Executive brief
Netty is a popular networking framework used by many Java applications to handle internet traffic. A flaw in how it processes DNS records allows an attacker to send specially crafted requests that cause the application to leak memory. Over time, this memory exhaustion can lead to a complete service outage or significant performance degradation.
Technical details
A memory leak exists in Netty's DNS record decoder due to improper resource management during exception handling. When parsing a DNS record, the `AbstractDnsRecord` constructor or `DnsCodecUtil#decompressDomainName` may allocate or retain a `ByteBuf`. If the domain name contains characters violating IDNA rules or contains a null byte, an `IllegalArgumentException` is thrown before the buffer is assigned to a field for later release. Because the exception bypasses the standard release logic, the memory remains allocated. An unauthenticated remote attacker can exploit this by sending a stream of malicious DNS packets, leading to cumulative memory exhaustion and eventual Denial of Service. The issue is fixed in versions 4.1.136.Final and 4.2.16.Final.
Affected products
- Netty netty-codec-dns >= 4.2.0.Final, <= 4.2.15.Final; <= 4.1.135.Final
Timeline
- 2026-07-23: disclosed
- 2026-07-24: advisory: GitHub Advisory published