Uploaded image for project: 'AMQ Streams Flink'
  1. AMQ Streams Flink
  2. ENTMQSTFL-256

Update netty in Flink

XMLWordPrintable

    • Icon: Task Task
    • Resolution: Unresolved
    • Icon: Major Major
    • 3.1.0.TP
    • 3.1.0.TP
    • flink
    • None

      Netty 4.1.100.Final is used directly in Flink and via Flink-Shaded 20.0. This version has several medium to high severity CVEs:

      • CVE-2024-29025
      • CVE-2024-47535
      • CVE-2025-25193
      • CVE-2025-24970

      Both the flink version of netty and the flink shaded version should be insync. Flink 2.1 uses Flink-Shaded 20.0 and we are unlikely to get a new shaded version out and 2.1 upgraded before release.

      However, we should upgrade upstream Flink master and flink-shaded to use the 4.1.118 version (newest 4.1.xxx release at time of writing). That should then be part of Flink-shaded 21.0 for future Flink release.

      Downstream we will need to patch our internal flink and flink-shaded 20.0 builds.

              Unassigned Unassigned
              rh-ee-tcooper Thomas Cooper (Inactive)
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

                Created:
                Updated: