix deferred
Red Hat build of Apache Camel - HawtIO 4netty-transport-native-epollFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-167
https://bugzilla.redhat.com/show_bug.cgi?id=2488394netty-transport-native-epoll: netty-transport-native-kqueue: Netty: Denial of Service due to file descriptor leak in SCM_RIGHTS message handling

EPSS

Процентиль: 3%
0.00136
Низкий

4 Medium

CVSS3

Связанные уязвимости

CVSS3: 4
ubuntu
около 2 месяцев назад

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, netty_unix_socket_recvFd sets msg_control to `char control[CMSG_SPACE(sizeof(int))]` (line 940) — 24 bytes on 64-bit Linux. A peer-sent SCM_RIGHTS cmsg carrying two ints has cmsg_len = CMSG_LEN(8) = 24, which fits exactly with no MSG_CTRUNC, so the kernel installs both fds in the receiving process. The subsequent check `cmsg->cmsg_len == CMSG_LEN(sizeof(int))` (line 972, expected 20) fails, the branch that would read the fd is skipped, and neither installed fd is closed. The for(;;) loop calls recvmsg again (non-blocking → EAGAIN → Java maps to 0 → read loop exits normally), leaving two leaked fds per message. There is no MSG_CTRUNC handling. Reachable via Epoll/KQueue DomainSocketChannel when the application opts into DomainSocketReadMode.FILE_DESCRIPTORS (non-default). Versions 4.1.135.Final and 4.2.15.Final patch the issue.

CVSS3: 4
nvd
около 2 месяцев назад

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, netty_unix_socket_recvFd sets msg_control to `char control[CMSG_SPACE(sizeof(int))]` (line 940) — 24 bytes on 64-bit Linux. A peer-sent SCM_RIGHTS cmsg carrying two ints has cmsg_len = CMSG_LEN(8) = 24, which fits exactly with no MSG_CTRUNC, so the kernel installs both fds in the receiving process. The subsequent check `cmsg->cmsg_len == CMSG_LEN(sizeof(int))` (line 972, expected 20) fails, the branch that would read the fd is skipped, and neither installed fd is closed. The for(;;) loop calls recvmsg again (non-blocking → EAGAIN → Java maps to 0 → read loop exits normally), leaving two leaked fds per message. There is no MSG_CTRUNC handling. Reachable via Epoll/KQueue DomainSocketChannel when the application opts into DomainSocketReadMode.FILE_DESCRIPTORS (non-default). Versions 4.1.135.Final and 4.2.15.Final patch the issue.

CVSS3: 4
debian
около 2 месяцев назад

Netty is a network application framework for development of protocol s ...

CVSS3: 4
github
2 месяца назад

Netty: Unix-socket fd receive leaks descriptors when peer sends two at once

suse-cvrf
около 1 месяца назад

Security update for netty, netty-tcnative

EPSS

Процентиль: 3%
0.00136
Низкий

4 Medium

CVSS3

Уязвимость CVE-2026-45536