Kapil Shewate created CASSANDRA-21695:
-----------------------------------------
Summary: CVE-2026-75595.Netty is an asynchronous, event-driven
network application framework. Prior to 4.1.137.Fina and 4.2.17.Final,
io.netty.handler.ssl.SslClientHelloHandler#decode checks the wrong offset
before reading the four-byte TLS handshake header
Key: CASSANDRA-21695
URL: https://issues.apache.org/jira/browse/CASSANDRA-21695
Project: Apache Cassandra
Issue Type: Bug
Reporter: Kapil Shewate
Netty is an asynchronous, event-driven network application framework. Prior to
4.1.137.Fina and 4.2.17.Final,
io.netty.handler.ssl.SslClientHelloHandler#decode checks the wrong offset
before reading the four-byte TLS handshake header, so a ClientHello whose
handshake header spans records can cause an IndexOutOfBoundsException and
invoke select(ctx, null). This selects the default SslContext instead of the
SNI-specific context. In deployments where per-SNI clientAuth=REQUIRE is the
sole mutual TLS gate, the default SslContext uses clientAuth=NONE or
clientAuth=OPTIONAL, and no application-layer certificate verification exists,
an unauthenticated remote attacker can bypass the protected route's mutual TLS
requirement. This issue is fixed in versions 4.1.137.Final and 4.2.17.Final.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]