SUSE-SU-2026:4391-1: important: Security update for netty, netty-tcnative
SLE-SECURITY-UPDATES
null at suse.de
Tue Sep 29 17:23:05 UTC 2026
# Security update for netty, netty-tcnative
Announcement ID: SUSE-SU-2026:4391-1
Release Date: 2026-09-29T11:47:42Z
Rating: important
References:
* bsc#1275500
* bsc#1275501
* bsc#1276420
* bsc#1276421
* bsc#1276455
* bsc#1276456
* bsc#1277243
* bsc#1280048
* bsc#1281431
* bsc#1281432
* bsc#1281433
* bsc#1281434
* bsc#1281435
* bsc#1282084
* bsc#1282085
* bsc#1282132
* bsc#1282140
* bsc#1282141
* bsc#1282362
* bsc#1282363
* bsc#1282364
* bsc#1282366
* bsc#1282367
* bsc#1282370
* bsc#1282372
* bsc#1282373
* bsc#1282374
* bsc#1282378
* bsc#1282506
* bsc#1282507
Cross-References:
* CVE-2026-59902
* CVE-2026-59903
* CVE-2026-62243
* CVE-2026-62380
* CVE-2026-75595
* CVE-2026-75596
* CVE-2026-76816
* CVE-2026-89044
* CVE-2026-93488
* CVE-2026-93491
* CVE-2026-93492
* CVE-2026-93493
* CVE-2026-93494
* CVE-2026-93558
* CVE-2026-93560
* CVE-2026-93562
* CVE-2026-93563
* CVE-2026-93564
* CVE-2026-93565
* CVE-2026-93566
* CVE-2026-93567
* CVE-2026-93568
* CVE-2026-93569
* CVE-2026-93572
* CVE-2026-93573
* CVE-2026-93574
* CVE-2026-93575
* CVE-2026-93576
* CVE-2026-93578
* CVE-2026-93579
CVSS scores:
* CVE-2026-59902 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-59902 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-59903 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N
* CVE-2026-59903 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
* CVE-2026-59903 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N
* CVE-2026-62243 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
* CVE-2026-62243 ( NVD ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-62243 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
* CVE-2026-62380 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
* CVE-2026-62380 ( NVD ): 6.3
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-62380 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-75595 ( SUSE ): 9.1
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-75595 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
* CVE-2026-75595 ( NVD ): 9.1
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-75595 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
* CVE-2026-75596 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-75596 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-75596 ( NVD ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-75596 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-76816 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N
* CVE-2026-76816 ( SUSE ): 8.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
* CVE-2026-76816 ( NVD ): 3.5 CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
* CVE-2026-89044 ( SUSE ): 6.9
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
* CVE-2026-89044 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
* CVE-2026-89044 ( NVD ): 6.9
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-89044 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
* CVE-2026-93488 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-93488 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-93488 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-93491 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-93491 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-93491 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-93492 ( SUSE ): 6.9
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-93492 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-93492 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-93493 ( SUSE ): 9.1
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-93493 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
* CVE-2026-93493 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-93494 ( SUSE ): 6.9
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-93494 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-93494 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-93558 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-93558 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-93558 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-93560 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-93560 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-93560 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-93562 ( SUSE ): 6.9
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
* CVE-2026-93562 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
* CVE-2026-93562 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
* CVE-2026-93563 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-93563 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-93563 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-93564 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-93564 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-93564 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-93565 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-93565 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-93565 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-93566 ( SUSE ): 6.9
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
* CVE-2026-93566 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
* CVE-2026-93566 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
* CVE-2026-93567 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-93567 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-93567 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-93568 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-93568 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-93568 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-93569 ( SUSE ): 8.8
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-93569 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N
* CVE-2026-93569 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N
* CVE-2026-93572 ( SUSE ): 7.1
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-93572 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-93572 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-93573 ( SUSE ): 6.9
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
* CVE-2026-93573 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
* CVE-2026-93573 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
* CVE-2026-93574 ( SUSE ): 6.9
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N
* CVE-2026-93574 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
* CVE-2026-93574 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
* CVE-2026-93575 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-93575 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-93575 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-93576 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-93576 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-93576 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-93578 ( SUSE ): 9.1
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-93578 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
* CVE-2026-93578 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-93579 ( SUSE ): 6.9
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
* CVE-2026-93579 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
* CVE-2026-93579 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Affected Products:
* Development Tools Module 15-SP7
* SUSE Linux Enterprise Desktop 15 SP7
* SUSE Linux Enterprise High Performance Computing 15 SP4
* SUSE Linux Enterprise High Performance Computing 15 SP5
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5
* SUSE Linux Enterprise Real Time 15 SP7
* SUSE Linux Enterprise Server 15 SP4
* SUSE Linux Enterprise Server 15 SP4 LTSS
* SUSE Linux Enterprise Server 15 SP5
* SUSE Linux Enterprise Server 15 SP5 LTSS
* SUSE Linux Enterprise Server 15 SP6
* SUSE Linux Enterprise Server 15 SP6 LTSS
* SUSE Linux Enterprise Server 15 SP7
* SUSE Linux Enterprise Server for SAP Applications 15 SP4
* SUSE Linux Enterprise Server for SAP Applications 15 SP5
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
* SUSE Linux Enterprise Server for SAP Applications 15 SP7
* SUSE Package Hub 15 15-SP7
An update that solves 30 vulnerabilities can now be installed.
## Description:
This update for netty, netty-tcnative fixes the following issues:
* CVE-2026-59902: Netty: Memory Exhaustion in SctpMessageCompletionHandler
(bsc#1275501).
* CVE-2026-59903: Netty Vulnerable to Cache Poisoning and Information
Disclosure via CORS Vary Header Overwrite (bsc#1275500).
* CVE-2026-62243: TLS hostname verification bypass in Netty OpenSSL client
path (bsc#1276455).
* CVE-2026-62380: null byte and CRLF injection in Socks4ClientEncoder and
Socks5ClientEncoder (bsc#1276456).
* CVE-2026-75595: fragmented TLS `ClientHello` causes fallback to default
`SslContext` and allows for SNI routing and mTLS requirement bypass
(bsc#1276420).
* CVE-2026-75596: fragmented `ClientHello`records can trigger quadratic pre-
handshake reassembly in default SNI parsing (bsc#1276421).
* CVE-2026-76816: missing input validation in `MqttEncoder` allows for null-
byte injection, topic hijacking, and ACL bypassing (bsc#1277243).
* CVE-2026-89044: HTTP request smuggling in Netty via improper validation of
final Transfer-Encoding coding (bsc#1280048).
* CVE-2026-93488: Denial of Service via unbounded concurrent SPDY streams
(bsc#1282084).
* CVE-2026-93491: Denial of Service via unbounded HttpServerCodec HTTP/1.1
pipeline queue (bsc#1282085).
* CVE-2026-93492: HTTP/2 HpackEncoder DoS with large table size (bsc#1282132).
* CVE-2026-93493: missing `nextUpdate` field in OCSP responses leads to silent
validation bypass (bsc#1281431).
* CVE-2026-93494: ByteBuf Leak in StompSubframeDecoder When a Frame Body Is
Never Terminated (bsc#1282506).
* CVE-2026-93558: Unbounded Per-Connection Queue Growth in
WebSocketServerExtensionHandler Leads to Denial of Service (bsc#1282140).
* CVE-2026-93560: STOMP codec content-length long-to-int truncation causes
infinite decode loop DoS (bsc#1282141).
* CVE-2026-93562: Incomplete validation of malformed Transfer-Encoding allows
HTTP request smuggling (bsc#1282362).
* CVE-2026-93563: unbounded multi-line response accumulation in
`SmtpResponseDecoder` leads to memory exhaustion and a DoS (bsc#1281432).
* CVE-2026-93564: HAProxy PROXY-v2 nested-TLV grandchild ByteBuf reference-
count leak (bsc#1282363).
* CVE-2026-93565: RtspDecoder Method-Token Smuggling via Trailing Control Byte
(bsc#1282364).
* CVE-2026-93566: HTTP Request Smuggling due to control characters in the
chunk-size line (bsc#1282366).
* CVE-2026-93567: HTTP/1 authority-form CONNECT is translated to malformed
HTTP/2 CONNECT with Host-controlled :authority (bsc#1282367).
* CVE-2026-93568: HTTP/2 and HTTP/3 Extended CONNECT requests are downgraded
as regular CONNECT requests (bsc#1282370).
* CVE-2026-93569: HTTP/1 absolute-form Host mismatch is translated to HTTP/2
:authority, overriding the request-target authority (bsc#1282372).
* CVE-2026-93572: multiplication of patched preallocation limits in
`RedisArrayAggregator` nested RESP headers can lead to denial of service
(bsc#1281433).
* CVE-2026-93573: Incomplete validation of malformed Transfer-Encoding allows
HTTP request smuggling (bsc#1282373).
* CVE-2026-93574: HTTP request smuggling via post-digit whitespace in chunk-
size parsing (bsc#1282374).
* CVE-2026-93575: missing validations in the `MqttDecoder` can lead to
excessive resource consumption and a DoS (bsc#1281434).
* CVE-2026-93576: netty-codec-smtp -- SMTP command-name field is not CRLF-
validated (bsc#1282507).
* CVE-2026-93578: missing Extended Key Usage (EKU) check in OCSP client allows
certificate revocation bypass (bsc#1281435).
* CVE-2026-93579: HTTP/2 header field values are not validated by default
(bsc#1282378).
Changes for netty:
* Upgrade to upstream version 4.1.138
Changes for netty-tcnative:
* Upgrade to version 2.0.84 Final
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Linux Enterprise Server for SAP Applications 15 SP4
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-4391
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4
zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-4391
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4
zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-4391
* SUSE Linux Enterprise Server for SAP Applications 15 SP5
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-4391
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5
zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-4391
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5
zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-4391
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-4391
* SUSE Linux Enterprise Server 15 SP4 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-4391
* Development Tools Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP7-2026-4391
* SUSE Package Hub 15 15-SP7
zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-4391
* SUSE Linux Enterprise Server 15 SP5 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-4391
* SUSE Linux Enterprise Server 15 SP6 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-4391
## Package List:
* SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64)
* netty-tcnative-2.0.84-150200.3.51.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64
x86_64)
* netty-tcnative-2.0.84-150200.3.51.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64
x86_64)
* netty-tcnative-2.0.84-150200.3.51.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64)
* netty-tcnative-2.0.84-150200.3.51.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64
x86_64)
* netty-tcnative-2.0.84-150200.3.51.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64
x86_64)
* netty-tcnative-2.0.84-150200.3.51.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64)
* netty-tcnative-2.0.84-150200.3.51.1
* SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64)
* netty-tcnative-2.0.84-150200.3.51.1
* Development Tools Module 15-SP7 (aarch64 ppc64le s390x x86_64)
* netty-tcnative-debugsource-2.0.84-150200.3.51.1
* netty-tcnative-2.0.84-150200.3.51.1
* SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x x86_64)
* netty-4.1.138-150200.4.56.1
* SUSE Package Hub 15 15-SP7 (noarch)
* netty-javadoc-4.1.138-150200.4.56.1
* SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64)
* netty-tcnative-2.0.84-150200.3.51.1
* SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64)
* netty-tcnative-2.0.84-150200.3.51.1
## References:
* https://www.suse.com/security/cve/CVE-2026-59902.html
* https://www.suse.com/security/cve/CVE-2026-59903.html
* https://www.suse.com/security/cve/CVE-2026-62243.html
* https://www.suse.com/security/cve/CVE-2026-62380.html
* https://www.suse.com/security/cve/CVE-2026-75595.html
* https://www.suse.com/security/cve/CVE-2026-75596.html
* https://www.suse.com/security/cve/CVE-2026-76816.html
* https://www.suse.com/security/cve/CVE-2026-89044.html
* https://www.suse.com/security/cve/CVE-2026-93488.html
* https://www.suse.com/security/cve/CVE-2026-93491.html
* https://www.suse.com/security/cve/CVE-2026-93492.html
* https://www.suse.com/security/cve/CVE-2026-93493.html
* https://www.suse.com/security/cve/CVE-2026-93494.html
* https://www.suse.com/security/cve/CVE-2026-93558.html
* https://www.suse.com/security/cve/CVE-2026-93560.html
* https://www.suse.com/security/cve/CVE-2026-93562.html
* https://www.suse.com/security/cve/CVE-2026-93563.html
* https://www.suse.com/security/cve/CVE-2026-93564.html
* https://www.suse.com/security/cve/CVE-2026-93565.html
* https://www.suse.com/security/cve/CVE-2026-93566.html
* https://www.suse.com/security/cve/CVE-2026-93567.html
* https://www.suse.com/security/cve/CVE-2026-93568.html
* https://www.suse.com/security/cve/CVE-2026-93569.html
* https://www.suse.com/security/cve/CVE-2026-93572.html
* https://www.suse.com/security/cve/CVE-2026-93573.html
* https://www.suse.com/security/cve/CVE-2026-93574.html
* https://www.suse.com/security/cve/CVE-2026-93575.html
* https://www.suse.com/security/cve/CVE-2026-93576.html
* https://www.suse.com/security/cve/CVE-2026-93578.html
* https://www.suse.com/security/cve/CVE-2026-93579.html
* https://bugzilla.suse.com/show_bug.cgi?id=1275500
* https://bugzilla.suse.com/show_bug.cgi?id=1275501
* https://bugzilla.suse.com/show_bug.cgi?id=1276420
* https://bugzilla.suse.com/show_bug.cgi?id=1276421
* https://bugzilla.suse.com/show_bug.cgi?id=1276455
* https://bugzilla.suse.com/show_bug.cgi?id=1276456
* https://bugzilla.suse.com/show_bug.cgi?id=1277243
* https://bugzilla.suse.com/show_bug.cgi?id=1280048
* https://bugzilla.suse.com/show_bug.cgi?id=1281431
* https://bugzilla.suse.com/show_bug.cgi?id=1281432
* https://bugzilla.suse.com/show_bug.cgi?id=1281433
* https://bugzilla.suse.com/show_bug.cgi?id=1281434
* https://bugzilla.suse.com/show_bug.cgi?id=1281435
* https://bugzilla.suse.com/show_bug.cgi?id=1282084
* https://bugzilla.suse.com/show_bug.cgi?id=1282085
* https://bugzilla.suse.com/show_bug.cgi?id=1282132
* https://bugzilla.suse.com/show_bug.cgi?id=1282140
* https://bugzilla.suse.com/show_bug.cgi?id=1282141
* https://bugzilla.suse.com/show_bug.cgi?id=1282362
* https://bugzilla.suse.com/show_bug.cgi?id=1282363
* https://bugzilla.suse.com/show_bug.cgi?id=1282364
* https://bugzilla.suse.com/show_bug.cgi?id=1282366
* https://bugzilla.suse.com/show_bug.cgi?id=1282367
* https://bugzilla.suse.com/show_bug.cgi?id=1282370
* https://bugzilla.suse.com/show_bug.cgi?id=1282372
* https://bugzilla.suse.com/show_bug.cgi?id=1282373
* https://bugzilla.suse.com/show_bug.cgi?id=1282374
* https://bugzilla.suse.com/show_bug.cgi?id=1282378
* https://bugzilla.suse.com/show_bug.cgi?id=1282506
* https://bugzilla.suse.com/show_bug.cgi?id=1282507
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.suse.com/pipermail/sle-security-updates/attachments/20260929/dee32974/attachment.htm>
More information about the sle-security-updates
mailing list