CVE-2024-47535 Information

Description

Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. An unsafe reading of environment file could potentially cause a denial of service in Netty. When loaded on an Windows application Netty attempts to load a file that does not exist. If an attacker creates such a large file the Netty application crashes. This vulnerability is fixed in 4.1.115.

Reference

https://github.com/netty/netty/security/advisories/GHSA-xq3w-v528-46rv https://github.com/netty/netty/commit/fbf7a704a82e7449b48bd0bbb679f5661c6d61a3

Share on: