REDHAT-BUG-2488053: High severity Netty netty-codec-redis vulnerability
Netty is a network application framework for development of protocol servers and clients. In netty-codec-redis prior to versions 4.1.135.Final and 4.2.15.Final, an attacker can cause DoS by sending crafted Redis payloads across multiple connections without \r\n. This exhausts the server's direct memory pool (OutOfDirectMemoryError), preventing legitimate connections from being processed. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
netty-codec-redisto a version that resolves this vulnerability.Fixed in 4.1.135.Final - Upgrade
Upgrade
netty-codec-redisto a version that resolves this vulnerability.Fixed in 4.2.15.Final
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2488053?
The severity of REDHAT-BUG-2488053 is classified as high with a score of 7.
What are the affected versions in REDHAT-BUG-2488053?
The affected versions in REDHAT-BUG-2488053 are netty-codec-redis prior to 4.1.135.Final and 4.2.15.Final.
How do I fix REDHAT-BUG-2488053?
To fix REDHAT-BUG-2488053, upgrade netty-codec-redis to version 4.1.135.Final or 4.2.15.Final or later.
What type of attack is associated with REDHAT-BUG-2488053?
REDHAT-BUG-2488053 is associated with a Denial of Service (DoS) attack.
What can an attacker exploit in REDHAT-BUG-2488053?
An attacker can exploit REDHAT-BUG-2488053 by sending crafted Redis payloads across multiple connections to exhaust the server's resources.