Ubuntu alert USN-8401-1 (netty)
| From: | noreply+usn-bot--- via ubuntu-security-announce <ubuntu-security-announce@lists.ubuntu.com> | |
| To: | ubuntu-security-announce@lists.ubuntu.com | |
| Subject: | [USN-8401-1] Netty vulnerabilities | |
| Date: | Mon, 08 Jun 2026 18:14:59 +0000 | |
| Message-ID: | <E1wWeV1-0006TK-CO@lists.ubuntu.com> | |
| Cc: | noreply+usn-bot@canonical.com |
========================================================================== Ubuntu Security Notice USN-8401-1 June 08, 2026 netty vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS - Ubuntu 14.04 LTS Summary: Several security issues were fixed in Netty. Software Description: - netty: event-driven asynchronous network application framework Details: It was discovered that Netty's HTTP proxy handler did not properly validate headers when constructing CONNECT requests. An attacker could possibly use this issue to inject arbitrary HTTP headers into CONNECT requests. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-42578) It was discovered that Netty's DNS codec did not properly enforce domain name constraints. An attacker could possibly use this issue to bypass domain name validation, or cause Netty to consume resources, leading to a denial of service. This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-42579) It was discovered that Netty did not correctly handle HTTP/1.0 requests containing both a Transfer-Encoding and Content-Length header. A remote attacker could possibly use this issue to perform HTTP request smuggling attacks. (CVE-2026-42581) Violeta Georgieva discovered that Netty incorrectly paired responses with requests when handling informational HTTP responses. A remote attacker could possibly use this issue to perform HTTP request smuggling attacks. (CVE-2026-42584) Violeta Georgieva discovered that Netty incorrectly parsed malformed Transfer-Encoding headers. A remote attacker could possibly use this issue to perform HTTP request smuggling attacks. (CVE-2026-42585) It was discovered that Netty's Redis encoder did not validate CRLF characters. An attacker could possibly use this issue to inject arbitrary Redis commands. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-42586) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS libnetty-java 1:4.1.48-16ubuntu0.1~esm2 Available with Ubuntu Pro Ubuntu 24.04 LTS libnetty-java 1:4.1.48-9ubuntu0.1+esm3 Available with Ubuntu Pro Ubuntu 22.04 LTS libnetty-java 1:4.1.48-4+deb11u2ubuntu0.1+esm3 Available with Ubuntu Pro Ubuntu 20.04 LTS libnetty-java 1:4.1.45-1ubuntu0.1~esm6 Available with Ubuntu Pro Ubuntu 18.04 LTS libnetty-java 1:4.1.7-4ubuntu0.1+esm6 Available with Ubuntu Pro Ubuntu 16.04 LTS libnetty-java 1:4.0.34-1ubuntu0.1~esm4 Available with Ubuntu Pro Ubuntu 14.04 LTS libnetty-java 1:3.2.6.Final-2+deb8u2ubuntu0.1~esm1 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8401-1 CVE-2026-42578, CVE-2026-42579, CVE-2026-42581, CVE-2026-42584, CVE-2026-42585, CVE-2026-42586
Attachment: signature.asc (type=application/pgp-signature)
-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+8neBLO2Hp/ppPlOcpJm3tlzhgEFAmonBdYACgkQcpJm3tlz hgFmPA//b++bS27tzaKRVrvgz3QPz7RxDZVy2eP2ofByR8FzcJX1CqxkLDGwl3Go 3a/WdBgn64UvjbCAXKASTB9HhJ9HM2f1m545of9rh2gZ0O+kKVUXGfDbsYc0xQbZ 1BhVEZPe11r4OwJH+i1DhQ5ggw5ogE3g+lThx0Gkrf9qkiGwVwTXSZmucdZE+NuR FX6W4tAsAGCzZWLN+pwhHCTjlGhSgjoAA0rlOm8a3ncCTsnltUOsGikulWkyGC+6 FNb4ylX2tdSDhwz75FddfcH7dsKbNtJVaRFNgyGLJYT4p12hcqiG1cO76c/IpTdS v3RtxdAPk8iFguP/FlaAKKt+yFOmfGCjk13yyz8e8LRdDv8L6//RyN9hGzvwSpC7 wP9m/SF9fyT87rgyvwkVFIJspvzAna4cALd1IBjJQE1SsCJtsufZ2cdRwcDt0CXf XkbaHkIcfx+ueSNiRUWqbZyLq7e2s/OlQ4bV5UZJEdLVse1rDC7KpK6stoSruxOP f29T9HRcZwe0TiKD95V3p8RV53/+l55lkgvfMgPGK7RrhYYnSWm7FrOfkyZBxkUh GYnTQCJxr3GYLUmswalhyH9r6gYUyW24tZoksBT7GBp5+eng81oEXAIT33HJ/vTe OxzhDB1x7vNkGY2RFUFwXrbDff1VH/BX3Fmrs81K8uFbmlC834k= =17d0 -----END PGP SIGNATURE-----
