Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

ZOOKEEPER-4414: Update Netty to 4.1.70.Final #1775

Closed
wants to merge 1 commit into from

Conversation

frederiko
Copy link
Contributor

This PR updates Netty to 4.1.70 Final on master. This addresses the following CVEs:

  • CVE-2021-37136
  • Netty codec/src/main/java/io/netty/handler/codec/compression/Lz4FrameEncoder.java Lz4FrameEncoder::finishEncode() Function Buffer Overflow
  • CVE-2021-37137

@frederiko frederiko changed the title Update Netty to 4.1.70.Final ZOOKEEPER-4414: Update Netty to 4.1.70.Final Nov 9, 2021
@maoling
Copy link
Member

maoling commented Nov 16, 2021

+1

@maoling maoling closed this Nov 27, 2021
@maoling maoling reopened this Nov 27, 2021
@asfgit asfgit closed this in 01f935c Nov 27, 2021
asfgit pushed a commit that referenced this pull request Nov 27, 2021
This PR updates Netty to 4.1.70 Final on master. This addresses the following CVEs:
* CVE-2021-37136
* Netty codec/src/main/java/io/netty/handler/codec/compression/Lz4FrameEncoder.java Lz4FrameEncoder::finishEncode() Function Buffer Overflow
* CVE-2021-37137

Author: Frederiko Costa <frederiko.costa@workday.com>

Reviewers: maoling <maoling@apache.org>

Closes #1775 from frederiko/netty-4.1.70.Final

(cherry picked from commit 01f935c)
Signed-off-by: maoling <maoling@apache.org>
@maoling
Copy link
Member

maoling commented Nov 27, 2021

@frederiko frederiko deleted the netty-4.1.70.Final branch December 6, 2021 19:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
2 participants