netty-codec: Bzip2Decoder doesn't allow setting size restrictions for decompressed data
Published Oct 19, 2021
7.5
HIGHCVSS 3.1
EPSS 5.91%
Description
The Bzip2 decompression decoder function doesn't allow setting size restrictions on the decompressed output data (which affects the allocation size used during decompression). All users of Bzip2Decoder are affected. The malicious input can trigger an OOME and so a DoS attack
Affected products
-
- Version unspecifiedStatusaffectedConstraints<4.1.68Final
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| The Netty project | Netty | n/a |
|
Configuration 3
- ≥ 18.1 · ≤ 18.3
- 19.1
- 19.2
- 20.1
- 21.1
- 18.1
- 18.2
- 18.3
- 19.1
- 19.2
- 20.1
- 21.1
- 12.2.1.4.0
- 14.1.1.0.0
- 11.3.2
- < 12.0.0.4.6
- 12
- 1.10.0
- 1.11.0
- 1.8.0
- 1.15.0
- 1.7.0
- 1.15.0
- ≥ 8.0.0.0 · ≤ 8.5.0.2
- 8.1
- 1.4.10
- 2.4.0
- 8.48
- 8.57
- 8.58
- 8.59
- 12.2.1.3.0
- 12.2.1.4.0
Configuration 4
- n/a
Configuration 5
- 10.0
- 11.0
No data.
Logging subsystem for Red Hat OpenShift 5.4
openshift-logging/elasticsearch6-rhel8:v6.8.1-156
Fixed · RHSA-2022:2216
OpenShift Logging 5.1
openshift-logging/elasticsearch6-rhel8:v6.8.1-67
Fixed · RHSA-2021:5128
OpenShift Logging 5.2
openshift-logging/elasticsearch6-rhel8:v6.8.1-157
Fixed · RHSA-2022:2218
OpenShift Logging 5.2
openshift-logging/elasticsearch6-rhel8:v6.8.1-66
Fixed · RHSA-2021:5127
OpenShift Logging 5.3
openshift-logging/elasticsearch6-rhel8:v6.8.1-159
Fixed · RHSA-2022:2217
OpenShift Logging 5.3
openshift-logging/elasticsearch6-rhel8:v6.8.1-65
Fixed · RHSA-2021:5129
RHINT Camel-Q 2.2.1
n/a
Fixed · RHSA-2022:1013
RHINT Service Registry 2.3.0 GA
netty-codec
Fixed · RHSA-2022:6835
RHPAM 7.13.0 async
netty-codec
Fixed · RHSA-2022:5903
Red Hat AMQ 7.9.1
netty-codec
Fixed · RHSA-2021:4851
Red Hat AMQ Streams 2.0.0
netty-codec
Fixed · RHSA-2022:0138
Red Hat AMQ Streams 2.4.0
n/a
Fixed · RHSA-2023:3223
Red Hat AMQ Streams 2.5.0
n/a
Fixed · RHSA-2023:5165
Red Hat Data Grid 8.3.0
netty-codec
Fixed · RHSA-2022:0520
Red Hat Fuse 7.10
netty-codec
Fixed · RHSA-2021:5134
Red Hat JBoss Enterprise Application Platform 7
netty-all
Fixed · RHSA-2022:4922
Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7
eap7-glassfish-el-0:3.0.1-4.b08_redhat_00005.1.ep7.el7
Fixed · RHSA-2025:9582
Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7
eap7-hibernate-0:5.1.17-3.Final_redhat_00004.1.ep7.el7
Fixed · RHSA-2025:9582
Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7
eap7-jackson-databind-0:2.8.11.6-3.SP1_redhat_00003.1.ep7.el7
Fixed · RHSA-2025:9582
Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7
eap7-jboss-ejb-client-0:4.0.12-1.Final_redhat_00002.1.ep7.el7
Fixed · RHSA-2025:9582
Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7
eap7-netty-0:4.1.63-2.Final_redhat_00003.1.ep7.el7
Fixed · RHSA-2025:9582
Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7
eap7-undertow-0:1.4.18-16.SP14_redhat_00001.1.ep7.el7
Fixed · RHSA-2025:9582
Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7
eap7-wildfly-0:7.1.11-4.GA_redhat_00002.1.ep7.el7
Fixed · RHSA-2025:9582
Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7
eap7-wildfly-elytron-0:1.1.14-1.Final_redhat_00001.1.ep7.el7
Fixed · RHSA-2025:9582
Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7
eap7-wildfly-http-client-0:1.0.21-1.Final_redhat_00001.1.ep7.el7
Fixed · RHSA-2025:9582
Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7
eap7-wildfly-naming-client-0:1.0.13-1.Final_redhat_00001.1.ep7.el7
Fixed · RHSA-2025:9582
Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7
eap7-wildfly-openssl-0:1.0.12-1.Final_redhat_00001.1.ep7.el7
Fixed · RHSA-2025:9582
Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7
eap7-wildfly-openssl-linux-0:1.0.12-6.Final_redhat_00001.1.ep7.el7
Fixed · RHSA-2025:9582
Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7
eap7-jackson-annotations-0:2.10.4-3.redhat_00006.1.el7eap
Fixed · RHSA-2025:9583
Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7
eap7-jackson-core-0:2.10.4-3.redhat_00006.1.el7eap
Fixed · RHSA-2025:9583
Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7
eap7-jackson-databind-0:2.10.4-5.redhat_00006.1.el7eap
Fixed · RHSA-2025:9583
Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7
eap7-jackson-jaxrs-providers-0:2.10.4-3.redhat_00006.1.el7eap
Fixed · RHSA-2025:9583
Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7
eap7-jackson-modules-base-0:2.10.4-5.redhat_00006.1.el7eap
Fixed · RHSA-2025:9583
Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7
eap7-jackson-modules-java8-0:2.10.4-2.redhat_00006.1.el7eap
Fixed · RHSA-2025:9583
Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7
eap7-jboss-server-migration-0:1.7.2-16.Final_redhat_00017.1.el7eap
Fixed · RHSA-2025:9583
Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7
eap7-netty-0:4.1.63-5.Final_redhat_00003.1.el7eap
Fixed · RHSA-2025:9583
Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7
eap7-undertow-0:2.0.41-4.SP5_redhat_00001.1.el7eap
Fixed · RHSA-2025:9583
Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7
eap7-wildfly-0:7.3.14-3.GA_redhat_00002.1.el7eap
Fixed · RHSA-2025:9583
Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7
eap7-wildfly-elytron-0:1.10.17-1.Final_redhat_00001.1.el7eap
Fixed · RHSA-2025:9583
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8
eap7-netty-0:4.1.72-4.Final_redhat_00001.1.el8eap
Fixed · RHSA-2022:4919
Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7
eap7-netty-0:4.1.72-4.Final_redhat_00001.1.el7eap
Fixed · RHSA-2022:4918
Red Hat Satellite 6.12 for RHEL 8
candlepin-0:4.1.15-1.el8sat
Fixed · RHSA-2022:8506
Red Hat build of Quarkus 2.2.5
netty-codec
Fixed · RHSA-2022:0589
Vert.x 4.1.5
netty-codec
Fixed · RHSA-2021:3959
A-MQ Clients 2
netty-codec
Affected
Red Hat BPM Suite 6
netty-codec
Out of support scope
Red Hat Integration Camel K 1
netty-codec
Affected
Red Hat Integration Camel Quarkus 1
netty-codec
Affected
Red Hat Integration Service Registry
netty-codec
Not affected
Red Hat JBoss BRMS 6
netty-codec
Out of support scope
Red Hat JBoss Data Grid 7
netty-codec
Out of support scope
Red Hat JBoss Data Virtualization 6
netty-codec
Out of support scope
Red Hat JBoss Fuse 6
netty-codec
Out of support scope
Red Hat JBoss Fuse Service Works 6
netty-codec
Out of support scope
Red Hat OpenShift Container Platform 3.11
openshift3/ose-logging-elasticsearch5
Out of support scope
Red Hat OpenShift Container Platform 4
openshift4/ose-logging-elasticsearch6
Out of support scope
Red Hat OpenShift Container Platform 4
openshift4/ose-metering-hadoop
Will not fix
Red Hat OpenShift Container Platform 4
openshift4/ose-metering-hive
Not affected
Red Hat OpenShift Container Platform 4
openshift4/ose-metering-presto
Not affected
Red Hat OpenStack Platform 10 (Newton)
opendaylight
Out of support scope
Red Hat OpenStack Platform 13 (Queens)
opendaylight
Out of support scope
Red Hat Single Sign-On 7
netty-codec
Affected
Red Hat build of Quarkus
netty-codec
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Logging subsystem for Red Hat OpenShift 5.4 | openshift-logging/elasticsearch6-rhel8:v6.8.1-156 | Fixed | RHSA-2022:2216 |
| OpenShift Logging 5.1 | openshift-logging/elasticsearch6-rhel8:v6.8.1-67 | Fixed | RHSA-2021:5128 |
| OpenShift Logging 5.2 | openshift-logging/elasticsearch6-rhel8:v6.8.1-157 | Fixed | RHSA-2022:2218 |
| OpenShift Logging 5.2 | openshift-logging/elasticsearch6-rhel8:v6.8.1-66 | Fixed | RHSA-2021:5127 |
| OpenShift Logging 5.3 | openshift-logging/elasticsearch6-rhel8:v6.8.1-159 | Fixed | RHSA-2022:2217 |
| OpenShift Logging 5.3 | openshift-logging/elasticsearch6-rhel8:v6.8.1-65 | Fixed | RHSA-2021:5129 |
| RHINT Camel-Q 2.2.1 | n/a | Fixed | RHSA-2022:1013 |
| RHINT Service Registry 2.3.0 GA | netty-codec | Fixed | RHSA-2022:6835 |
| RHPAM 7.13.0 async | netty-codec | Fixed | RHSA-2022:5903 |
| Red Hat AMQ 7.9.1 | netty-codec | Fixed | RHSA-2021:4851 |
| Red Hat AMQ Streams 2.0.0 | netty-codec | Fixed | RHSA-2022:0138 |
| Red Hat AMQ Streams 2.4.0 | n/a | Fixed | RHSA-2023:3223 |
| Red Hat AMQ Streams 2.5.0 | n/a | Fixed | RHSA-2023:5165 |
| Red Hat Data Grid 8.3.0 | netty-codec | Fixed | RHSA-2022:0520 |
| Red Hat Fuse 7.10 | netty-codec | Fixed | RHSA-2021:5134 |
| Red Hat JBoss Enterprise Application Platform 7 | netty-all | Fixed | RHSA-2022:4922 |
| Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7 | eap7-glassfish-el-0:3.0.1-4.b08_redhat_00005.1.ep7.el7 | Fixed | RHSA-2025:9582 |
| Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7 | eap7-hibernate-0:5.1.17-3.Final_redhat_00004.1.ep7.el7 | Fixed | RHSA-2025:9582 |
| Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7 | eap7-jackson-databind-0:2.8.11.6-3.SP1_redhat_00003.1.ep7.el7 | Fixed | RHSA-2025:9582 |
| Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7 | eap7-jboss-ejb-client-0:4.0.12-1.Final_redhat_00002.1.ep7.el7 | Fixed | RHSA-2025:9582 |
| Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7 | eap7-netty-0:4.1.63-2.Final_redhat_00003.1.ep7.el7 | Fixed | RHSA-2025:9582 |
| Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7 | eap7-undertow-0:1.4.18-16.SP14_redhat_00001.1.ep7.el7 | Fixed | RHSA-2025:9582 |
| Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7 | eap7-wildfly-0:7.1.11-4.GA_redhat_00002.1.ep7.el7 | Fixed | RHSA-2025:9582 |
| Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7 | eap7-wildfly-elytron-0:1.1.14-1.Final_redhat_00001.1.ep7.el7 | Fixed | RHSA-2025:9582 |
| Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7 | eap7-wildfly-http-client-0:1.0.21-1.Final_redhat_00001.1.ep7.el7 | Fixed | RHSA-2025:9582 |
| Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7 | eap7-wildfly-naming-client-0:1.0.13-1.Final_redhat_00001.1.ep7.el7 | Fixed | RHSA-2025:9582 |
| Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7 | eap7-wildfly-openssl-0:1.0.12-1.Final_redhat_00001.1.ep7.el7 | Fixed | RHSA-2025:9582 |
| Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7 | eap7-wildfly-openssl-linux-0:1.0.12-6.Final_redhat_00001.1.ep7.el7 | Fixed | RHSA-2025:9582 |
| Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7 | eap7-jackson-annotations-0:2.10.4-3.redhat_00006.1.el7eap | Fixed | RHSA-2025:9583 |
| Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7 | eap7-jackson-core-0:2.10.4-3.redhat_00006.1.el7eap | Fixed | RHSA-2025:9583 |
| Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7 | eap7-jackson-databind-0:2.10.4-5.redhat_00006.1.el7eap | Fixed | RHSA-2025:9583 |
| Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7 | eap7-jackson-jaxrs-providers-0:2.10.4-3.redhat_00006.1.el7eap | Fixed | RHSA-2025:9583 |
| Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7 | eap7-jackson-modules-base-0:2.10.4-5.redhat_00006.1.el7eap | Fixed | RHSA-2025:9583 |
| Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7 | eap7-jackson-modules-java8-0:2.10.4-2.redhat_00006.1.el7eap | Fixed | RHSA-2025:9583 |
| Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7 | eap7-jboss-server-migration-0:1.7.2-16.Final_redhat_00017.1.el7eap | Fixed | RHSA-2025:9583 |
| Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7 | eap7-netty-0:4.1.63-5.Final_redhat_00003.1.el7eap | Fixed | RHSA-2025:9583 |
| Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7 | eap7-undertow-0:2.0.41-4.SP5_redhat_00001.1.el7eap | Fixed | RHSA-2025:9583 |
| Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7 | eap7-wildfly-0:7.3.14-3.GA_redhat_00002.1.el7eap | Fixed | RHSA-2025:9583 |
| Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7 | eap7-wildfly-elytron-0:1.10.17-1.Final_redhat_00001.1.el7eap | Fixed | RHSA-2025:9583 |
| Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 | eap7-netty-0:4.1.72-4.Final_redhat_00001.1.el8eap | Fixed | RHSA-2022:4919 |
| Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7 | eap7-netty-0:4.1.72-4.Final_redhat_00001.1.el7eap | Fixed | RHSA-2022:4918 |
| Red Hat Satellite 6.12 for RHEL 8 | candlepin-0:4.1.15-1.el8sat | Fixed | RHSA-2022:8506 |
| Red Hat build of Quarkus 2.2.5 | netty-codec | Fixed | RHSA-2022:0589 |
| Vert.x 4.1.5 | netty-codec | Fixed | RHSA-2021:3959 |
| A-MQ Clients 2 | netty-codec | Affected | n/a |
| Red Hat BPM Suite 6 | netty-codec | Out of support scope | n/a |
| Red Hat Integration Camel K 1 | netty-codec | Affected | n/a |
| Red Hat Integration Camel Quarkus 1 | netty-codec | Affected | n/a |
| Red Hat Integration Service Registry | netty-codec | Not affected | n/a |
| Red Hat JBoss BRMS 6 | netty-codec | Out of support scope | n/a |
| Red Hat JBoss Data Grid 7 | netty-codec | Out of support scope | n/a |
| Red Hat JBoss Data Virtualization 6 | netty-codec | Out of support scope | n/a |
| Red Hat JBoss Fuse 6 | netty-codec | Out of support scope | n/a |
| Red Hat JBoss Fuse Service Works 6 | netty-codec | Out of support scope | n/a |
| Red Hat OpenShift Container Platform 3.11 | openshift3/ose-logging-elasticsearch5 | Out of support scope | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-logging-elasticsearch6 | Out of support scope | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-metering-hadoop | Will not fix | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-metering-hive | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-metering-presto | Not affected | n/a |
| Red Hat OpenStack Platform 10 (Newton) | opendaylight | Out of support scope | n/a |
| Red Hat OpenStack Platform 13 (Queens) | opendaylight | Out of support scope | n/a |
| Red Hat Single Sign-On 7 | netty-codec | Affected | n/a |
| Red Hat build of Quarkus | netty-codec | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
In the OpenShift Container Platform (OCP), the Hive/Presto/Hadoop components that comprise the OCP Metering stack ship the vulnerable version of netty-codec package. Since the release of OCP 4.6, the Metering product has been deprecated [1], so the affected components are marked as wontfix. This may be fixed in the future. Starting in OCP 4.7, the elasticsearch component is shipping as a part of the OpenShift Logging product (openshift-logging/elasticsearch6-rhel8). The elasticsearch component delivered in OCP 4.6 is marked as `Out of support scope` because these versions are already under Maintenance Phase of the support. [1] https://docs.openshift.com/container-platform/4.6/release_notes/ocp-4-6-release-notes.html#ocp-4-6-metering-operator-deprecated
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:N/I:N/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (29 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 5.91% (0.05908) | 93.01th | v5 (v2026.06.15) |
| Jun 15, 2026 | 5.65% (0.05651) | 91.94th | v5 (v2026.06.15) |
| Nov 21, 2025 | 0.30% (0.00302) | 53.05th | v4 (v2025.03.14) |
| Nov 18, 2025 | 2.78% (0.02782) | 84.78th | v4 (v2025.03.14) |
| Mar 17, 2025 | 0.22% (0.00217) | 42.34th | v4 (v2025.03.14) |
| Dec 12, 2024 | 1.44% (0.01441) | 87.16th | v3 (v2023.03.01) |
| Jul 4, 2024 | 0.74% (0.00741) | 80.99th | v3 (v2023.03.01) |
| May 25, 2024 | 0.68% (0.00682) | 79.98th | v3 (v2023.03.01) |
| Apr 29, 2024 | 0.66% (0.00662) | 79.40th | v3 (v2023.03.01) |
| Mar 6, 2024 | 0.47% (0.00467) | 74.94th | v3 (v2023.03.01) |
| Jan 11, 2024 | 0.47% (0.00467) | 72.93th | v3 (v2023.03.01) |
| Jul 8, 2023 | 0.33% (0.00328) | 66.87th | v3 (v2023.03.01) |
| Jun 10, 2023 | 0.21% (0.00214) | 58.12th | v3 (v2023.03.01) |
| May 27, 2023 | 0.21% (0.00207) | 57.31th | v3 (v2023.03.01) |
| May 8, 2023 | 0.18% (0.00182) | 53.93th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.18% (0.00176) | 52.89th | v3 (v2023.03.01) |
| Mar 6, 2023 | 2.69% (0.02686) | 82.85th | v2 (v2022.01.01) |
| Jan 12, 2023 | 2.69% (0.02686) | 82.27th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.54% (0.01537) | 72.41th | v2 (v2022.01.01) |
| Feb 11, 2022 | 16.31% (0.16306) | 92.88th | v2 (v2022.01.01) |
| Feb 9, 2022 | 19.17% (0.19173) | 93.73th | v2 (v2022.01.01) |
| Feb 8, 2022 | 24.20% (0.24201) | 95.22th | v2 (v2022.01.01) |
| Feb 4, 2022 | 19.03% (0.19026) | 93.66th | v2 (v2022.01.01) |
| Feb 3, 2022 | 18.55% (0.18552) | 93.63th | v1 |
| Jan 6, 2022 | 18.55% (0.18552) | 93.55th | v1 |
| Dec 4, 2021 | 4.83% (0.04831) | 87.73th | v1 |
| Oct 27, 2021 | 1.66% (0.01659) | 74.43th | v1 |
| Oct 26, 2021 | 1.25% (0.01247) | 69.17th | v1 |
| Oct 20, 2021 | 0.42% (0.00416) | 25.80th | v1 |
References (28)
- https://access.redhat.com/security/cve/CVE-2021-37136 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2004133 Issue Tracking
- https://github.com/advisories/GHSA-grg4-wf29-r9vv Advisory
- https://github.com/netty/netty/blob/4.1/codec/src/main/java/io/netty/handler/codec/compression/Bzip2Decoder.java#L294
- https://github.com/netty/netty/blob/4.1/codec/src/main/java/io/netty/handler/codec/compression/Bzip2Decoder.java#L305
- https://github.com/netty/netty/blob/4.1/codec/src/main/java/io/netty/handler/codec/compression/Bzip2Decoder.java#L80
- https://github.com/netty/netty/commit/41d3d61a61608f2223bb364955ab2045dd5e4020
- https://github.com/netty/netty/security/advisories/GHSA-grg4-wf29-r9vv Third Party Advisory
- https://lists.apache.org/thread.html/r06a145c9bd41a7344da242cef07977b24abe3349161ede948e30913d%40%3Ccommits.druid.apache.org%3E mailing-list
- https://lists.apache.org/thread.html/r06a145c9bd41a7344da242cef07977b24abe3349161ede948e30913d@%3Ccommits.druid.apache.org%3E
- https://lists.apache.org/thread.html/r5406eaf3b07577d233b9f07cfc8f26e28369e6bab5edfcab41f28abb%40%3Ccommits.druid.apache.org%3E mailing-list
- https://lists.apache.org/thread.html/r5406eaf3b07577d233b9f07cfc8f26e28369e6bab5edfcab41f28abb@%3Ccommits.druid.apache.org%3E
- https://lists.apache.org/thread.html/r5e05eba32476c580412f9fbdfc9b8782d5b40558018ac4ac07192a04%40%3Ccommits.druid.apache.org%3E mailing-list
- https://lists.apache.org/thread.html/r5e05eba32476c580412f9fbdfc9b8782d5b40558018ac4ac07192a04@%3Ccommits.druid.apache.org%3E
- https://lists.apache.org/thread.html/r75490c61c2cb7b6ae2c81238fd52ae13636c60435abcd732d41531a0%40%3Ccommits.druid.apache.org%3E mailing-list
- https://lists.apache.org/thread.html/r75490c61c2cb7b6ae2c81238fd52ae13636c60435abcd732d41531a0@%3Ccommits.druid.apache.org%3E
- https://lists.apache.org/thread.html/rd262f59b1586a108e320e5c966feeafbb1b8cdc96965debc7cc10b16%40%3Ccommits.druid.apache.org%3E mailing-list
- https://lists.apache.org/thread.html/rd262f59b1586a108e320e5c966feeafbb1b8cdc96965debc7cc10b16@%3Ccommits.druid.apache.org%3E
- https://lists.apache.org/thread.html/rfb2bf8597e53364ccab212fbcbb2a4e9f0a9e1429b1dc08023c6868e%40%3Cdev.tinkerpop.apache.org%3E mailing-list
- https://lists.apache.org/thread.html/rfb2bf8597e53364ccab212fbcbb2a4e9f0a9e1429b1dc08023c6868e@%3Cdev.tinkerpop.apache.org%3E
- https://lists.debian.org/debian-lts-announce/2023/01/msg00008.html mailing-listMailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2021-37136
- https://security.netapp.com/advisory/ntap-20220210-0012/ Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2021-37136
- https://www.debian.org/security/2023/dsa-5316 vendor-advisoryThird Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2022.html PatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpujan2022.html PatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpujul2022.html PatchThird Party Advisory
Change history (0)
No recorded changes yet.