Bug 2541871 (CVE-2026-100662)
| Summary: | CVE-2026-100662 io.netty/netty-codec-http3: netty-codec-http3: Denial of Service via unbounded memory allocation in QPACK stream decoder | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | high | Docs Contact: | |
| Priority: | high | ||
| Version: | unspecified | CC: | sdawley |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in Netty's HTTP/3 codec. A remote, unauthenticated attacker can cause a Denial of Service (DoS) by establishing an HTTP/3 connection and sending stream instructions that declare excessively large field lengths without delivering the complete data. Because the server does not enforce size limits on these instructions, it continuously allocates and retains connection buffers until memory is exhausted, resulting in an application crash.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
OSIDB Bzimport
2026-09-26 13:38:19 UTC
|