Netty: SNI handler pre-allocates up to 16 MiB from nine attacker bytes
21Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 7.5epss 0.9%
probabilidad de explotación
0.9%top 45% de las CVE
explotación observada
noninguna fuente lo reporta
Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, SslClientHelloHandler.decode() reads the 24-bit TLS handshake length and, when the ClientHello does not fit in the first record, eagerly allocates `ctx.alloc().buffer(handshakeLength)` (line 161). The guard at line 140 is `handshakeLength > maxClientHelloLength && maxClientHelloLength != 0`, and the commonly-used SniHandler/AbstractSniHandler constructors (SniHandler(Mapping), SniHandler(AsyncMapping), AbstractSniHandler()) pass maxClientHelloLength=0 and handshakeTimeoutMillis=0, so the length guard is disabled and no timeout is scheduled. A 16 MiB request exceeds the default pooled chunk size and becomes a huge/unpooled allocation performed immediately. The buffer is retained in the handler until the channel closes. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Productos afectados
netty · nettyReferencias
https://access.redhat.com/errata/RHSA-2026:26017https://access.redhat.com/errata/RHSA-2026:26018https://access.redhat.com/errata/RHSA-2026:26586https://access.redhat.com/errata/RHSA-2026:28573https://access.redhat.com/errata/RHSA-2026:34608https://access.redhat.com/errata/RHSA-2026:37390https://access.redhat.com/errata/RHSA-2026:41951https://access.redhat.com/errata/RHSA-2026:48151https://access.redhat.com/errata/RHSA-2026:49700https://access.redhat.com/errata/RHSA-2026:49701https://access.redhat.com/errata/RHSA-2026:53644https://access.redhat.com/errata/RHSA-2026:53806