{"id":"UBUNTU-CVE-2026-47321","details":"The CompressionFilter class uses ZLib to deflate and inflate data sent and received. When we inflate incoming data, the filter does not control the resulting size, and create a buffer no matter what. Some compressed data may have a compression ration greater than 1 thousand, leading to an exhaustion of the application memory, as we don't control the deflated size. The fix adds such a control by allowing the application developer to provide a fixed size limit, which when reached throws an exception. It also allows the user to provide a compression ratio that should not be exceeded, protected the application from small inflated files that inflate in gigantic files, but with a grace limit for the resulting size (1Mb) to avoid false positive (like a very small file inflating with a high ratio, but resulting with a acceptable size, like a few thousands bytes) For application using this feature, it is highly recommended to create the CompressionFilter and to pass the maximum limit as a forth constructor parameter, maxDecompressedSize: public CompressionFilter(final boolean compressInbound, final boolean compressOutbound, final int compressionLevel, final int maxDecompressedSize)Optionally one can also provide a maxDecompressRatio fifth parameter, and a decompressRatioMinSize sixth parameter to allow small inflated files with a high compression ratio to still be accepted. Here are the additional constructor: public CompressionFilter(final boolean compressInbound, final boolean compressOutbound,             final int compressionLevel, final int maxDecompressedSize,             final long maxDecompressRatio, final long decompressRatioMinSize) Also note that a fluent API has been added to spare the users the pain to call a constructor with that many parameters:  CompressionFilter compressionFilter = new CompressionFilter() .setCompressionLevel(Zlib.COMPRESSION_MAX) .setMaxDecompressedSize(1_000_000) .setMaxDecompressRatio(100). .setDecompressRatioMinSize(100_000); Applications using Apache MINA are advised to upgrade and configure their CompressionFilter instance.","modified":"2026-09-24T02:00:33.598092885Z","published":"2026-09-21T08:16:00Z","upstream":["CVE-2026-47321"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-47321"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2026-47321"},{"type":"REPORT","url":"https://lists.apache.org/thread/y7xj1bl8qo47p9bktb11hg5v6k1d4dyj"}],"affected":[{"package":{"name":"mina","ecosystem":"Ubuntu:16.04:LTS","purl":"pkg:deb/ubuntu/mina?arch=source&distro=xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.1.7.dfsg-11"],"ecosystem_specific":{"binaries":[{"binary_version":"1.1.7.dfsg-11","binary_name":"libmina-java"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-47321.json"}},{"package":{"name":"mina2","ecosystem":"Ubuntu:16.04:LTS","purl":"pkg:deb/ubuntu/mina2?arch=source&distro=xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.0.7+dfsg-2","2.0.9-1","2.0.9-2"],"ecosystem_specific":{"binaries":[{"binary_name":"libmina2-java","binary_version":"2.0.9-2"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-47321.json"}},{"package":{"name":"mina","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/mina?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.1.7.dfsg-11","1.1.7.dfsg-12"],"ecosystem_specific":{"binaries":[{"binary_version":"1.1.7.dfsg-12","binary_name":"libmina-java"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-47321.json"}},{"package":{"name":"mina2","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/mina2?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.0.16-2"],"ecosystem_specific":{"binaries":[{"binary_name":"libmina2-java","binary_version":"2.0.16-2"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-47321.json"}},{"package":{"name":"mina","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/mina?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.1.7.dfsg-13"],"ecosystem_specific":{"binaries":[{"binary_name":"libmina-java","binary_version":"1.1.7.dfsg-13"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-47321.json"}},{"package":{"name":"mina2","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/mina2?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.0.19-2"],"ecosystem_specific":{"binaries":[{"binary_name":"libmina2-java","binary_version":"2.0.19-2"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-47321.json"}},{"package":{"name":"mina","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/mina?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.1.7.dfsg-13"],"ecosystem_specific":{"binaries":[{"binary_version":"1.1.7.dfsg-13","binary_name":"libmina-java"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-47321.json"}},{"package":{"name":"mina2","ecosystem":"Ubuntu:Pro:22.04:LTS","purl":"pkg:deb/ubuntu/mina2?arch=source&distro=esm-apps%2Fjammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.1.4-2","2.1.5-1","2.1.5-1ubuntu0.1~esm1"],"ecosystem_specific":{"binaries":[{"binary_name":"libmina2-java","binary_version":"2.1.5-1ubuntu0.1~esm1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-47321.json"}},{"package":{"name":"mina","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/mina?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.1.7.dfsg-13","1.1.7.dfsg-13ubuntu1"],"ecosystem_specific":{"binaries":[{"binary_version":"1.1.7.dfsg-13ubuntu1","binary_name":"libmina-java"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-47321.json"}},{"package":{"name":"mina2","ecosystem":"Ubuntu:Pro:24.04:LTS","purl":"pkg:deb/ubuntu/mina2?arch=source&distro=esm-apps%2Fnoble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.2.1-3","2.2.1-3ubuntu0.1~esm1"],"ecosystem_specific":{"binaries":[{"binary_name":"libmina2-java","binary_version":"2.2.1-3ubuntu0.1~esm1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-47321.json"}},{"package":{"name":"mina2","ecosystem":"Ubuntu:25.10","purl":"pkg:deb/ubuntu/mina2?arch=source&distro=questing"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.2.1-3","2.2.1-4"],"ecosystem_specific":{"binaries":[{"binary_version":"2.2.1-4","binary_name":"libmina2-java"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-47321.json"}},{"package":{"name":"mina2","ecosystem":"Ubuntu:Pro:26.04:LTS","purl":"pkg:deb/ubuntu/mina2?arch=source&distro=esm-apps%2Fresolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.2.1-4","2.2.1-4ubuntu0.1~esm1"],"ecosystem_specific":{"binaries":[{"binary_version":"2.2.1-4ubuntu0.1~esm1","binary_name":"libmina2-java"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-47321.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},{"type":"Ubuntu","score":"medium"}]}