[
https://issues.apache.org/jira/browse/HADOOP-18578?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17701731#comment-17701731
]
ASF GitHub Bot commented on HADOOP-18578:
-----------------------------------------
steveloughran commented on PR #5229:
URL: https://github.com/apache/hadoop/pull/5229#issuecomment-1473838489
@degant it won't be in the release about to ship (3.3.5) because if we kept
having to abort an RC to deal with a transient CVE we would never be able to
ship anything. And doing last-minute jar updates is how you get major
regressions in without noticing.
please review that RC and see if there are other issues which would stop you
upgrading.
```
The RC is available at:
https://dist.apache.org/repos/dist/dev/hadoop/hadoop-3.3.5-RC3/
The git tag is release-3.3.5-RC3, commit 706d88266ab
The maven artifacts are staged at
https://repository.apache.org/content/repositories/orgapachehadoop-1369/
You can find my public key at:
https://dist.apache.org/repos/dist/release/hadoop/common/KEYS
Change log
https://dist.apache.org/repos/dist/dev/hadoop/hadoop-3.3.5-RC3/CHANGELOG.md
Release notes
https://dist.apache.org/repos/dist/dev/hadoop/hadoop-3.3.5-RC3/RELEASENOTES.md
```
and helping get that netty upgrade into the release which comes after 3.3.5,
with testing, is always welcome
> Bump netty to the latest 4.1.86
> -------------------------------
>
> Key: HADOOP-18578
> URL: https://issues.apache.org/jira/browse/HADOOP-18578
> Project: Hadoop Common
> Issue Type: Task
> Components: build
> Affects Versions: 3.4.0, 3.2.4, 3.3.4
> Reporter: Donghyun Kim
> Priority: Major
> Labels: pull-request-available, transitive-cve
> Fix For: 3.4.0
>
>
> Netty 4.1.86 fixes the following vulnerabilities.
> * HAProxyMessageDecoder Stack Exhaustion DoS (CVE-2022-41881)
> * HTTP Response splitting from assigning header value iterator
> (CVE-2022-41915)
> For more details: https://netty.io/news/2022/12/12/4-1-86-Final.html
--
This message was sent by Atlassian Jira
(v8.20.10#820010)
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]