REDHAT-BUG-2452456: High severity Netty Netty vulnerability
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, a remote user can trigger a Denial of Service (DoS) against a Netty HTTP/2 server by sending a flood of CONTINUATION frames. The server's lack of a limit on the number of CONTINUATION frames, combined with a bypass of existing size-based mitigations using zero-byte frames, allows an user to cause excessive CPU consumption with minimal bandwidth, rendering the server unresponsive. Versions 4.1.132.Final and 4.2.10.Final fix the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Netty HTTP/2 serverto a version that resolves this vulnerability.Fixed in 4.1.132.Final - Upgrade
Upgrade
Netty HTTP/2 serverto a version that resolves this vulnerability.Fixed in 4.2.10.Final
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2452456?
The severity of REDHAT-BUG-2452456 is considered high due to the potential for Denial of Service (DoS) attacks.
How do I fix REDHAT-BUG-2452456?
To fix REDHAT-BUG-2452456, upgrade Netty to versions 4.1.132.Final or 4.2.10.Final or later.
What types of systems are impacted by REDHAT-BUG-2452456?
Systems running Netty versions prior to 4.1.132.Final and 4.2.10.Final are impacted by REDHAT-BUG-2452456.
Can REDHAT-BUG-2452456 lead to data breaches?
REDHAT-BUG-2452456 primarily enables Denial of Service attacks, rather than direct data breaches.
Is there a workaround for REDHAT-BUG-2452456?
There are no known workarounds for REDHAT-BUG-2452456; upgrading to a fixed version is necessary.