netty / netty-tcnative

A fork of Apache Tomcat Native, based on finagle-native

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Is there CVE-2022-28331 vulnerability in netty-tcnative?

5tushar opened this issue · comments

CVE-2022-28331: On Windows, Apache Portable Runtime 1.7.0 and earlier may write beyond the end of a stack based buffer in apr_socket_sendv(). This is a result of integer overflow.

No we are not affected as we not use any socket functions provided by apr.