VDB
Sign up
HIGH7.5

GHSA-4g8c-wm8x-jfhw

SslHandler doesn't correctly validate packets which can lead to native crash when using native SSLEngine

Quick fix

GHSA-4g8c-wm8x-jfhw — io.netty:netty-handler: upgrade to the fixed version with the command below.

# pom.xml: bump <version>4.1.118.Final</version> for io.netty:netty-handler

Details

### Impact When a special crafted packet is received via SslHandler it doesn't correctly handle validation of such a packet in all cases which can lead to a native crash.

### Workarounds As workaround its possible to either disable the usage of the native SSLEngine or changing the code from:

``` SslContext context = ...; SslHandler handler = context.newHandler(....); ```

to:

``` SslContext context = ...; SSLEngine engine = context.newEngine(....); SslHandler handler = new SslHandler(engine, ....); ```

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/io.netty:netty-handler
Introduced in: 4.1.91.FinalFixed in: 4.1.118.Final
Fix# pom.xml: bump <version>4.1.118.Final</version> for io.netty:netty-handler

References