Resource exhaustion in Netty - CVE-2020-11612
Published: May 4, 2020
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources within ZlibDecoders in Netty while decoding a ZlibEncoded byte stream. A remote attacker can trigger resource exhaustion by passing an overly large ZlibEncoded byte stream to the Netty server, forcing the server to allocate all of its free memory to a single decoder.
Affected software
IBM Observability with Instana
Log Analysis
IBM Watson Knowledge Catalog in Cloud Pak for Data
Oracle Communications Design Studio
Oracle Blockchain Platform
Oracle Communications Cloud Native Core Service Communication Proxy
IBM Cloud Pak for Multicloud Management
Dell Support Assist Enterprise
DataStage on Cloud Pak for Data
Oracle FLEXCUBE Universal Banking
Dell EMC PowerStore Family Operating System
IBM Cloud Pak for Watson AIOps
IBM Sterling Order Management
SUSE Manager Server
SUSE Linux Enterprise Module for SUSE Manager Server
Ubuntu
Fedora
netty (Debian package)
libnetty-java (Ubuntu package)
jctools
netty
Red Hat Process Automation Manager (formerly JBoss BPM Suite)
Oracle Communications Instant Messaging Server
Oracle Communications BRM - Elastic Charging Engine
Oracle NoSQL Database
Oracle WebCenter Portal
Oracle Banking Liquidity Management
Oracle Banking Virtual Account Management
Oracle Banking Trade Finance Process Management
Oracle Banking Corporate Lending Process Management
Oracle Banking Credit Facilities Process Management
Oracle Banking Supply Chain Finance
Oracle Banking Payments
AMQ Streams
AMQ Broker
watsonx.data
JBoss Data Grid
How to mitigate CVE-2020-11612
Log Analysis - update to 1.3.8
IBM Cloud Pak for Multicloud Management - update to 2.3.21
Dell Support Assist Enterprise - update to 4.00.06.00
netty (Debian package) - update to 1:4.1.33-1+deb10u2
DataStage on Cloud Pak for Data - update to 4.8.5
IBM Watson Knowledge Catalog in Cloud Pak for Data - addressed in versions 4.8.8, 4.8.9, 5.1.1, 5.1.2, 5.1.3
Red Hat Process Automation Manager (formerly JBoss BPM Suite) - update to 7.8.0
Oracle NoSQL Database - update to 20.3
libnetty-java (Ubuntu package) - addressed in versions Ubuntu Pro, 1:4.1.7-4ubuntu0.1, 1:4.1.48-4+deb11u1build0.22.04.1, 1:4.1.48-5ubuntu0.1
Dell EMC PowerStore Family Operating System - update to 1.0.4.0.5.003
AMQ Streams - update to 1.5.0
watsonx.data - update to 2.0.2
jctools - update to 3.1.0-1.fc33
IBM Cloud Pak for Watson AIOps - update to 3.5
netty - addressed in versions 4.1.44.Final-150200.3.4.2, 4.1.44.Final-150300.4.3.2, 4.1.44.Final-150400.3.3.2
netty - update to 4.1.51-1.fc33
AMQ Broker - addressed in versions 7.4.4, 7.7
JBoss Data Grid - update to 8.1.0
IBM Sterling Order Management - update to 10.0.2206.2
Oracle Blockchain Platform - update to 21.1.2
External References
- https://github.com/netty/netty/compare/netty-4.1.45.Final...netty-4.1.46.Final
- https://github.com/netty/netty/issues/6168
- https://github.com/netty/netty/pull/9924
- https://lists.apache.org/thread.html/r14446ed58208cb6d97b6faa6ebf145f1cf2c70c0886c0c133f4d3b6f@%3Ccommits.druid.apache.org%3E
- https://lists.apache.org/thread.html/r255ed239e65d0596812362adc474bee96caf7ba042c7ad2f3c62cec7@%3Cissues.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/r281882fdf9ea89aac02fd2f92786693a956aac2ce9840cce87c7df6b@%3Ccommits.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/r2958e4d49ee046e1e561e44fdc114a0d2285927501880f15852a9b53@%3Ccommits.druid.apache.org%3E
- https://lists.apache.org/thread.html/r31424427cc6d7db46beac481bdeed9a823fc20bb1b9deede38557f71@%3Cnotifications.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/r3195127e46c87a680b5d1d3733470f83b886bfd3b890c50df718bed1@%3Ccommits.druid.apache.org%3E
- https://lists.apache.org/thread.html/r3ea4918d20d0c1fa26cac74cc7cda001d8990bc43473d062867ef70d@%3Cnotifications.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/r4a7e4e23bd84ac24abf30ab5d5edf989c02b555e1eca6a2f28636692@%3Cnotifications.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/r5030cd8ea5df1e64cf6a7b633eff145992fbca03e8bfc687cd2427ab@%3Cnotifications.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/r5b1ad61552591b747cd31b3a908d5ff2e8f2a8a6847583dd6b7b1ee7@%3Cissues.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/r7836bbdbe95c99d4d725199f0c169927d4e87ba57e4beeeb699c097a@%3Ccommits.druid.apache.org%3E
- https://lists.apache.org/thread.html/r866288c2ada00ce148b7307cdf869f15f24302b3eb2128af33830997@%3Ccommits.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/r88e2b91560c065ed67e62adf8f401c417e4d70256d11ea447215a70c@%3Cissues.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/r8a654f11e1172b0effbfd6f8d5b6ca651ae4ac724a976923c268a42f@%3Ccommits.druid.apache.org%3E
- https://lists.apache.org/thread.html/r9c30b7fca4baedebcb46d6e0f90071b30cc4a0e074164d50122ec5ec@%3Ccommits.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/ra98e3a8541a09271f96478d5e22c7e3bd1afdf48641c8be25d62d9f9@%3Ccommits.druid.apache.org%3E
- https://lists.apache.org/thread.html/rd302ddb501fa02c5119120e5fc21df9a1c00e221c490edbe2d7ad365@%3Cnotifications.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/re1ea144e91f03175d661b2d3e97c7d74b912e019613fa90419cf63f4@%3Cissues.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/ref2c8a0cbb3b8271e5b9a06457ba78ad2028128627186531730f50ef@%3Cnotifications.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/ref3943adbc3a8813aee0e3a9dd919bacbb27f626be030a3c6d6c7f83@%3Ccommits.pulsar.apache.org%3E
- https://lists.apache.org/thread.html/rf803b65b4a57589d79cf2e83d8ece0539018d32864f932f63c972844@%3Cnotifications.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/rfd173eac20d5e5f581c8984b685c836dafea8eb2f7ff85f617704cf1@%3Cdev.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/rff8859c0d06b1688344b39097f9685c43b461cf2bc41f60f001704e9@%3Ccommits.zookeeper.apache.org%3E
Related Security Bulletins
- Denial of service in Netty
- Multiple vulnerabilities in Red Hat Process Automation Manager
- Multiple vulnerabilities in Oracle FLEXCUBE Universal Banking
- Multiple vulnerabilities in Oracle Banking Virtual Account Management
- Multiple vulnerabilities in Oracle Banking Trade Finance Process Management
- Multiple vulnerabilities in Oracle Banking Supply Chain Finance
- Multiple vulnerabilities in Oracle Banking Payments
- Multiple vulnerabilities in Oracle Banking Liquidity Management
- Multiple vulnerabilities in Oracle Banking Credit Facilities Process Management
- Multiple vulnerabilities in Oracle Banking Corporate Lending Process Management
- Debian update for netty
- Multiple vulnerabilities in Oracle NoSQL Database
- Multiple vulnerabilities in Oracle Communications Messaging Server
- Resource exhaustion in Oracle Communications Design Studio
- Multiple vulnerabilities in Oracle WebCenter Portal
- Multiple vulnerabilities in Oracle Communications BRM - Elastic Charging Engine
- Resource exhaustion in Oracle Communications Cloud Native Core Service Communication Proxy
- Resource exhaustion in IBM Cloud Pak for Multicloud Management
- Multiple vulnerabilities in Oracle Blockchain Platform
- SUSE update for netty
- Multiple vulnerabilities in Dell EMC PowerStore Family Operating System
- SUSE update for netty
- SUSE update for netty
- Multiple Vulnerabilities in IBM CloudPak for Watson AIOPs
- Ubuntu update for netty
- Multiple vulnerabilities in IBM Observability with Instana (OnPrem)
- Multiple vulnerabilities in IBM Sterling Order Management
- Multiple vulnerabilities in IBM Operations Analytics - Log Analysis
- Multiple vulnerabilities in Dell Support Assist Enterprise
- Resource exhaustion in IBM watsonx.data
- Multiple vulnerabilities in IBM DataStage on Cloud Pak for Data
- Ubuntu update for netty
- Multiple vulnerabilities in AMQ Streams 1.5
- Multiple vulnerabilities in AMQ Broker 7
- Multiple vulnerabilities in AMQ Broker 7.4
- Multiple vulnerabilities in JBoss Data Grid 8.1
- Fedora 33 update for jctools, netty
- Multiple vulnerabilities in IBM Watson Knowledge Catalog