{"id":"DEBIAN-CVE-2026-47321","details":"The CompressionFilter class uses ZLib to deflate and inflate data sent and received. When we inflate incoming data, the filter does not control the resulting size, and create a buffer no matter what.  Some compressed data may have a compression ration greater than 1 thousand, leading to an exhaustion of the application memory, as we don't control the deflated size.     The fix adds such a control by allowing the application developer to provide a fixed size limit, which when reached throws an exception. It also allows the user to provide a compression ratio that should not be exceeded, protected the application from small inflated files that inflate in gigantic files, but with a grace limit for the resulting size (1Mb) to avoid false positive (like a very small file inflating with a high ratio, but resulting with a acceptable size, like a few thousands bytes)     For application using this feature, it is highly recommended to create the CompressionFilter and to pass the maximum limit as a forth constructor parameter, maxDecompressedSize:     public CompressionFilter(final boolean compressInbound, final boolean compressOutbound, final int compressionLevel, final int maxDecompressedSize)Optionally one can also provide a maxDecompressRatio fifth parameter, and a decompressRatioMinSize sixth parameter to allow small inflated files with a high compression ratio to still be accepted.     Here are the additional constructor:       public CompressionFilter(final boolean compressInbound, final boolean compressOutbound,                final int compressionLevel, final int maxDecompressedSize,                final long maxDecompressRatio, final long decompressRatioMinSize)         Also note that a fluent API has been added to spare the users the pain to call a constructor with that many parameters:        CompressionFilter compressionFilter = new CompressionFilter()                                                  .setCompressionLevel(Zlib.COMPRESSION_MAX)                                                  .setMaxDecompressedSize(1_000_000)                                                  .setMaxDecompressRatio(100).                                                  .setDecompressRatioMinSize(100_000);           Applications using Apache MINA are advised to upgrade and configure their CompressionFilter instance.","modified":"2026-09-22T05:01:39.834447939Z","published":"2026-09-21T08:16:37.520Z","upstream":["CVE-2026-47321"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2026-47321"}],"affected":[{"package":{"name":"mina","ecosystem":"Debian:12","purl":"pkg:deb/debian/mina?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.1.7.dfsg-13","1.1.7.dfsg-14"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-47321.json"}},{"package":{"name":"mina2","ecosystem":"Debian:12","purl":"pkg:deb/debian/mina2?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.2.1-3","2.2.1-4","2.2.9-1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-47321.json"}},{"package":{"name":"mina2","ecosystem":"Debian:13","purl":"pkg:deb/debian/mina2?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.2.1-4","2.2.9-1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-47321.json"}},{"package":{"name":"mina2","ecosystem":"Debian:14","purl":"pkg:deb/debian/mina2?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.2.9-1"}]}],"versions":["2.2.1-4"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-47321.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}