-
Notifications
You must be signed in to change notification settings - Fork 3.6k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[security] Upgrade Netty to 4.1.72 - CVE-2021-43797 #13328
Conversation
@nicoloboschi:Thanks for your contribution. For this PR, do we need to update docs? |
/pulsarbot rerun-failure-checks |
b2e7acf
to
42d3ac0
Compare
/pulsarbot rerun-failure-checks |
* [security] Upgrade Netty to 4.1.72 * fix licenses files
* [security] Upgrade Netty to 4.1.72 * fix licenses files
* [security] Upgrade Netty to 4.1.72 * fix licenses files (cherry picked from commit 3b44d67)
* [security] Upgrade Netty to 4.1.72 * fix licenses files
* [security] Upgrade Netty to 4.1.72 * fix licenses files (cherry picked from commit 3b44d67)
@merlimat @codelipenghui @rdhabalia This Netty upgrade to 4.1.72.Final brings in a major change in the Netty Recycler. The Netty Recycler was rewritten for Netty 4.1.71.Final in netty/netty#11858 . |
Motivation
Netty versions prior to 4.1.71 are vulnerable to CVE-2021-43797
https://nvd.nist.gov/vuln/detail/CVE-2021-43797
Netty release notes:
Modifications
Documentation