Skip to content

fix: bump netty to 4.1.133.Final to remediate CVE-2026-42583#896

Open
nikagra wants to merge 1 commit into
scylla-4.xfrom
fix/cve-2026-42583-netty-bump
Open

fix: bump netty to 4.1.133.Final to remediate CVE-2026-42583#896
nikagra wants to merge 1 commit into
scylla-4.xfrom
fix/cve-2026-42583-netty-bump

Conversation

@nikagra
Copy link
Copy Markdown

@nikagra nikagra commented May 19, 2026

Summary

Root fix for CVE-2026-42583, tracked in scylladb/kafka-connect-scylladb#164.

Lz4FrameDecoder in netty-codec prior to 4.1.133.Final allocates up to 32 MB per block before LZ4 decompression runs. A peer needs only a 21-byte crafted header to trigger that allocation, enabling remote memory exhaustion (DoS). CVSS 7.5 (HIGH).

Change

-    <netty.version>4.1.127.Final</netty.version>
+    <netty.version>4.1.133.Final</netty.version>

One-line change in the root pom.xml. All consumers of java-driver-core will inherit the fix transitively once a new driver release is published, eliminating the need for downstream <dependencyManagement> overrides.

Follow-up

After this merges and a new release is cut, scylladb/kafka-connect-scylladb will bump scylladb.version and remove the temporary BOM override added in Stage 1.

Lz4FrameDecoder in netty-codec prior to 4.1.133.Final allocates up to
32 MB per block before decompression runs. A peer can trigger this with
a 21-byte crafted LZ4 header, causing memory exhaustion (DoS).

Bump netty.version from 4.1.127.Final to 4.1.133.Final so all consumers
of java-driver-core inherit the fix transitively, without needing local
dependencyManagement overrides.

Ref: scylladb/kafka-connect-scylladb#164
CVE: CVE-2026-42583
CVSS: 7.5 (HIGH)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant