GHSA-5xrh-qmmq-w6ch
Netty: SCTP reassembly nests buffers without bound
Quick fix
GHSA-5xrh-qmmq-w6ch — io.netty:netty-transport-sctp: upgrade to the fixed version with the command below.
# pom.xml: bump <version>4.2.15.Final</version> for io.netty:netty-transport-sctpDetails
For each non-complete SctpMessage fragment the handler does `fragments.put(streamId, Unpooled.wrappedBuffer(frag, byteBuf))`, wrapping the previous accumulator and the new slice into a *new* CompositeByteBuf every time. After N fragments the accumulator is an N-deep chain of composites, each holding references and component arrays; readableBytes()/getBytes() on the final buffer recurse N levels. There is no limit on N, on total bytes, or on the number of streamIdentifiers an attacker can open (each gets its own map entry). A peer that never sets the `complete` flag can grow this structure indefinitely from tiny 1-byte DATA chunks.
Are you affected?
Enter the version of the package you're using.
Affected packages
4.2.0.FinalFixed in: 4.2.15.Final# pom.xml: bump <version>4.2.15.Final</version> for io.netty:netty-transport-sctp0Fixed in: 4.1.135.Final# pom.xml: bump <version>4.1.135.Final</version> for io.netty:netty-transport-sctpReferences
- https://github.com/netty/netty/security/advisories/GHSA-5xrh-qmmq-w6ch[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2026-46340[ADVISORY]
- https://github.com/netty/netty[PACKAGE]
- https://github.com/netty/netty/releases/tag/netty-4.1.135.Final[WEB]
- https://github.com/netty/netty/releases/tag/netty-4.2.15.Final[WEB]