FlawAtlas
Search the atlas
SUSE-SU-2024:4407-1 Not scored

Security update for aalto-xml, flatten-maven-plugin, jctools, moditect, netty, netty-tcnative

This update for aalto-xml, flatten-maven-plugin, jctools, moditect, netty, netty-tcnative fixes the following issues: - CVE-2024-47535: Fixed unsafe reading of large environment files when Netty is loaded by a java application can lead to a crash due to the JVM memory limit being exceeded in netty (bsc#1233297) Other fixes: - Upgraded netty to upstream version 4.1.115 - Upgraded netty-tcnative to version 2.0.69 Final - Updated jctools to version 4.0.5 - Updated aalto-xml to version 1.3.3 - Updated moditect to version 1.2.2 - Updated flatten-maven-plugin to version 1.6.0

Exploit probability Not scored
Published December 23, 2024
Required by Not available
Last source change February 4, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Linux Enterprise Module for Development Tools 15 SP5 netty-tcnative
SUSE:Linux Enterprise Module for Development Tools 15 SP6 netty-tcnative
SUSE:Linux Enterprise Module for Package Hub 15 SP5 jctools
SUSE:Linux Enterprise Module for Package Hub 15 SP5 netty
SUSE:Linux Enterprise Module for Package Hub 15 SP6 jctools
SUSE:Linux Enterprise Module for Package Hub 15 SP6 netty
openSUSE:Leap 15.5 jctools
openSUSE:Leap 15.5 netty
openSUSE:Leap 15.5 netty-tcnative
openSUSE:Leap 15.6 jctools
openSUSE:Leap 15.6 netty
openSUSE:Leap 15.6 netty-tcnative

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2024:4407-1

This update for aalto-xml, flatten-maven-plugin, jctools, moditect, netty, netty-tcnative fixes the following issues: - CVE-2024-47535: Fixed unsafe reading of large environment files when Netty is loaded by a java application can lead to a crash due to the JVM memory limit being exceeded in netty (bsc#1233297) Other fixes: - Upgraded netty to upstream version 4.1.115 - Upgraded netty-tcnative to version 2.0.69 Final - Updated jctools to version 4.0.5 - Updated aalto-xml to version 1.3.3 - Updated moditect to version 1.2.2 - Updated flatten-maven-plugin to version 1.6.0

View original source

05 / REFERENCES

Further evidence