Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-34462
HistoryJun 22, 2023 - 12:00 a.m.

CVE-2023-34462

2023-06-2200:00:00
ubuntu.com
ubuntu.com
13
netty
snihandler
tls handshake
heap allocation
tcp server
vulnerability
fix

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

47.2%

Netty is an asynchronous event-driven network application framework for
rapid development of maintainable high performance protocol servers &
clients. The SniHandler can allocate up to 16MB of heap for each channel
during the TLS handshake. When the handler or the channel does not have an
idle timeout, it can be used to make a TCP server using the SniHandler to
allocate 16MB of heap. The SniHandler class is a handler that waits for
the TLS handshake to configure a SslHandler according to the indicated
server name by the ClientHello record. For this matter it allocates a
ByteBuf using the value defined in the ClientHello record. Normally the
value of the packet should be smaller than the handshake packet but there
are not checks done here and the way the code is written, it is possible to
craft a packet that makes the SslClientHelloHandler. This vulnerability
has been fixed in version 4.1.94.Final.

OSVersionArchitecturePackageVersionFilename
ubuntu22.04noarchnetty< anyUNKNOWN
ubuntu24.04noarchnetty< anyUNKNOWN

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

47.2%