Security update for netty
This update for netty fixes the following issues: - Updated to version 4.1.75: - CVE-2021-37136: Fixed an unrestricted decompressed data size in Bzip2Decoder (bsc#1190610). - CVE-2021-37137: Fixed an unrestricted chunk length in SnappyFrameDecoder, which might lead to excessive memory usage (#bsc#1190613). - CVE-2021-43797: Fixed a potential HTTP request smuggling issue due to insufficient validation against control characters (bsc#1193672). - CVE-2021-21290: Fixed an information disclosure via the local system temporary directory (bsc#1182103).
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for netty fixes the following issues: - Updated to version 4.1.75: - CVE-2021-37136: Fixed an unrestricted decompressed data size in Bzip2Decoder (bsc#1190610). - CVE-2021-37137: Fixed an unrestricted chunk length in SnappyFrameDecoder, which might lead to excessive memory usage (#bsc#1190613). - CVE-2021-43797: Fixed a potential HTTP request smuggling issue due to insufficient validation against control characters (bsc#1193672). - CVE-2021-21290: Fixed an information disclosure via the local system temporary directory (bsc#1182103).
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1182103
- https://bugzilla.suse.com/1183262
- https://bugzilla.suse.com/1190610
- https://bugzilla.suse.com/1190613
- https://bugzilla.suse.com/1193672
- https://www.suse.com/security/cve/CVE-2021-21290
- https://www.suse.com/security/cve/CVE-2021-21295
- https://www.suse.com/security/cve/CVE-2021-37136
- https://www.suse.com/security/cve/CVE-2021-37137
- https://www.suse.com/security/cve/CVE-2021-43797
- https://www.suse.com/support/update/announcement/2022/suse-su-20221271-1/