Netty merged a fix for a concurrency flaw in its adaptive allocator after maintainers found that BuddyChunk.remainingCapacity() was mutating allocator state while reading it. The method drained entries from freeList without exclusive access, which could trigger racy updates to the buddies array and lead to rare assertion failures and allocator state corruption under concurrent use.
The patch changes BuddyChunk.remainingCapacity() to a non-mutating implementation that calculates free capacity by summing queue contents instead of consuming them, and adds a weakPeekReduce method to MpscIntQueue to support the new behavior. Netty also added a regression test that reproduced the bug before the fix and reported that the change eliminated buddies-array corruption; the update was merged into the 4.2 branch for inclusion in 4.2.14.Final, then ported to Netty 5.0 and cherry-picked into another branch.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
The day after the 4.2 merge, Netty auto-ported the fix to Netty 5.0 and cherry-picked it into another branch. This extended the concurrency bug fix beyond the initial 4.2 branch.
Netty merged pull request #16777 into the 5.0 branch, bringing the adaptive allocator concurrency fix to the 5.0.0.Final milestone. The change made BuddyChunk.remainingCapacity non-mutating, added weakPeekReduce on MpscIntQueue, and included a regression test for buddies-array corruption and assertion failures.
Netty merged the adaptive allocator concurrency fix into the 4.2 branch, targeting release in version 4.2.14.Final. The patch included a regression test that reproduced the issue before the fix and reportedly eliminated buddies-array corruption.
Netty opened pull request #16767 to fix a concurrency issue in the adaptive allocator where BuddyChunk.remainingCapacity() modified internal state without exclusive access, causing racy updates and rare assertion failures. The change replaced the modifying implementation with a non-mutating capacity calculation and added support via weakPeekReduce on MpscIntQueue.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
github.com
Open sourcegithub.com
Open sourceredirect.github.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.