REDHAT-BUG-2488391: High severity Netty Netty vulnerability
Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, SslClientHelloHandler.decode() reads the 24-bit TLS handshake length and, when the ClientHello does not fit in the first record, eagerly allocates ctx.alloc().buffer(handshakeLength) (line 161). The guard at line 140 is handshakeLength > maxClientHelloLength && maxClientHelloLength != 0, and the commonly-used SniHandler/AbstractSniHandler constructors (SniHandler(Mapping), SniHandler(AsyncMapping), AbstractSniHandler()) pass maxClientHelloLength=0 and handshakeTimeoutMillis=0, so the length guard is disabled and no timeout is scheduled. A 16 MiB request exceeds the default pooled chunk size and becomes a huge/unpooled allocation performed immediately. The buffer is retained in the handler until the channel closes. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Nettyto a version that resolves this vulnerability.Fixed in 4.1.135.Final - Upgrade
Upgrade
Nettyto a version that resolves this vulnerability.Fixed in 4.2.15.Final
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2488391?
The severity of REDHAT-BUG-2488391 is rated high with a score of 7.
How do I fix REDHAT-BUG-2488391?
To fix REDHAT-BUG-2488391, upgrade Netty to versions 4.1.135.Final or 4.2.15.Final or later.
What are the potential risks associated with REDHAT-BUG-2488391?
The risks associated with REDHAT-BUG-2488391 include potential vulnerabilities in the handling of TLS handshake lengths, which may lead to security issues.
Which software is affected by REDHAT-BUG-2488391?
The software affected by REDHAT-BUG-2488391 is the Netty framework.
When was REDHAT-BUG-2488391 published?
REDHAT-BUG-2488391 was published on June 12, 2026.