Bug 2488400 (CVE-2026-45674)
| Summary: | CVE-2026-45674 netty-resolver-dns: Netty: Information disclosure and data manipulation due to improper CNAME record validation | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security <prodsec-ir-bot> |
| Status: | NEW --- | QA Contact: | |
| Severity: | high | Docs Contact: | |
| Priority: | high | ||
| Version: | unspecified | CC: | aazores, abrianik, ant, anujha, aschwart, asoldano, aszczucz, avibelli, bbaranow, bbrownin, bgeorges, bmaxwell, boliveir, bstansbe, ccranfor, cescoffi, chfoley, cmah, dandread, dhanak, dkreling, dlofthou, drichtar, drosa, dsimansk, eaguilar, ebaron, ewittman, fmariani, fmongiar, ggrzybek, gmalinko, gsmet, istudens, ivassile, iweiss, janstey, jkoehler, jmartisk, jmatsuok, jnethert, jolong, jpechane, jraez, jtolenti, jwon, kaycoth, kingland, lphiri, lthon, manderse, mcarlett, mnovotny, mosmerov, mposolda, mstipich, msvehla, nipatil, nwallace, olubyans, pantinor, parichar, pberan, pesilva, pgallagh, pjindal, pmackay, probinso, rexwhite, rgodfrey, rguimara, rkubis, rmartinc, rruss, rstancel, rstepani, rsvoboda, sausingh, sbiarozk, sdawley, ssilvert, sthirugn, sthorger, swoodman, tasato, tcunning, thjenkin, tqvarnst, vdosoudi, vmuzikar, yfang |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in Netty's DnsResolveContext. This vulnerability allows a remote attacker to achieve information disclosure or data manipulation by crafting malicious DNS responses. The flaw occurs because the DnsResolveContext fails to validate the origin (bailiwick) of CNAME records in DNS responses, which could enable an attacker to redirect network traffic or intercept sensitive data from affected applications.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
OSIDB Bzimport
2026-06-12 15:02:38 UTC
This issue has been addressed in the following products: Red Hat Build of Apache Camel 3.33 for Quarkus 3.33.2.SP1 Via RHSA-2026:26586 https://access.redhat.com/errata/RHSA-2026:26586 This issue has been addressed in the following products: Streams for Apache Kafka 2.9.4 Via RHSA-2026:34608 https://access.redhat.com/errata/RHSA-2026:34608 This issue has been addressed in the following products: Red Hat build of Apache Camel 4.18.1.P1 for Spring Boot 3.5.16 Via RHSA-2026:37390 https://access.redhat.com/errata/RHSA-2026:37390 This issue has been addressed in the following products: Red Hat Data Grid 8.6.2 Via RHSA-2026:41951 https://access.redhat.com/errata/RHSA-2026:41951 This issue has been addressed in the following products: Cryostat 4 on RHEL 9 Via RHSA-2026:48151 https://access.redhat.com/errata/RHSA-2026:48151 This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 8.1 Via RHSA-2026:49701 https://access.redhat.com/errata/RHSA-2026:49701 This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9 Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8 Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 10 Via RHSA-2026:49700 https://access.redhat.com/errata/RHSA-2026:49700 This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 8.1 Via RHSA-2026:50085 https://access.redhat.com/errata/RHSA-2026:50085 This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7 Via RHSA-2026:53644 https://access.redhat.com/errata/RHSA-2026:53644 This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 7.4.25 Via RHSA-2026:53806 https://access.redhat.com/errata/RHSA-2026:53806 |