From 2fb84e05807ea3a495a3df22c2fe91b43e101382 Mon Sep 17 00:00:00 2001 From: L1nq0 Date: Mon, 14 Sep 2026 19:54:38 +0800 Subject: [PATCH] Documented the object serialization format change introduced in 2.2.8 --- .../java/org/apache/mina/core/buffer/IoBuffer.java | 12 ++++++++++++ 1 file changed, 12 insertions(+) diff --git a/mina-core/src/main/java/org/apache/mina/core/buffer/IoBuffer.java b/mina-core/src/main/java/org/apache/mina/core/buffer/IoBuffer.java index b68f10824..583f92c9b 100644 --- a/mina-core/src/main/java/org/apache/mina/core/buffer/IoBuffer.java +++ b/mina-core/src/main/java/org/apache/mina/core/buffer/IoBuffer.java @@ -1711,6 +1711,9 @@ public abstract IoBuffer putPrefixedString(CharSequence val, int prefixLength, i /** * Reads a Java object from the buffer using the context {@link ClassLoader} of * the current thread. + *

+ * See {@link #putObject(Object)} for how the serialized form differs + * across MINA versions. * * @return The read Object * @throws ClassNotFoundException thrown when we can't find the Class to use @@ -1719,6 +1722,9 @@ public abstract IoBuffer putPrefixedString(CharSequence val, int prefixLength, i /** * Reads a Java object from the buffer using the specified classLoader. + *

+ * See {@link #putObject(Object)} for how the serialized form differs + * across MINA versions. * * @param classLoader The classLoader to use to read an Object from the IoBuffer * @return The read Object @@ -1728,6 +1734,12 @@ public abstract IoBuffer putPrefixedString(CharSequence val, int prefixLength, i /** * Writes the specified Java object to the buffer. + *

+ * The serialized form of Serializable objects changed in MINA 2.2.8, as + * part of the CVE-2026-47065 fix: a stream produced by MINA 2.2.7 or + * earlier cannot be read by MINA 2.2.8 or later, and a stream produced by + * MINA 2.2.8 or later cannot be read by MINA 2.2.7 or earlier. Arrays and + * primitives are not affected. * * @param o The Object to write in the IoBuffer * @return The modified IoBuffer