Skip to content

[GHSA-h2qv-fj59-j46j] Add Netty HAProxy fix commit references - #9611

Open
TayfurYldz wants to merge 1 commit into
github:TayfurYldz/advisory-improvement-9611from
TayfurYldz:tayfuryldz-GHSA-h2qv-fj59-j46j
Open

TayfurYldz wants to merge 1 commit into
github:TayfurYldz/advisory-improvement-9611from
TayfurYldz:tayfuryldz-GHSA-h2qv-fj59-j46j

Conversation

@TayfurYldz

Copy link
Copy Markdown

Summary

Adds the upstream remediation commits for the Netty 4.1 and 4.2 release lines as FIX references for GHSA-h2qv-fj59-j46j.

Evidence

  • The advisory records 4.1.135.Final and 4.2.15.Final as the first patched versions.
  • Netty PR #16881 fixes the exact successful-parse nested PP2_TYPE_SSL leak described by the advisory by recursively releasing depth-2+ TLVs.
  • The 4.1 merge commit bd6214fe1c3bae1d42aad6e372657b5b2c1f5105 is an ancestor of netty-4.1.135.Final.
  • The equivalent 4.2 commit 270800e5d336913606493a562c8200ecf321a0c1 is an ancestor of netty-4.2.15.Final and changes the same HAProxyMessage release path.

No affected range, patched version, severity, CWE, package, or vulnerability-description metadata is changed.

Validation

  • JSON parse: pass
  • git diff --check: pass
  • One advisory file changed
  • No open competing PR for this GHSA immediately before submission

AI-assisted metadata curation based solely on already-public upstream history; no new vulnerability disclosure or exploit reproduction is claimed.

Copilot AI balanced review requested due to automatic review settings September 19, 2026 10:23

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@github-actions
github-actions Bot changed the base branch from main to TayfurYldz/advisory-improvement-9611 September 19, 2026 10:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants