Skip to content

fix: bump netty to 4.1.138.Final for CVE-2026-75595/-75596 - #1098

Merged
dkropachev merged 1 commit into
scylladb:scylla-3.xfrom
nikagra:fix/cve-2026-75595-75596-bump-netty
Sep 16, 2026
Merged

dkropachev merged 1 commit into
scylladb:scylla-3.xfrom
nikagra:fix/cve-2026-75595-75596-bump-netty

Conversation

@nikagra

@nikagra nikagra commented Sep 16, 2026 •

Copy link
Copy Markdown

Summary

  • SslClientHelloHandler#decode reads the wrong offset on a split ClientHello, falling back to the default SslContext and bypassing per-SNI clientAuth=REQUIRE mTLS gates (CVE-2026-75595, CRITICAL)
  • The same handshake-aggregation path recopies the full buffer per TLS record, letting an unauthenticated peer trigger quadratic CPU work on the event loop (CVE-2026-75596, MEDIUM)
  • Both are fixed in Netty 4.1.137.Final; bumps the single netty.version property to the latest 4.1.x patch, 4.1.138.Final

Test plan

  • mvn -pl driver-core -am dependency:tree -Dincludes=io.netty confirms every io.netty:* module resolves to 4.1.138.Final
  • mvn -pl driver-core -am install -DskipTests builds cleanly
  • Full CCM/integration suite not run in this session

Note: this targets scylla-3.x, which is in maintenance mode per #919 — security fixes are the expected exception to that mode.

🤖 Generated with Claude Code

@coderabbitai

coderabbitai Bot commented Sep 16, 2026 •

Copy link
Copy Markdown

Warning

Review limit reached

Next included review available in 50 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Organization UI

Review profile: QUIET

Plan: Advanced

Run ID: f5e6d261-10fc-4594-b3bb-110b31fc670d

📥 Commits

Reviewing files that changed from the base of the PR and between 9d89187 and 8777f0b.

📒 Files selected for processing (1)
  • pom.xml

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@qodo-scylladb

qodo-scylladb Bot commented Sep 16, 2026

Copy link
Copy Markdown

Code Review by Qodo

🐞 Bugs (0) 📘 Rule violations (0) 📎 Requirement gaps (0)

Great, no issues found!

Qodo reviewed your code and found no material issues that require review
Tip of the day
💡 Did you know, you can group findings by type and pick your Finding display, from Minimal to Full

More tips ↗ | Customize Qodo ↗ | Qodo docs ↗


Powered by Qodo

SslClientHelloHandler#decode read the wrong offset on a split
ClientHello, falling back to the default SslContext and bypassing
per-SNI clientAuth=REQUIRE mTLS gates (CVE-2026-75595, CRITICAL).
The same aggregation path recopied the full handshake buffer per
TLS record, letting an unauthenticated peer trigger quadratic CPU
work on the event loop (CVE-2026-75596, MEDIUM). Both fixed in
Netty 4.1.137.Final; bumps to the latest 4.1.x patch, 4.1.138.Final.

Co-Authored-By: Claude Sonnet 5 <[email protected]>
@nikagra
nikagra force-pushed the fix/cve-2026-75595-75596-bump-netty branch from 12024fb to 8777f0b Compare September 16, 2026 11:28
@nikagra nikagra changed the title fix: bump netty to 4.1.137.Final for CVE-2026-75595/-75596 fix: bump netty to 4.1.138.Final for CVE-2026-75595/-75596 Sep 16, 2026
@dkropachev
dkropachev merged commit b7e7f8e into scylladb:scylla-3.x Sep 16, 2026
14 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants