Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-59901

Опубликовано: 09 июл. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

A flaw was found in the netty-codec-compression component of Netty. This vulnerability, caused by a logic error in the bzip2 decoder, allows a remote attacker to send specially crafted bzip2-compressed data. Processing this malformed data can trigger an infinite loop, causing the decoder thread to consume excessive CPU resources. This leads to a denial of service (DoS), requiring manual intervention to restore service.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat build of Apache Camel - HawtIO 4netty-codec-compressionAffected
Red Hat Data Grid 8netty-codec-compressionAffected
Red Hat JBoss Enterprise Application Platform Expansion Packnetty-codec-compressionNot affected
Red Hat OpenShift Dev Spacesdevspaces/multicluster-redirector-rhel9Affected
Red Hat OpenShift Dev Spacesdevspaces/server-rhel9Affected
streams for Apache Kafka 3netty-codec-compressionAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-835
https://bugzilla.redhat.com/show_bug.cgi?id=2507481io.netty/netty-codec-compression: Netty: Infinite loop in netty-codec-compression (bzip2)

EPSS

Процентиль: 16%
0.00246
Низкий

7.5 High

CVSS3

Связанные уязвимости

ubuntu
5 дней назад

(Netty is an asynchronous, event-driven network application framework. ...)

nvd
5 дней назад

Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, the `Bzip2Decoder` handler in Netty's compression codec pipeline is vulnerable to a denial-of-service attack through a malformed bzip2 stream that permanently captures the event-loop thread in an infinite loop. The vulnerability exists in the run-length encoding (RLE) state machine within [`Bzip2BlockDecompressor.read()`]. This issue has been fixed in versions 4.1.136.Final and 4.2.16.Final.

debian
5 дней назад

Netty is an asynchronous, event-driven network application framework. ...

github
12 дней назад

Netty: [Bzip2Decoder] Infinite Loop in RLE State Machine Leads to Event-Loop Thread Hang

EPSS

Процентиль: 16%
0.00246
Низкий

7.5 High

CVSS3