Skip to content

[security] Upgrade Netty to 4.1.72 - CVE-2021-43797#2951

Merged
zymap merged 3 commits intoapache:masterfrom
nicoloboschi:upgrade-netty-72
Dec 22, 2021
Merged

[security] Upgrade Netty to 4.1.72 - CVE-2021-43797#2951
zymap merged 3 commits intoapache:masterfrom
nicoloboschi:upgrade-netty-72

Conversation

@nicoloboschi
Copy link
Contributor

Motivation

Netty versions prior to 4.1.71 are vulnerable to CVE-2021-43797
https://nvd.nist.gov/vuln/detail/CVE-2021-43797

Netty release notes:

Changes

  • Upgraded Netty libraries to 4.1.72.Final
  • Upgraded netty-tcnative-boringssl-static to 2.0.46.Final which is compatible with Netty 4.1.72.Final

@zymap zymap merged commit 10081d2 into apache:master Dec 22, 2021
merlimat pushed a commit that referenced this pull request Dec 22, 2021
Netty versions prior to 4.1.71 are vulnerable to CVE-2021-43797
https://nvd.nist.gov/vuln/detail/CVE-2021-43797

Netty release notes:
- https://netty.io/news/2021/10/11/4-1-69-Final.html
- https://netty.io/news/2021/10/11/4-1-70-Final.html
- https://netty.io/news/2021/12/09/4-1-71-Final.html
- https://netty.io/news/2021/12/13/4-1-72-Final.html

- Upgraded Netty libraries to 4.1.72.Final
- Upgraded netty-tcnative-boringssl-static to 2.0.46.Final which is compatible with Netty 4.1.72.Final
nicoloboschi added a commit to datastax/bookkeeper that referenced this pull request Jan 25, 2022
Netty versions prior to 4.1.71 are vulnerable to CVE-2021-43797
https://nvd.nist.gov/vuln/detail/CVE-2021-43797

Netty release notes:
- https://netty.io/news/2021/10/11/4-1-69-Final.html
- https://netty.io/news/2021/10/11/4-1-70-Final.html
- https://netty.io/news/2021/12/09/4-1-71-Final.html
- https://netty.io/news/2021/12/13/4-1-72-Final.html

- Upgraded Netty libraries to 4.1.72.Final
- Upgraded netty-tcnative-boringssl-static to 2.0.46.Final which is compatible with Netty 4.1.72.Final

(cherry picked from commit a5ef549)
Ghatage pushed a commit to sijie/bookkeeper that referenced this pull request Jul 12, 2024
### Motivation

Netty versions prior to 4.1.71 are vulnerable to CVE-2021-43797
https://nvd.nist.gov/vuln/detail/CVE-2021-43797


Netty release notes:
- https://netty.io/news/2021/10/11/4-1-69-Final.html
- https://netty.io/news/2021/10/11/4-1-70-Final.html
- https://netty.io/news/2021/12/09/4-1-71-Final.html
- https://netty.io/news/2021/12/13/4-1-72-Final.html


### Changes
- Upgraded Netty libraries to 4.1.72.Final
- Upgraded netty-tcnative-boringssl-static to 2.0.46.Final which is compatible with Netty 4.1.72.Final
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants