Bugzilla – Bug 1206360
VUL-0: CVE-2022-41881: netty: Infinte recursion in HAProxyMessageDecoder
Last modified: 2023-03-30 19:04:26 UTC
CVE-2022-41881 Netty project is an event-driven asynchronous network application framework. In versions prior to 4.1.86.Final, a StackOverflowError can be raised when parsing a malformed crafted message due to an infinite recursion. This issue is patched in version 4.1.86.Final. There is no workaround, except using a custom HaProxyMessageDecoder. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-41881 https://www.cve.org/CVERecord?id=CVE-2022-41881 https://github.com/netty/netty/security/advisories/GHSA-fx2c-96vj-985v
Affected: - SUSE:SLE-15-SP2:Update/netty 4.1.75 - SUSE:SLE-15-SP2:Update:Products:Manager41:Update/netty 4.1.44 - SUSE:SLE-15-SP3:Update:Products:Manager42:Update/netty 4.1.44 - SUSE:SLE-15-SP4:Update:Products:Manager43:Update/netty 4.1.44 - openSUSE:Backports:SLE-15-SP3/netty 4.1.13 Not Affected: - SUSE:SLE-15-SP2:Update/netty3 3.10.6 - openSUSE:Factory/netty3 3.10.6