Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2025:4489-1

Опубликовано: 19 дек. 2025
Источник: suse-cvrf

Описание

Security update for netty

This update for netty fixes the following issues:

Update to upstream version 4.1.130.

Security issues fixed:

  • CVE-2025-67735: lack of URI sanitization in HttpRequestEncoder allows for CRLF injection through a request URI and can lead to request smuggling (bsc#1255048).

Other updates and bugfixes:

  • Version 4.1.130:

    • Update lz4-java version to 1.10.1
    • Close Channel and fail bootstrap when setting a ChannelOption causes an error
    • Discard the following HttpContent for preflight request
    • Fix race condition in NonStickyEventExecutorGroup causing incorrect inEventLoop() results
    • Fix Zstd compression for large data
    • Fix ZstdEncoder not producing data when source is smaller than block
    • Make big endian ASCII hashcode consistent with little endian
    • Fix reentrancy bug in ByteToMessageDecoder
    • Add 32k and 64k size classes to adaptive allocator
    • Re-enable reflective field accesses in native images
    • Correct HTTP/2 padding length check
    • Fix HTTP startline validation
    • Fix MpscIntQueue bug
  • Build against the org.jboss:jdk-misc artifact that is implementing the sun.misc classes removed in Java 25

Список пакетов

Container suse/manager/5.0/x86_64/server:latest
netty-4.1.130-150200.4.40.1
Container suse/multi-linux-manager/5.1/x86_64/server:latest
netty-4.1.130-150200.4.40.1
Image server-image
netty-4.1.130-150200.4.40.1
SUSE Linux Enterprise Module for Package Hub 15 SP7
netty-4.1.130-150200.4.40.1
netty-javadoc-4.1.130-150200.4.40.1
openSUSE Leap 15.6
netty-4.1.130-150200.4.40.1
netty-javadoc-4.1.130-150200.4.40.1

Описание

Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.129.Final and 4.2.8.Final, the `io.netty.handler.codec.http.HttpRequestEncoder` has a CRLF injection with the request URI when constructing a request. This leads to request smuggling when `HttpRequestEncoder` is used without proper sanitization of the URI. Any application / framework using `HttpRequestEncoder` can be subject to be abused to perform request smuggling using CRLF injection. Versions 4.1.129.Final and 4.2.8.Final fix the issue.


Затронутые продукты
Container suse/manager/5.0/x86_64/server:latest:netty-4.1.130-150200.4.40.1
Container suse/multi-linux-manager/5.1/x86_64/server:latest:netty-4.1.130-150200.4.40.1
Image server-image:netty-4.1.130-150200.4.40.1
SUSE Linux Enterprise Module for Package Hub 15 SP7:netty-4.1.130-150200.4.40.1

Ссылки