[
https://issues.apache.org/jira/browse/CASSANDRA-21695?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Kapil Shewate updated CASSANDRA-21695:
--------------------------------------
Severity: Critical
> CVE-2026-75595.Netty is an asynchronous, event-driven network application
> framework. Prior to 4.1.137.Fina and 4.2.17.Final,
> io.netty.handler.ssl.SslClientHelloHandler#decode checks the wrong offset
> before reading the four-byte TLS handshake header
> --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
>
> Key: CASSANDRA-21695
> URL: https://issues.apache.org/jira/browse/CASSANDRA-21695
> Project: Apache Cassandra
> Issue Type: Bug
> Reporter: Kapil Shewate
> Priority: Urgent
>
> Netty is an asynchronous, event-driven network application framework. Prior
> to 4.1.137.Fina and 4.2.17.Final,
> io.netty.handler.ssl.SslClientHelloHandler#decode checks the wrong offset
> before reading the four-byte TLS handshake header, so a ClientHello whose
> handshake header spans records can cause an IndexOutOfBoundsException and
> invoke select(ctx, null). This selects the default SslContext instead of the
> SNI-specific context. In deployments where per-SNI clientAuth=REQUIRE is the
> sole mutual TLS gate, the default SslContext uses clientAuth=NONE or
> clientAuth=OPTIONAL, and no application-layer certificate verification
> exists, an unauthenticated remote attacker can bypass the protected route's
> mutual TLS requirement. This issue is fixed in versions 4.1.137.Final and
> 4.2.17.Final.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]