PT-2020-5478 · Netty+4 · Netty+4

Published

2020-04-07

·

Updated

2024-06-15

·

CVE-2020-11612

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Netty versions 4.1.x through 4.1.45
Description The issue is related to the ZlibDecoders class in Netty, which allows for unbounded memory allocation while decoding a ZlibEncoded byte stream. This can be exploited by an attacker to impact the confidentiality, integrity, and availability of protected information by sending a large ZlibEncoded byte stream to the Netty server, forcing it to allocate all of its free memory to a single decoder.
Recommendations For Netty versions 4.1.x through 4.1.45, update to version 4.1.46 or later to resolve the issue. As a temporary workaround, consider restricting the size of incoming ZlibEncoded byte streams to prevent excessive memory allocation.

Exploit

Fix

Allocation of Resources Without Limits

Buffer Overflow

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-00773
CVE-2020-11612
DLA-2364-1
DSA-4885-1
GHSA-MM9X-G8PC-W292
OPENSUSE-SU-2024:11085-1
RHSA-2020:2605
RHSA-2020:3461
RHSA-2020:3462
RHSA-2020:3463
RHSA-2021:1313
SUSE-SU-2022:3617-1
SUSE-SU-2022:3760-1
SUSE-SU-2022:3793-1
USN-4600-2
USN-6049-1

Affected Products

Astra Linux
Linuxmint
Netty
Suse
Ubuntu