Executive brief
Netty is a popular software framework used to build high-performance network applications. A flaw in how it handles Unix domain sockets can allow a local attacker to cause a 'file descriptor leak,' which gradually consumes system resources. If left unchecked, this can lead to a denial-of-service condition where the application or the entire server becomes unable to open new connections or files.
Technical details
A vulnerability exists in the `netty_unix_socket_recvFd` function within Netty's native Epoll and KQueue transports. The implementation allocates a control message buffer sized for a single integer (24 bytes on 64-bit Linux). If a peer sends two file descriptors via SCM_RIGHTS, the kernel installs both into the process because the message fits the buffer without truncation. However, Netty's subsequent length check expects exactly one descriptor; when this check fails, the code skips the logic to read or close the descriptors, leading to a resource leak. This is reachable when using `DomainSocketChannel` with `DomainSocketReadMode.FILE_DESCRIPTORS` enabled. The issue is fixed in versions 4.1.135.Final and 4.2.15.Final.
Affected products
- Netty netty-transport-native-epoll < 4.1.135.Final, 4.2.0.Final - 4.2.14.Final
- Netty netty-transport-native-kqueue < 4.1.135.Final, 4.2.0.Final - 4.2.14.Final
Timeline
- 2026-06-02: patched: Fixes released in 4.1.135.Final and 4.2.15.Final
- 2026-06-05: advisory: GitHub Security Advisory GHSA-w573-9ffj-6ff9 published
- 2026-06-12: disclosed: CVE-2026-45536 published to NVD