Bug 2515377 (CVE-2026-73508) - CVE-2026-73508 io.netty/netty-codec-dns: Netty: Denial of Service via Memory Leak in DNS Record Decoder with Malformed Domain Names
Summary: CVE-2026-73508 io.netty/netty-codec-dns: Netty: Denial of Service via Memory ...
Keywords:
Status: NEW
Alias: CVE-2026-73508
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-08-13 15:50 UTC by OSIDB Bzimport
Modified: 2026-09-22 15:37 UTC (History)
78 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2026:69296 0 None None None 2026-09-21 12:20:43 UTC
Red Hat Product Errata RHSA-2026:70228 0 None None None 2026-09-22 12:57:37 UTC
Red Hat Product Errata RHSA-2026:70229 0 None None None 2026-09-22 13:02:15 UTC
Red Hat Product Errata RHSA-2026:70230 0 None None None 2026-09-22 13:00:04 UTC
Red Hat Product Errata RHSA-2026:70277 0 None None None 2026-09-22 15:37:11 UTC

Description OSIDB Bzimport 2026-08-13 15:50:58 UTC
Netty is an asynchronous, event-driven network application framework. Prior to 4.1.136.Final and 4.2.16.Final, io.netty.handler.codec.dns.AbstractDnsRecord, io.netty.handler.codec.dns.DefaultDnsRecordDecoder.decodeRecord(), and io.netty.handler.codec.dns.DnsCodecUtil.decompressDomainName() failed to release retained or newly allocated ByteBuf objects when IDN.toASCII() or encodeDomainName() rejected a malformed domain name, allowing unauthenticated remote DNS packets to leak direct memory incrementally until denial of service. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.

Comment 2 Jon Orris 2026-09-21 12:20:38 UTC
This issue has been addressed in the following products:

  Red Hat Data Grid 8.6.3

Via RHSA-2026:69296 https://access.redhat.com/errata/RHSA-2026:69296

Comment 3 Jon Orris 2026-09-22 12:57:33 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8

Via RHSA-2026:70228 https://access.redhat.com/errata/RHSA-2026:70228

Comment 4 Jon Orris 2026-09-22 13:00:00 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 10

Via RHSA-2026:70230 https://access.redhat.com/errata/RHSA-2026:70230

Comment 5 Jon Orris 2026-09-22 13:02:10 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9

Via RHSA-2026:70229 https://access.redhat.com/errata/RHSA-2026:70229

Comment 6 Jon Orris 2026-09-22 15:37:06 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 8.1

Via RHSA-2026:70277 https://access.redhat.com/errata/RHSA-2026:70277


Note You need to log in before you can comment on or make changes to this bug.