Missing Release of Resource after Effective Lifetime Affecting io.netty:netty-transport-classes-epoll package, versions [4.2.0.Alpha1,4.2.13.Final)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JAVA-IONETTY-16438936
  • published7 May 2026
  • disclosed6 May 2026
  • creditStormpx

Introduced: 6 May 2026

NewCVE-2026-42577  (opens in a new tab)
CWE-772  (opens in a new tab)

How to fix?

Upgrade io.netty:netty-transport-classes-epoll to version 4.2.13.Final or higher.

Overview

Affected versions of this package are vulnerable to Missing Release of Resource after Effective Lifetime in the handling of TCP connections with ALLOW_HALF_CLOSURE enabled when a remote peer sends a FIN followed by a RST. An attacker can cause resource exhaustion or high CPU utilization by repeatedly establishing such connections and triggering the described sequence, leading to stale channels that are never cleaned up and potential CPU busy-loops in the event loop thread.

Workaround

This vulnerability can be mitigated by configuring idle timeouts on connections to limit the lifetime of stale channels.

CVSS Base Scores

version 4.0
version 3.1