SUSE-SU-2026:4391-1: important: Security update for netty, netty-tcnative

SLE-SECURITY-UPDATES null at suse.de
Tue Sep 29 17:23:05 UTC 2026


# Security update for netty, netty-tcnative

Announcement ID: SUSE-SU-2026:4391-1  
Release Date: 2026-09-29T11:47:42Z  
Rating: important  
References:

  * bsc#1275500
  * bsc#1275501
  * bsc#1276420
  * bsc#1276421
  * bsc#1276455
  * bsc#1276456
  * bsc#1277243
  * bsc#1280048
  * bsc#1281431
  * bsc#1281432
  * bsc#1281433
  * bsc#1281434
  * bsc#1281435
  * bsc#1282084
  * bsc#1282085
  * bsc#1282132
  * bsc#1282140
  * bsc#1282141
  * bsc#1282362
  * bsc#1282363
  * bsc#1282364
  * bsc#1282366
  * bsc#1282367
  * bsc#1282370
  * bsc#1282372
  * bsc#1282373
  * bsc#1282374
  * bsc#1282378
  * bsc#1282506
  * bsc#1282507

  
Cross-References:

  * CVE-2026-59902
  * CVE-2026-59903
  * CVE-2026-62243
  * CVE-2026-62380
  * CVE-2026-75595
  * CVE-2026-75596
  * CVE-2026-76816
  * CVE-2026-89044
  * CVE-2026-93488
  * CVE-2026-93491
  * CVE-2026-93492
  * CVE-2026-93493
  * CVE-2026-93494
  * CVE-2026-93558
  * CVE-2026-93560
  * CVE-2026-93562
  * CVE-2026-93563
  * CVE-2026-93564
  * CVE-2026-93565
  * CVE-2026-93566
  * CVE-2026-93567
  * CVE-2026-93568
  * CVE-2026-93569
  * CVE-2026-93572
  * CVE-2026-93573
  * CVE-2026-93574
  * CVE-2026-93575
  * CVE-2026-93576
  * CVE-2026-93578
  * CVE-2026-93579

  
CVSS scores:

  * CVE-2026-59902 ( SUSE ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-59902 ( NVD ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-59903 ( SUSE ):  6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N
  * CVE-2026-59903 ( NVD ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
  * CVE-2026-59903 ( NVD ):  6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N
  * CVE-2026-62243 ( SUSE ):  7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
  * CVE-2026-62243 ( NVD ):  8.7
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  * CVE-2026-62243 ( NVD ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
  * CVE-2026-62380 ( SUSE ):  5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
  * CVE-2026-62380 ( NVD ):  6.3
    CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  * CVE-2026-62380 ( NVD ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
  * CVE-2026-75595 ( SUSE ):  9.1
    CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
  * CVE-2026-75595 ( SUSE ):  7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
  * CVE-2026-75595 ( NVD ):  9.1
    CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  * CVE-2026-75595 ( NVD ):  9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
  * CVE-2026-75596 ( SUSE ):  8.7
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
  * CVE-2026-75596 ( SUSE ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-75596 ( NVD ):  8.7
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  * CVE-2026-75596 ( NVD ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-76816 ( SUSE ):  8.7
    CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N
  * CVE-2026-76816 ( SUSE ):  8.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
  * CVE-2026-76816 ( NVD ):  3.5 CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
  * CVE-2026-89044 ( SUSE ):  6.9
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
  * CVE-2026-89044 ( SUSE ):  6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
  * CVE-2026-89044 ( NVD ):  6.9
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  * CVE-2026-89044 ( NVD ):  6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
  * CVE-2026-93488 ( SUSE ):  8.7
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
  * CVE-2026-93488 ( SUSE ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-93488 ( NVD ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-93491 ( SUSE ):  8.7
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
  * CVE-2026-93491 ( SUSE ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-93491 ( NVD ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-93492 ( SUSE ):  6.9
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
  * CVE-2026-93492 ( SUSE ):  5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
  * CVE-2026-93492 ( NVD ):  5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
  * CVE-2026-93493 ( SUSE ):  9.1
    CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
  * CVE-2026-93493 ( SUSE ):  7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
  * CVE-2026-93493 ( NVD ):  5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
  * CVE-2026-93494 ( SUSE ):  6.9
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
  * CVE-2026-93494 ( SUSE ):  5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
  * CVE-2026-93494 ( NVD ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-93558 ( SUSE ):  8.7
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
  * CVE-2026-93558 ( SUSE ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-93558 ( NVD ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-93560 ( SUSE ):  8.7
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
  * CVE-2026-93560 ( SUSE ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-93560 ( NVD ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-93562 ( SUSE ):  6.9
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
  * CVE-2026-93562 ( SUSE ):  6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
  * CVE-2026-93562 ( NVD ):  6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
  * CVE-2026-93563 ( SUSE ):  8.7
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
  * CVE-2026-93563 ( SUSE ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-93563 ( NVD ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-93564 ( SUSE ):  8.7
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
  * CVE-2026-93564 ( SUSE ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-93564 ( NVD ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-93565 ( SUSE ):  8.7
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
  * CVE-2026-93565 ( SUSE ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
  * CVE-2026-93565 ( NVD ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
  * CVE-2026-93566 ( SUSE ):  6.9
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
  * CVE-2026-93566 ( SUSE ):  6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
  * CVE-2026-93566 ( NVD ):  6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
  * CVE-2026-93567 ( SUSE ):  8.7
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
  * CVE-2026-93567 ( SUSE ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
  * CVE-2026-93567 ( NVD ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
  * CVE-2026-93568 ( SUSE ):  8.7
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
  * CVE-2026-93568 ( SUSE ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
  * CVE-2026-93568 ( NVD ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
  * CVE-2026-93569 ( SUSE ):  8.8
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N
  * CVE-2026-93569 ( SUSE ):  8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N
  * CVE-2026-93569 ( NVD ):  8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N
  * CVE-2026-93572 ( SUSE ):  7.1
    CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
  * CVE-2026-93572 ( SUSE ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-93572 ( NVD ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-93573 ( SUSE ):  6.9
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
  * CVE-2026-93573 ( SUSE ):  6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
  * CVE-2026-93573 ( NVD ):  6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
  * CVE-2026-93574 ( SUSE ):  6.9
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N
  * CVE-2026-93574 ( SUSE ):  6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
  * CVE-2026-93574 ( NVD ):  6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
  * CVE-2026-93575 ( SUSE ):  8.7
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
  * CVE-2026-93575 ( SUSE ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-93575 ( NVD ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-93576 ( SUSE ):  8.7
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
  * CVE-2026-93576 ( SUSE ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
  * CVE-2026-93576 ( NVD ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
  * CVE-2026-93578 ( SUSE ):  9.1
    CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
  * CVE-2026-93578 ( SUSE ):  7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
  * CVE-2026-93578 ( NVD ):  5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
  * CVE-2026-93579 ( SUSE ):  6.9
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
  * CVE-2026-93579 ( SUSE ):  6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
  * CVE-2026-93579 ( NVD ):  6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

  
Affected Products:

  * Development Tools Module 15-SP7
  * SUSE Linux Enterprise Desktop 15 SP7
  * SUSE Linux Enterprise High Performance Computing 15 SP4
  * SUSE Linux Enterprise High Performance Computing 15 SP5
  * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4
  * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5
  * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4
  * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5
  * SUSE Linux Enterprise Real Time 15 SP7
  * SUSE Linux Enterprise Server 15 SP4
  * SUSE Linux Enterprise Server 15 SP4 LTSS
  * SUSE Linux Enterprise Server 15 SP5
  * SUSE Linux Enterprise Server 15 SP5 LTSS
  * SUSE Linux Enterprise Server 15 SP6
  * SUSE Linux Enterprise Server 15 SP6 LTSS
  * SUSE Linux Enterprise Server 15 SP7
  * SUSE Linux Enterprise Server for SAP Applications 15 SP4
  * SUSE Linux Enterprise Server for SAP Applications 15 SP5
  * SUSE Linux Enterprise Server for SAP Applications 15 SP6
  * SUSE Linux Enterprise Server for SAP Applications 15 SP7
  * SUSE Package Hub 15 15-SP7

  
  
An update that solves 30 vulnerabilities can now be installed.

## Description:

This update for netty, netty-tcnative fixes the following issues:

  * CVE-2026-59902: Netty: Memory Exhaustion in SctpMessageCompletionHandler
    (bsc#1275501).
  * CVE-2026-59903: Netty Vulnerable to Cache Poisoning and Information
    Disclosure via CORS Vary Header Overwrite (bsc#1275500).
  * CVE-2026-62243: TLS hostname verification bypass in Netty OpenSSL client
    path (bsc#1276455).
  * CVE-2026-62380: null byte and CRLF injection in Socks4ClientEncoder and
    Socks5ClientEncoder (bsc#1276456).
  * CVE-2026-75595: fragmented TLS `ClientHello` causes fallback to default
    `SslContext` and allows for SNI routing and mTLS requirement bypass
    (bsc#1276420).
  * CVE-2026-75596: fragmented `ClientHello`records can trigger quadratic pre-
    handshake reassembly in default SNI parsing (bsc#1276421).
  * CVE-2026-76816: missing input validation in `MqttEncoder` allows for null-
    byte injection, topic hijacking, and ACL bypassing (bsc#1277243).
  * CVE-2026-89044: HTTP request smuggling in Netty via improper validation of
    final Transfer-Encoding coding (bsc#1280048).
  * CVE-2026-93488: Denial of Service via unbounded concurrent SPDY streams
    (bsc#1282084).
  * CVE-2026-93491: Denial of Service via unbounded HttpServerCodec HTTP/1.1
    pipeline queue (bsc#1282085).
  * CVE-2026-93492: HTTP/2 HpackEncoder DoS with large table size (bsc#1282132).
  * CVE-2026-93493: missing `nextUpdate` field in OCSP responses leads to silent
    validation bypass (bsc#1281431).
  * CVE-2026-93494: ByteBuf Leak in StompSubframeDecoder When a Frame Body Is
    Never Terminated (bsc#1282506).
  * CVE-2026-93558: Unbounded Per-Connection Queue Growth in
    WebSocketServerExtensionHandler Leads to Denial of Service (bsc#1282140).
  * CVE-2026-93560: STOMP codec content-length long-to-int truncation causes
    infinite decode loop DoS (bsc#1282141).
  * CVE-2026-93562: Incomplete validation of malformed Transfer-Encoding allows
    HTTP request smuggling (bsc#1282362).
  * CVE-2026-93563: unbounded multi-line response accumulation in
    `SmtpResponseDecoder` leads to memory exhaustion and a DoS (bsc#1281432).
  * CVE-2026-93564: HAProxy PROXY-v2 nested-TLV grandchild ByteBuf reference-
    count leak (bsc#1282363).
  * CVE-2026-93565: RtspDecoder Method-Token Smuggling via Trailing Control Byte
    (bsc#1282364).
  * CVE-2026-93566: HTTP Request Smuggling due to control characters in the
    chunk-size line (bsc#1282366).
  * CVE-2026-93567: HTTP/1 authority-form CONNECT is translated to malformed
    HTTP/2 CONNECT with Host-controlled :authority (bsc#1282367).
  * CVE-2026-93568: HTTP/2 and HTTP/3 Extended CONNECT requests are downgraded
    as regular CONNECT requests (bsc#1282370).
  * CVE-2026-93569: HTTP/1 absolute-form Host mismatch is translated to HTTP/2
    :authority, overriding the request-target authority (bsc#1282372).
  * CVE-2026-93572: multiplication of patched preallocation limits in
    `RedisArrayAggregator` nested RESP headers can lead to denial of service
    (bsc#1281433).
  * CVE-2026-93573: Incomplete validation of malformed Transfer-Encoding allows
    HTTP request smuggling (bsc#1282373).
  * CVE-2026-93574: HTTP request smuggling via post-digit whitespace in chunk-
    size parsing (bsc#1282374).
  * CVE-2026-93575: missing validations in the `MqttDecoder` can lead to
    excessive resource consumption and a DoS (bsc#1281434).
  * CVE-2026-93576: netty-codec-smtp -- SMTP command-name field is not CRLF-
    validated (bsc#1282507).
  * CVE-2026-93578: missing Extended Key Usage (EKU) check in OCSP client allows
    certificate revocation bypass (bsc#1281435).
  * CVE-2026-93579: HTTP/2 header field values are not validated by default
    (bsc#1282378).

Changes for netty:

  * Upgrade to upstream version 4.1.138

Changes for netty-tcnative:

  * Upgrade to version 2.0.84 Final

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".  
Alternatively you can run the command listed for your product:

  * SUSE Linux Enterprise Server for SAP Applications 15 SP4  
    zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-4391

  * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4  
    zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-4391

  * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4  
    zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-4391

  * SUSE Linux Enterprise Server for SAP Applications 15 SP5  
    zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-4391

  * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5  
    zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-4391

  * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5  
    zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-4391

  * SUSE Linux Enterprise Server for SAP Applications 15 SP6  
    zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-4391

  * SUSE Linux Enterprise Server 15 SP4 LTSS  
    zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-4391

  * Development Tools Module 15-SP7  
    zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP7-2026-4391

  * SUSE Package Hub 15 15-SP7  
    zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-4391

  * SUSE Linux Enterprise Server 15 SP5 LTSS  
    zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-4391

  * SUSE Linux Enterprise Server 15 SP6 LTSS  
    zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-4391

## Package List:

  * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64)
    * netty-tcnative-2.0.84-150200.3.51.1
  * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64
    x86_64)
    * netty-tcnative-2.0.84-150200.3.51.1
  * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64
    x86_64)
    * netty-tcnative-2.0.84-150200.3.51.1
  * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64)
    * netty-tcnative-2.0.84-150200.3.51.1
  * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64
    x86_64)
    * netty-tcnative-2.0.84-150200.3.51.1
  * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64
    x86_64)
    * netty-tcnative-2.0.84-150200.3.51.1
  * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64)
    * netty-tcnative-2.0.84-150200.3.51.1
  * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64)
    * netty-tcnative-2.0.84-150200.3.51.1
  * Development Tools Module 15-SP7 (aarch64 ppc64le s390x x86_64)
    * netty-tcnative-debugsource-2.0.84-150200.3.51.1
    * netty-tcnative-2.0.84-150200.3.51.1
  * SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x x86_64)
    * netty-4.1.138-150200.4.56.1
  * SUSE Package Hub 15 15-SP7 (noarch)
    * netty-javadoc-4.1.138-150200.4.56.1
  * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64)
    * netty-tcnative-2.0.84-150200.3.51.1
  * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64)
    * netty-tcnative-2.0.84-150200.3.51.1

## References:

  * https://www.suse.com/security/cve/CVE-2026-59902.html
  * https://www.suse.com/security/cve/CVE-2026-59903.html
  * https://www.suse.com/security/cve/CVE-2026-62243.html
  * https://www.suse.com/security/cve/CVE-2026-62380.html
  * https://www.suse.com/security/cve/CVE-2026-75595.html
  * https://www.suse.com/security/cve/CVE-2026-75596.html
  * https://www.suse.com/security/cve/CVE-2026-76816.html
  * https://www.suse.com/security/cve/CVE-2026-89044.html
  * https://www.suse.com/security/cve/CVE-2026-93488.html
  * https://www.suse.com/security/cve/CVE-2026-93491.html
  * https://www.suse.com/security/cve/CVE-2026-93492.html
  * https://www.suse.com/security/cve/CVE-2026-93493.html
  * https://www.suse.com/security/cve/CVE-2026-93494.html
  * https://www.suse.com/security/cve/CVE-2026-93558.html
  * https://www.suse.com/security/cve/CVE-2026-93560.html
  * https://www.suse.com/security/cve/CVE-2026-93562.html
  * https://www.suse.com/security/cve/CVE-2026-93563.html
  * https://www.suse.com/security/cve/CVE-2026-93564.html
  * https://www.suse.com/security/cve/CVE-2026-93565.html
  * https://www.suse.com/security/cve/CVE-2026-93566.html
  * https://www.suse.com/security/cve/CVE-2026-93567.html
  * https://www.suse.com/security/cve/CVE-2026-93568.html
  * https://www.suse.com/security/cve/CVE-2026-93569.html
  * https://www.suse.com/security/cve/CVE-2026-93572.html
  * https://www.suse.com/security/cve/CVE-2026-93573.html
  * https://www.suse.com/security/cve/CVE-2026-93574.html
  * https://www.suse.com/security/cve/CVE-2026-93575.html
  * https://www.suse.com/security/cve/CVE-2026-93576.html
  * https://www.suse.com/security/cve/CVE-2026-93578.html
  * https://www.suse.com/security/cve/CVE-2026-93579.html
  * https://bugzilla.suse.com/show_bug.cgi?id=1275500
  * https://bugzilla.suse.com/show_bug.cgi?id=1275501
  * https://bugzilla.suse.com/show_bug.cgi?id=1276420
  * https://bugzilla.suse.com/show_bug.cgi?id=1276421
  * https://bugzilla.suse.com/show_bug.cgi?id=1276455
  * https://bugzilla.suse.com/show_bug.cgi?id=1276456
  * https://bugzilla.suse.com/show_bug.cgi?id=1277243
  * https://bugzilla.suse.com/show_bug.cgi?id=1280048
  * https://bugzilla.suse.com/show_bug.cgi?id=1281431
  * https://bugzilla.suse.com/show_bug.cgi?id=1281432
  * https://bugzilla.suse.com/show_bug.cgi?id=1281433
  * https://bugzilla.suse.com/show_bug.cgi?id=1281434
  * https://bugzilla.suse.com/show_bug.cgi?id=1281435
  * https://bugzilla.suse.com/show_bug.cgi?id=1282084
  * https://bugzilla.suse.com/show_bug.cgi?id=1282085
  * https://bugzilla.suse.com/show_bug.cgi?id=1282132
  * https://bugzilla.suse.com/show_bug.cgi?id=1282140
  * https://bugzilla.suse.com/show_bug.cgi?id=1282141
  * https://bugzilla.suse.com/show_bug.cgi?id=1282362
  * https://bugzilla.suse.com/show_bug.cgi?id=1282363
  * https://bugzilla.suse.com/show_bug.cgi?id=1282364
  * https://bugzilla.suse.com/show_bug.cgi?id=1282366
  * https://bugzilla.suse.com/show_bug.cgi?id=1282367
  * https://bugzilla.suse.com/show_bug.cgi?id=1282370
  * https://bugzilla.suse.com/show_bug.cgi?id=1282372
  * https://bugzilla.suse.com/show_bug.cgi?id=1282373
  * https://bugzilla.suse.com/show_bug.cgi?id=1282374
  * https://bugzilla.suse.com/show_bug.cgi?id=1282378
  * https://bugzilla.suse.com/show_bug.cgi?id=1282506
  * https://bugzilla.suse.com/show_bug.cgi?id=1282507

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.suse.com/pipermail/sle-security-updates/attachments/20260929/dee32974/attachment.htm>


More information about the sle-security-updates mailing list