Resource exhaustion in Netty - CVE-2020-11612

 

Resource exhaustion in Netty - CVE-2020-11612

Published: May 4, 2020


Vulnerability identifier: #VU27513
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-11612
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to application does not properly control consumption of internal resources within ZlibDecoders in Netty while decoding a ZlibEncoded byte stream. A remote attacker can trigger resource exhaustion by passing an overly large ZlibEncoded byte stream to the Netty server, forcing the server to allocate all of its free memory to a single decoder.


Affected software

Netty
IBM Observability with Instana
Log Analysis
IBM Watson Knowledge Catalog in Cloud Pak for Data
Oracle Communications Design Studio
Oracle Blockchain Platform
Oracle Communications Cloud Native Core Service Communication Proxy
IBM Cloud Pak for Multicloud Management
Dell Support Assist Enterprise
DataStage on Cloud Pak for Data
Oracle FLEXCUBE Universal Banking
Dell EMC PowerStore Family Operating System
IBM Cloud Pak for Watson AIOps
IBM Sterling Order Management
SUSE Manager Server
SUSE Linux Enterprise Module for SUSE Manager Server
Ubuntu
Fedora
netty (Debian package)
libnetty-java (Ubuntu package)
jctools
netty
Red Hat Process Automation Manager (formerly JBoss BPM Suite)
Oracle Communications Instant Messaging Server
Oracle Communications BRM - Elastic Charging Engine
Oracle NoSQL Database
Oracle WebCenter Portal
Oracle Banking Liquidity Management
Oracle Banking Virtual Account Management
Oracle Banking Trade Finance Process Management
Oracle Banking Corporate Lending Process Management
Oracle Banking Credit Facilities Process Management
Oracle Banking Supply Chain Finance
Oracle Banking Payments
AMQ Streams
AMQ Broker
watsonx.data
JBoss Data Grid

How to mitigate CVE-2020-11612

Install updates from vendor's website.

Netty - update to 4.1.46
Log Analysis - update to 1.3.8
IBM Cloud Pak for Multicloud Management - update to 2.3.21
Dell Support Assist Enterprise - update to 4.00.06.00
netty (Debian package) - update to 1:4.1.33-1+deb10u2
DataStage on Cloud Pak for Data - update to 4.8.5
IBM Watson Knowledge Catalog in Cloud Pak for Data - addressed in versions 4.8.8, 4.8.9, 5.1.1, 5.1.2, 5.1.3
Red Hat Process Automation Manager (formerly JBoss BPM Suite) - update to 7.8.0
Oracle NoSQL Database - update to 20.3
libnetty-java (Ubuntu package) - addressed in versions Ubuntu Pro, 1:4.1.7-4ubuntu0.1, 1:4.1.48-4+deb11u1build0.22.04.1, 1:4.1.48-5ubuntu0.1
Dell EMC PowerStore Family Operating System - update to 1.0.4.0.5.003
AMQ Streams - update to 1.5.0
watsonx.data - update to 2.0.2
jctools - update to 3.1.0-1.fc33
IBM Cloud Pak for Watson AIOps - update to 3.5
netty - addressed in versions 4.1.44.Final-150200.3.4.2, 4.1.44.Final-150300.4.3.2, 4.1.44.Final-150400.3.3.2
netty - update to 4.1.51-1.fc33
AMQ Broker - addressed in versions 7.4.4, 7.7
JBoss Data Grid - update to 8.1.0
IBM Sterling Order Management - update to 10.0.2206.2
Oracle Blockchain Platform - update to 21.1.2

External References

Related Security Bulletins