Fedora Account System
Red Hat Associate
Red Hat Customer
Netty is a network application framework for development of protocol servers and clients. In netty-codec-haproxy prior to versions 4.1.135.Final and 4.2.15.Final, when decoding a PP2_TYPE_SSL TLV, HAProxyMessage.readNextTLV() first calls `header.retainedSlice(header.readerIndex(), length)` and only then reads the 1-byte client field and 4-byte verify field. If the attacker sets the TLV length below 5, the subsequent readByte/readInt throws IndexOutOfBoundsException. HAProxyMessageDecoder only catches HAProxyProtocolException around this call, so the IOOBE propagates and the retained slice on the pooled cumulation buffer is never released. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
This issue has been addressed in the following products: Red Hat Build of Apache Camel 3.33 for Quarkus 3.33.2.SP1 Via RHSA-2026:26586 https://access.redhat.com/errata/RHSA-2026:26586
This issue has been addressed in the following products: Streams for Apache Kafka 2.9.4 Via RHSA-2026:34608 https://access.redhat.com/errata/RHSA-2026:34608
This issue has been addressed in the following products: Red Hat build of Apache Camel 4.18.1.P1 for Spring Boot 3.5.16 Via RHSA-2026:37390 https://access.redhat.com/errata/RHSA-2026:37390
This issue has been addressed in the following products: Red Hat Data Grid 8.6.2 Via RHSA-2026:41951 https://access.redhat.com/errata/RHSA-2026:41951
This issue has been addressed in the following products: Cryostat 4 on RHEL 9 Via RHSA-2026:48151 https://access.redhat.com/errata/RHSA-2026:48151
This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 8.1 Via RHSA-2026:50085 https://access.redhat.com/errata/RHSA-2026:50085
This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7 Via RHSA-2026:53644 https://access.redhat.com/errata/RHSA-2026:53644
This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 7.4.25 Via RHSA-2026:53806 https://access.redhat.com/errata/RHSA-2026:53806