Netty, an asynchronous, event-driven network application framework, has a vulnerability starting in version 4.1.91.Final and prior to version 4.1.118.Final. When a special crafted packet is received via SslHandler it doesn't correctly handle validation of such a packet in all cases which can lead to a native crash. Version 4.1.118.Final contains a patch. As workaround its possible to either disable the usage of the native SSLEngine or change the code manually.
History

Thu, 03 Apr 2025 03:15:00 +0000

Type Values Removed Values Added
First Time appeared Redhat apache Camel Spring Boot
Redhat camel K
CPEs cpe:/a:redhat:apache_camel_spring_boot:4.8.5
cpe:/a:redhat:camel_k:1.10.10
Vendors & Products Redhat apache Camel Spring Boot
Redhat camel K

Wed, 02 Apr 2025 03:15:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:jboss_enterprise_application_platform:7.4
cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el7
cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el8
cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el9

Fri, 28 Mar 2025 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Redhat jboss Enterprise Application Platform
CPEs cpe:/a:redhat:jboss_enterprise_application_platform:8.0
cpe:/a:redhat:jboss_enterprise_application_platform:8.0::el8
cpe:/a:redhat:jboss_enterprise_application_platform:8.0::el9
Vendors & Products Redhat jboss Enterprise Application Platform

Wed, 12 Mar 2025 07:00:00 +0000

Type Values Removed Values Added
First Time appeared Redhat jboss Data Grid
Redhat openshift Ai
CPEs cpe:/a:redhat:jboss_data_grid:8
cpe:/a:redhat:openshift_ai:2.18::el8
Vendors & Products Redhat jboss Data Grid
Redhat openshift Ai

Tue, 04 Mar 2025 03:00:00 +0000

Type Values Removed Values Added
First Time appeared Redhat camel Quarkus
CPEs cpe:/a:redhat:camel_quarkus:3.15
Vendors & Products Redhat camel Quarkus

Fri, 28 Feb 2025 03:00:00 +0000

Type Values Removed Values Added
First Time appeared Redhat
Redhat quarkus
CPEs cpe:/a:redhat:quarkus:3.15::el8
cpe:/a:redhat:quarkus:3.8::el8
Vendors & Products Redhat
Redhat quarkus

Fri, 21 Feb 2025 18:45:00 +0000

Type Values Removed Values Added
References

Tue, 11 Feb 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 11 Feb 2025 13:45:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Mon, 10 Feb 2025 22:15:00 +0000

Type Values Removed Values Added
Description Netty, an asynchronous, event-driven network application framework, has a vulnerability starting in version 4.1.91.Final and prior to version 4.1.118.Final. When a special crafted packet is received via SslHandler it doesn't correctly handle validation of such a packet in all cases which can lead to a native crash. Version 4.1.118.Final contains a patch. As workaround its possible to either disable the usage of the native SSLEngine or change the code manually.
Title SslHandler doesn't correctly validate packets which can lead to native crash when using native SSLEngine
Weaknesses CWE-20
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-02-21T18:03:37.212Z

Reserved: 2025-01-29T15:18:03.210Z

Link: CVE-2025-24970

cve-icon Vulnrichment

Updated: 2025-02-21T18:03:37.212Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-02-10T22:15:38.057

Modified: 2025-02-21T18:15:36.383

Link: CVE-2025-24970

cve-icon Redhat

Severity : Important

Publid Date: 2025-02-10T21:57:28Z

Links: CVE-2025-24970 - Bugzilla