- What: Vulnerability in Netty leading to DNS cache poisoning
- Impact: Affects Ubuntu 24.04 LTS, can be exploited to facilitate cache poisoning attacks
Ubuntu Security Notices USN-8742-1 USN-8742-1: Netty vulnerability Publication date 10 September 2026 Overview Netty could be exposed to cache poisoning. Releases 24.04 LTS Open side navigation Close side navigation Packages Details Update instructions References Packages netty - event-driven asynchronous network application framework Details It was discovered that Netty incorrectly validates the bailiwick of NS records. An attacker could possibly use this issue to facilitate DNS cache poisoning attacks. It was discovered that Netty incorrectly validates the bailiwick of NS records. An attacker could possibly use this issue to facilitate DNS cache poisoning attacks. Update instructions In general, a standard system update will make all the necessary changes. Learn more about how to get the fixes. The problem can be corrected by updating your system to the following package versions: Ubuntu Release Package Version 24.04 LTS noble libnetty-java – 1:4.1.48-9ubuntu0.2+esm2 Ubuntu Pro Fix available with Ubuntu Pro via ESM Apps. A community fix might become publicly available in the future. Reduce your security exposure Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines. Get Ubuntu Pro References CVE-2026-47691 CVE-2026-47691