Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-3996 | SslHandler doesn't correctly validate packets which can lead to native crash when using native SSLEngine |
Github GHSA |
GHSA-4g8c-wm8x-jfhw | SslHandler doesn't correctly validate packets which can lead to native crash when using native SSLEngine |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Sat, 06 Sep 2025 02:30:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Netapp
Netapp active Iq Unified Manager Netapp oncommand Insight Netty Netty netty |
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:linux:*:* cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:* cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:windows:*:* cpe:2.3:a:netapp:oncommand_insight:-:*:*:*:*:*:*:* cpe:2.3:a:netty:netty:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Netapp
Netapp active Iq Unified Manager Netapp oncommand Insight Netty Netty netty |
Wed, 16 Jul 2025 22:45:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 01 Jul 2025 11:45:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat amq Streams
|
|
| CPEs | cpe:/a:redhat:amq_streams:2.9::el9 | |
| Vendors & Products |
Redhat amq Streams
|
Thu, 12 Jun 2025 00:00:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat apache Camel Hawtio
|
|
| CPEs | cpe:/a:redhat:apache_camel_hawtio:4.2::el6 | |
| Vendors & Products |
Redhat rhboac Hawtio
|
Redhat apache Camel Hawtio
|
Wed, 11 Jun 2025 04:00:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat rhboac Hawtio
|
|
| CPEs | cpe:/a:redhat:rhboac_hawtio:4 | |
| Vendors & Products |
Redhat rhboac Hawtio
|
Tue, 03 Jun 2025 11:45:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/a:redhat:quarkus:3.20::el8 |
Thu, 17 Apr 2025 01:45:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Thu, 03 Apr 2025 12:15:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat apache Camel Spring Boot
Redhat camel K |
|
| CPEs | cpe:/a:redhat:apache_camel_spring_boot:4.8.5 cpe:/a:redhat:camel_k:1.10.10 |
|
| Vendors & Products |
Redhat apache Camel Spring Boot
Redhat camel K |
Wed, 02 Apr 2025 12:15:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/a:redhat:jboss_enterprise_application_platform:7.4 cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el7 cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el8 cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el9 |
Sat, 29 Mar 2025 00:45:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat jboss Enterprise Application Platform
|
|
| CPEs | cpe:/a:redhat:jboss_enterprise_application_platform:8.0 cpe:/a:redhat:jboss_enterprise_application_platform:8.0::el8 cpe:/a:redhat:jboss_enterprise_application_platform:8.0::el9 |
|
| Vendors & Products |
Redhat jboss Enterprise Application Platform
|
Wed, 12 Mar 2025 16:00:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat jboss Data Grid
Redhat openshift Ai |
|
| CPEs | cpe:/a:redhat:jboss_data_grid:8 cpe:/a:redhat:openshift_ai:2.18::el8 |
|
| Vendors & Products |
Redhat jboss Data Grid
Redhat openshift Ai |
Tue, 04 Mar 2025 12:00:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat camel Quarkus
|
|
| CPEs | cpe:/a:redhat:camel_quarkus:3.15 | |
| Vendors & Products |
Redhat camel Quarkus
|
Fri, 28 Feb 2025 12:00:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat
Redhat quarkus |
|
| CPEs | cpe:/a:redhat:quarkus:3.15::el8 cpe:/a:redhat:quarkus:3.8::el8 |
|
| Vendors & Products |
Redhat
Redhat quarkus |
Sat, 22 Feb 2025 03:45:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 12 Feb 2025 01:15:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 11 Feb 2025 22:45:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Tue, 11 Feb 2025 07:15:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Netty, an asynchronous, event-driven network application framework, has a vulnerability starting in version 4.1.91.Final and prior to version 4.1.118.Final. When a special crafted packet is received via SslHandler it doesn't correctly handle validation of such a packet in all cases which can lead to a native crash. Version 4.1.118.Final contains a patch. As workaround its possible to either disable the usage of the native SSLEngine or change the code manually. | |
| Title | SslHandler doesn't correctly validate packets which can lead to native crash when using native SSLEngine | |
| Weaknesses | CWE-20 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-04-16T15:37:17.191Z
Reserved: 2025-01-29T15:18:03.210Z
Link: CVE-2025-24970
Updated: 2025-04-16T15:37:17.191Z
Status : Analyzed
Published: 2025-02-10T22:15:38.057
Modified: 2025-09-05T17:20:12.260
Link: CVE-2025-24970
OpenCVE Enrichment
No data.
EUVD
Github GHSA