Takanobu Asanuma created HADOOP-17955: -----------------------------------------
Summary: Bump netty to the latest 4.1.68 Key: HADOOP-17955 URL: https://issues.apache.org/jira/browse/HADOOP-17955 Project: Hadoop Common Issue Type: Task Environment: Netty 4.1.68 fixes the following vulnerabilities. * Bzip2Decoder doesn't allow setting size restrictions for decompressed data (#CVE-2021-37136) * SnappyFrameDecoder doesn't restrict chunk length any may buffer skippable chunks in an unnecessary way (#CVE-2021-37137) For more details: [https://netty.io/news/2021/09/09/4-1-68-Final.html] Reporter: Takanobu Asanuma Assignee: Takanobu Asanuma -- This message was sent by Atlassian Jira (v8.3.4#803005) --------------------------------------------------------------------- To unsubscribe, e-mail: common-dev-unsubscr...@hadoop.apache.org For additional commands, e-mail: common-dev-h...@hadoop.apache.org