Описание
A flaw was found in the netty-codec-compression component of Netty. This vulnerability, caused by a logic error in the bzip2 decoder, allows a remote attacker to send specially crafted bzip2-compressed data. Processing this malformed data can trigger an infinite loop, causing the decoder thread to consume excessive CPU resources. This leads to a denial of service (DoS), requiring manual intervention to restore service.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat build of Apache Camel - HawtIO 4 | netty-codec-compression | Affected | ||
| Red Hat Data Grid 8 | netty-codec-compression | Affected | ||
| Red Hat JBoss Enterprise Application Platform Expansion Pack | netty-codec-compression | Not affected | ||
| Red Hat OpenShift Dev Spaces | devspaces/multicluster-redirector-rhel9 | Affected | ||
| Red Hat OpenShift Dev Spaces | devspaces/server-rhel9 | Affected | ||
| streams for Apache Kafka 3 | netty-codec-compression | Affected |
Показывать по
Дополнительная информация
Статус:
EPSS
7.5 High
CVSS3
Связанные уязвимости
(Netty is an asynchronous, event-driven network application framework. ...)
Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, the `Bzip2Decoder` handler in Netty's compression codec pipeline is vulnerable to a denial-of-service attack through a malformed bzip2 stream that permanently captures the event-loop thread in an infinite loop. The vulnerability exists in the run-length encoding (RLE) state machine within [`Bzip2BlockDecompressor.read()`]. This issue has been fixed in versions 4.1.136.Final and 4.2.16.Final.
Netty is an asynchronous, event-driven network application framework. ...
Netty: [Bzip2Decoder] Infinite Loop in RLE State Machine Leads to Event-Loop Thread Hang
EPSS
7.5 High
CVSS3