Описание
Netty is an asynchronous, event-driven network application framework. From 4.2.0.Final to 4.2.13.Final , Netty's epoll transport fails to detect and close TCP connections that receive a RST after being half-closed, leading to stale channels that are never cleaned up and, in some code paths, a 100% CPU busy-loop in the event loop thread. This vulnerability is fixed in 4.2.13.Final.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | vulnerable code not present |
| esm-apps-legacy/xenial | not-affected | vulnerable code not present |
| esm-apps/bionic | not-affected | vulnerable code not present |
| esm-apps/focal | not-affected | vulnerable code not present |
| esm-apps/jammy | not-affected | vulnerable code not present |
| esm-apps/noble | not-affected | vulnerable code not present |
| esm-apps/resolute | not-affected | vulnerable code not present |
| esm-infra-legacy/trusty | not-affected | vulnerable code not present |
| jammy | not-affected | vulnerable code not present |
| noble | not-affected | vulnerable code not present |
Показывать по
EPSS
7.5 High
CVSS3
Связанные уязвимости
Netty is an asynchronous, event-driven network application framework. From 4.2.0.Final to 4.2.13.Final , Netty's epoll transport fails to detect and close TCP connections that receive a RST after being half-closed, leading to stale channels that are never cleaned up and, in some code paths, a 100% CPU busy-loop in the event loop thread. This vulnerability is fixed in 4.2.13.Final.
Netty is an asynchronous, event-driven network application framework. ...
Netty epoll transport denial of service via RST on half-closed TCP connection
EPSS
7.5 High
CVSS3