CVE-2022-41881
published 2022-12-12CVE-2022-41881: Netty project is an event-driven asynchronous network application framework. In versions prior to 4.1.86.Final, a StackOverflowError can be raised when parsing…
PriorityP340high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.47%
70.6th percentile
Netty project is an event-driven asynchronous network application framework. In versions prior to 4.1.86.Final, a StackOverflowError can be raised when parsing a malformed crafted message due to an infinite recursion. This issue is patched in version 4.1.86.Final. There is no workaround, except using a custom HaProxyMessageDecoder.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | netty | < netty 1:4.1.48-6 (bookworm) | netty 1:4.1.48-6 (bookworm) |
| netty | netty | < 4.1.86.Final | 4.1.86.Final |
| netty | netty | < 4.1.86 | 4.1.86 |
| netty | netty | >= 0 < 1:4.1.48-4+deb11u1 | 1:4.1.48-4+deb11u1 |
| netty | netty | >= 0 < 1:4.1.48-6 | 1:4.1.48-6 |
| netty | netty | >= 0 < 1:4.1.48-6 | 1:4.1.48-6 |
| netty | netty | >= 0 < 1:4.1.48-6 | 1:4.1.48-6 |
| netty | netty | >= 0 < 1:4.1.48-4+deb11u1build0.22.04.1 | 1:4.1.48-4+deb11u1build0.22.04.1 |
| netty | netty | >= 0 < 1:4.0.34-1ubuntu0.1~esm1 | 1:4.0.34-1ubuntu0.1~esm1 |
| netty | netty | >= 0 < 1:4.1.7-4ubuntu0.1+esm2 | 1:4.1.7-4ubuntu0.1+esm2 |
| netty | netty | >= 0 < 1:4.1.45-1ubuntu0.1~esm1 | 1:4.1.45-1ubuntu0.1~esm1 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_oracle7.5MEDIUM
vendor_ubuntu7.5HIGH
vendor_debian5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Database Server Risk Matrix: Fleet Patching and Provisioning (Netty) — CVE-2022-41881
vendor_oracle·2024-07-15·CVSS 7.5
CVE-2022-41881 [MEDIUM] Oracle Oracle Database Server Risk Matrix: Fleet Patching and Provisioning (Netty) — CVE-2022-41881
Oracle Oracle Database Server Risk Matrix: Fleet Patching and Provisioning (Netty) vulnerability
CVE: CVE-2022-41881
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2024 (JUL 2024)
Oracle
Oracle Oracle Financial Services Applications Risk Matrix: Security (Netty) — CVE-2022-41881
vendor_oracle·2023-10-15·CVSS 7.5
CVE-2022-41881 [MEDIUM] Oracle Oracle Financial Services Applications Risk Matrix: Security (Netty) — CVE-2022-41881
Oracle Oracle Financial Services Applications Risk Matrix: Security (Netty) vulnerability
CVE: CVE-2022-41881
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2023 (OCT 2023)
Oracle
Oracle Oracle Commerce Risk Matrix: Experience Manager (Netty) — CVE-2022-41881
vendor_oracle·2023-07-15·CVSS 7.5
CVE-2022-41881 [MEDIUM] Oracle Oracle Commerce Risk Matrix: Experience Manager (Netty) — CVE-2022-41881
Oracle Oracle Commerce Risk Matrix: Experience Manager (Netty) vulnerability
CVE: CVE-2022-41881
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2023 (JUL 2023)
Ubuntu
Netty vulnerabilities
vendor_ubuntu·2023-04-28·CVSS 7.5
CVE-2021-21295 [HIGH] Netty vulnerabilities
Title: Netty vulnerabilities
Summary: Several security issues were fixed in Netty.
It was discovered that Netty's Zlib decoders did not limit memory
allocations. A remote attacker could possibly use this issue to cause
Netty to exhaust memory via malicious input, leading to a denial of
service. This issue only affected Ubuntu 16.04 ESM and Ubuntu 20.04 ESM.
(CVE-2020-11612)
It was discovered that Netty created temporary files with excessive
permissions. A local attacker could possibly use this issue to expose
sensitive information. This issue only affected Ubuntu 16.04 ESM, Ubuntu
18.04 ESM, and Ubuntu 20.04 ESM. (CVE-2021-21290)
It was discovered that Netty did not properly validate content-length
headers. A remote attacker could possibly use this issue to smuggle
requests. This issue
Oracle
Oracle Oracle Communications Risk Matrix: Policy (Netty) — CVE-2022-41881
vendor_oracle·2023-04-15·CVSS 7.5
CVE-2022-41881 [MEDIUM] Oracle Oracle Communications Risk Matrix: Policy (Netty) — CVE-2022-41881
Oracle Oracle Communications Risk Matrix: Policy (Netty) vulnerability
CVE: CVE-2022-41881
CVSS: 7.5
Protocol: HTTPS
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2023 (APR 2023)
Oracle
Oracle Oracle Communications Risk Matrix: Configuration (Netty) — CVE-2022-41881
vendor_oracle·2023-01-15·CVSS 7.5
CVE-2022-41881 [MEDIUM] Oracle Oracle Communications Risk Matrix: Configuration (Netty) — CVE-2022-41881
Oracle Oracle Communications Risk Matrix: Configuration (Netty) vulnerability
CVE: CVE-2022-41881
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2023 (JAN 2023)
Red Hat
codec-haproxy: HAProxyMessageDecoder Stack Exhaustion DoS
vendor_redhat·2022-12-12·CVSS 5.3
CVE-2022-41881 [MEDIUM] CWE-674 codec-haproxy: HAProxyMessageDecoder Stack Exhaustion DoS
codec-haproxy: HAProxyMessageDecoder Stack Exhaustion DoS
Netty project is an event-driven asynchronous network application framework. In versions prior to 4.1.86.Final, a StackOverflowError can be raised when parsing a malformed crafted message due to an infinite recursion. This issue is patched in version 4.1.86.Final. There is no workaround, except using a custom HaProxyMessageDecoder.
A flaw was found in codec-haproxy from the Netty project. This flaw allows an attacker to build a malformed crafted message and cause infinite recursion, causing stack exhaustion and leading to a denial of service (DoS).
Package: codec-haproxy (A-MQ Clients 2) - Will not fix
Package: openshift-logging/elasticsearch6-rhel8 (Logging Subsystem for Red Hat OpenShift) - Not affected
Package: io.netty-nett
Debian
CVE-2022-41881: netty - Netty project is an event-driven asynchronous network application framework. In ...
vendor_debian·2022·CVSS 5.3
CVE-2022-41881 [MEDIUM] CVE-2022-41881: netty - Netty project is an event-driven asynchronous network application framework. In ...
Netty project is an event-driven asynchronous network application framework. In versions prior to 4.1.86.Final, a StackOverflowError can be raised when parsing a malformed crafted message due to an infinite recursion. This issue is patched in version 4.1.86.Final. There is no workaround, except using a custom HaProxyMessageDecoder.
Scope: local
bookworm: resolved (fixed in 1:4.1.48-6)
bullseye: resolved (fixed in 1:4.1.48-4+deb11u1)
forky: resolved (fixed in 1:4.1.48-6)
sid: resolved (fixed in 1:4.1.48-6)
trixie: resolved (fixed in 1:4.1.48-6)
OSV
netty vulnerabilities
osv·2023-04-28·CVSS 7.5
CVE-2020-11612 [HIGH] netty vulnerabilities
netty vulnerabilities
It was discovered that Netty's Zlib decoders did not limit memory
allocations. A remote attacker could possibly use this issue to cause
Netty to exhaust memory via malicious input, leading to a denial of
service. This issue only affected Ubuntu 16.04 ESM and Ubuntu 20.04 ESM.
(CVE-2020-11612)
It was discovered that Netty created temporary files with excessive
permissions. A local attacker could possibly use this issue to expose
sensitive information. This issue only affected Ubuntu 16.04 ESM, Ubuntu
18.04 ESM, and Ubuntu 20.04 ESM. (CVE-2021-21290)
It was discovered that Netty did not properly validate content-length
headers. A remote attacker could possibly use this issue to smuggle
requests. This issue was only fixed in Ubuntu 20.04 ESM. (CVE-2021-21295,
CVE-2021
OSV
HAProxyMessageDecoder Stack Exhaustion DoS
osv·2022-12-12
CVE-2022-41881 [MEDIUM] HAProxyMessageDecoder Stack Exhaustion DoS
HAProxyMessageDecoder Stack Exhaustion DoS
### Impact
A StackOverflowError can be raised when parsing a malformed crafted message due to an infinite recursion.
### Patches
Users should upgrade to 4.1.86.Final.
### Workarounds
There is no workaround, except using a custom HaProxyMessageDecoder.
### References
When parsing a TLV with type = PP2_TYPE_SSL, the value can be again a TLV with type = PP2_TYPE_SSL and so on.
The only limitation of the recursion is that the TLV length cannot be bigger than 0xffff because it is encoded in an unsigned short type.
Providing a TLV with a nesting level that is large enough will lead to raising of a StackOverflowError.
The StackOverflowError will be caught if HAProxyMessageDecoder is used as part of Netty’s ChannelPipeline, but using it directly witho
GHSA
HAProxyMessageDecoder Stack Exhaustion DoS
ghsa·2022-12-12
CVE-2022-41881 [MEDIUM] CWE-674 HAProxyMessageDecoder Stack Exhaustion DoS
HAProxyMessageDecoder Stack Exhaustion DoS
### Impact
A StackOverflowError can be raised when parsing a malformed crafted message due to an infinite recursion.
### Patches
Users should upgrade to 4.1.86.Final.
### Workarounds
There is no workaround, except using a custom HaProxyMessageDecoder.
### References
When parsing a TLV with type = PP2_TYPE_SSL, the value can be again a TLV with type = PP2_TYPE_SSL and so on.
The only limitation of the recursion is that the TLV length cannot be bigger than 0xffff because it is encoded in an unsigned short type.
Providing a TLV with a nesting level that is large enough will lead to raising of a StackOverflowError.
The StackOverflowError will be caught if HAProxyMessageDecoder is used as part of Netty’s ChannelPipeline, but using it directly witho
OSV
CVE-2022-41881: Netty project is an event-driven asynchronous network application framework
osv·2022-12-12·CVSS 7.5
CVE-2022-41881 [HIGH] CVE-2022-41881: Netty project is an event-driven asynchronous network application framework
Netty project is an event-driven asynchronous network application framework. In versions prior to 4.1.86.Final, a StackOverflowError can be raised when parsing a malformed crafted message due to an infinite recursion. This issue is patched in version 4.1.86.Final. There is no workaround, except using a custom HaProxyMessageDecoder.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/netty/netty/security/advisories/GHSA-fx2c-96vj-985vhttps://lists.debian.org/debian-lts-announce/2023/01/msg00008.htmlhttps://security.netapp.com/advisory/ntap-20230113-0004/https://www.debian.org/security/2023/dsa-5316https://github.com/netty/netty/security/advisories/GHSA-fx2c-96vj-985vhttps://lists.debian.org/debian-lts-announce/2023/01/msg00008.htmlhttps://security.netapp.com/advisory/ntap-20230113-0004/https://www.debian.org/security/2023/dsa-5316
2022-12-12
Published