Bug 26019 - netty, netty3 new security issues CVE-2019-16869, CVE-2019-20444, CVE-2019-20445, CVE-2020-7238, CVE-2020-11612, CVE-2021-21290, CVE-2021-21295, CVE-2021-21409
Summary: netty, netty3 new security issues CVE-2019-16869, CVE-2019-20444, CVE-2019-20...
Status: RESOLVED OLD
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 7
Hardware: All Linux
Priority: Normal critical
Target Milestone: ---
Assignee: Java Stack Maintainers
QA Contact: Sec team
URL:
Whiteboard:
Keywords:
: 27828 (view as bug list)
Depends on: 28446 28985
Blocks:
  Show dependency treegraph
 
Reported: 2020-01-05 04:33 CET by David Walser
Modified: 2021-07-01 18:21 CEST (History)
2 users (show)

See Also:
Source RPM: netty-4.1.13-1.mga7.src.rpm, netty3-3.10.6-2.mga7.src.rpm
CVE:
Status comment: Fixed upstream in 4.1.61


Attachments

Description David Walser 2020-01-05 04:33:31 CET
Debian has issued an advisory on January 3:
https://www.debian.org/security/2020/dsa-4597

The issue is fixed upstream in 4.1.42.

Mageia 7 is also affected.
David Walser 2020-01-05 04:34:17 CET

Whiteboard: (none) => MGA7TOO

David Walser 2020-01-14 17:35:52 CET

Status comment: (none) => Fixed upstream in 4.1.42

Comment 1 David Walser 2020-02-19 23:24:43 CET
Debian-LTS has issued an advisory today (February 19):
https://www.debian.org/lts/security/2020/dla-2109

It fixes three new issues (one due to an incomplete fix for the original issue in this bug) which are fixed upstream in 4.1.44.

Status comment: Fixed upstream in 4.1.42 => Fixed upstream in 4.1.44
Summary: netty new security issue CVE-2019-16869 => netty new security issue CVE-2019-16869, CVE-2019-20444, CVE-2019-20445, CVE-2020-7238

Comment 2 David Walser 2020-09-22 19:31:19 CEST
Debian-LTS has issued an advisory on September 4:
https://www.debian.org/lts/security/2020/dla-2364

It fixes a new issue, fixed upstream in 4.1.46.

I noticed we still have netty3 packaged too, and Debian-LTS fixed some of these issues for that on September 4:
https://www.debian.org/lts/security/2020/dla-2365

Severity: major => critical
Summary: netty new security issue CVE-2019-16869, CVE-2019-20444, CVE-2019-20445, CVE-2020-7238 => netty, netty3 new security issues CVE-2019-16869, CVE-2019-20444, CVE-2019-20445, CVE-2020-7238, CVE-2020-11612
Status comment: Fixed upstream in 4.1.44 => Fixed upstream in 4.1.46
Source RPM: netty-4.1.13-2.mga8.src.rpm => netty-4.1.13-2.mga8.src.rpm, netty3-3.10.6-4.mga8.src.rpm

Comment 3 David Walser 2020-09-23 21:15:41 CEST
Ubuntu has issued an advisory for some of these issues on September 22:
https://ubuntu.com/security/notices/USN-4532-1
Comment 4 David Walser 2020-09-25 21:53:47 CEST
Fedora has issued an advisory for this today (September 25):
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/TS6VX7OMXPDJIU5LRGUAHRK6MENAVJ46/
Comment 5 David Walser 2020-10-29 17:03:04 CET
Ubuntu has issued an advisory for some of these issues on October 27:
https://ubuntu.com/security/notices/USN-4600-2
Comment 6 David Walser 2020-12-15 17:02:59 CET
*** Bug 27828 has been marked as a duplicate of this bug. ***

CC: (none) => zombie_ryushu

Comment 7 Nicolas Lécureuil 2020-12-27 00:34:22 CET
not an issue in cauldron, we have netty 4.1.51

Version: Cauldron => 7
CC: (none) => mageia
Whiteboard: MGA7TOO => (none)

Comment 8 David Walser 2020-12-27 00:40:10 CET
Also netty3 was dropped.

Source RPM: netty-4.1.13-2.mga8.src.rpm, netty3-3.10.6-4.mga8.src.rpm => netty-4.1.13-1.mga7.src.rpm, netty3-3.10.6-2.mga7.src.rpm

Comment 9 David Walser 2021-02-26 17:13:19 CET
Debian-LTS has issued an advisory on February 11:
https://www.debian.org/lts/security/2021/dla-2555

The issue is fixed upstream in 4.1.59:
https://github.com/netty/netty/security/advisories/GHSA-5mcr-gq6c-3hq2

Summary: netty, netty3 new security issues CVE-2019-16869, CVE-2019-20444, CVE-2019-20445, CVE-2020-7238, CVE-2020-11612 => netty, netty3 new security issues CVE-2019-16869, CVE-2019-20444, CVE-2019-20445, CVE-2020-7238, CVE-2020-11612, CVE-2021-21290
Status comment: Fixed upstream in 4.1.46 => Fixed upstream in 4.1.59

David Walser 2021-02-26 17:14:10 CET

Depends on: (none) => 28446

David Walser 2021-05-28 22:10:17 CEST

Depends on: (none) => 28985

Comment 10 David Walser 2021-05-28 22:10:48 CEST
Debian has issued an advisory on April 5:
https://www.debian.org/security/2021/dsa-4885

The issues are fixed upstream in 4.1.61.

Status comment: Fixed upstream in 4.1.59 => Fixed upstream in 4.1.61
Summary: netty, netty3 new security issues CVE-2019-16869, CVE-2019-20444, CVE-2019-20445, CVE-2020-7238, CVE-2020-11612, CVE-2021-21290 => netty, netty3 new security issues CVE-2019-16869, CVE-2019-20444, CVE-2019-20445, CVE-2020-7238, CVE-2020-11612, CVE-2021-21290, CVE-2021-21295, CVE-2021-21409

Comment 11 David Walser 2021-05-30 22:07:41 CEST
openSUSE has issued an advisory for CVE-2021-21295 on March 19:
https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XDF63Q7PJ5ZO6J24Z3YJ7WWZWTTROVC2/

They patched the same netty version we have in Mageia 7.
Comment 12 David Walser 2021-07-01 18:21:11 CEST
https://blog.mageia.org/en/2021/06/08/mageia-7-will-reach-end-of-support-on-30th-of-june-the-king-is-dead-long-live-the-king/

Resolution: (none) => OLD
Status: NEW => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.