CyberRota Analysis
AI-GeneratedThe vulnerability affects the Netty framework in Java, specifically in the SniHandler constructors prior to versions 4.1.137.Final and 4.2.17.Final. An unauthenticated remote attacker can exploit this flaw by sending a large ClientHello in numerous small records, leading to excessive CPU usage and performance degradation during TLS handshakes, which can impact other clients' connections. Organizations using affected versions of Netty should prioritize upgrading to the patched versions to mitigate this high-severity risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Final and 4.2.17.Final, the default io.netty.handler.ssl.SniHandler constructors use the pre-handshake ClientHello aggregation path in handler/src/main/java/io/netty/handler/ssl/SslClientHelloHandler.java at io.netty.handler.ssl.SslClientHelloHandler#decode, where handshakeBuffer.clear() and writeBytes() recopy all previously received body bytes for every additional TLS record. An unauthenticated remote peer can advertise a large ClientHello and deliver its body in thousands of tiny records, causing quadratic CPU work on the event loop before the TLS handshake completes and degrading TLS handling for other clients. This issue is fixed in versions 4.1.137.Final and 4.2.17.Final.