[OpenNMS/opennms] 5a4f39: NMS-20168: Update Netty to 4.1.136.Final
Marshall Massengill via opennms-cvs <[email protected]>
| Newsgroups | gmane.network.opennms.cvs |
|---|---|
| Message-ID | <OpenNMS/opennms/push/refs/heads/mm/NMS-20168-smoke/[email protected]> |
Branch: refs/heads/mm/NMS-20168-smoke
Home: https://github.com/OpenNMS/opennms
Commit: 5a4f39fd7b634011c6a0882dd27f13d17b624d70
https://github.com/OpenNMS/opennms/commit/5a4f39fd7b634011c6a0882dd27f13d17b624d70
Author: Marshall Massengill <[email protected]>
Date: 2026-08-05 (Wed, 05 Aug 2026)
Changed paths:
M pom.xml
M smoke-test/pom.xml
Log Message:
-----------
NMS-20168: Update Netty to 4.1.136.Final
NMS-20164 locked the Camel and Newts Karaf feature descriptors to
netty4Version, which was 4.1.100.Final. That cleared everything through
2023 but left the 2026 advisories open.
4.1.136.Final closes CVE-2026-45674 and CVE-2026-47691, DNS cache
poisoning in netty-resolver-dns from missing bailiwick validation on
CNAME and NS records. Those two are the only reachable ones:
NettyDnsResolver backs the reverse-DNS enrichment that telemetryd's
netflow, sflow and BMP parsers perform on received flow records.
CVE-2026-33871, CVE-2026-48006, CVE-2026-48059 and CVE-2026-55851 are
covered as well, though their modules (netty-codec-http2,
netty-codec-redis, netty-codec-haproxy) ship in no installed feature.
smoke-test/pom.xml carries a separate netty4Version for its netty-bom
import and moves from 4.1.99.Final.
To unsubscribe from these emails, change your notification settings at https://github.com/OpenNMS/opennms/settings/notifications
_______________________________________________
Please read the OpenNMS Mailing List FAQ:
http://www.opennms.org/wiki/index.php?page=MailingListFaq
opennms-cvs mailing list
To *unsubscribe* or change your subscription options, see the bottom of this page:
https://lists.sourceforge.net/lists/listinfo/opennms-cvs