Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-25193

Опубликовано: 10 фев. 2025
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

Netty, an asynchronous, event-driven network application framework, has a vulnerability in versions up to and including 4.1.118.Final. An unsafe reading of environment file could potentially cause a denial of service in Netty. When loaded on an Windows application, Netty attempts to load a file that does not exist. If an attacker creates such a large file, the Netty application crash. A similar issue was previously reported as CVE-2024-47535. This issue was fixed, but the fix was incomplete in that null-bytes were not counted against the input limit. Commit d1fbda62d3a47835d3fb35db8bd42ecc205a5386 contains an updated fix.

A flaw was found in Netty. An unsafe reading of the environment file could cause a denial of service. When loaded on a Windows application, Netty attempts to load a file that does not exist. If an attacker creates a large file, the Netty application crash.

Отчет

This issue only affects Windows environments, therefore, this would affect an environment when running a supported Red Hat JBoss EAP 7 or 8, for example, if running on Windows.

Меры по смягчению последствий

Currently, no mitigation is available for this vulnerability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat build of Quarkusnetty-commonNot affected
Red Hat Integration Camel K 1netty-commonWill not fix
Red Hat JBoss Enterprise Application Platform 7netty-commonFixedRHSA-2025:346701.04.2025
Red Hat JBoss Enterprise Application Platform 7.4.22FixedRHSA-2025:455206.05.2025
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8eap7-nettyFixedRHSA-2025:346501.04.2025
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8eap7-netty-transport-native-epollFixedRHSA-2025:346501.04.2025
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8eap7-wildflyFixedRHSA-2025:346501.04.2025
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8eap7-apache-commons-ioFixedRHSA-2025:454906.05.2025
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8eap7-hal-consoleFixedRHSA-2025:454906.05.2025
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8eap7-ironjacamarFixedRHSA-2025:454906.05.2025

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=2344788netty: Denial of Service attack on windows app using Netty

EPSS

Процентиль: 27%
0.00098
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
около 1 года назад

Netty, an asynchronous, event-driven network application framework, has a vulnerability in versions up to and including 4.1.118.Final. An unsafe reading of environment file could potentially cause a denial of service in Netty. When loaded on an Windows application, Netty attempts to load a file that does not exist. If an attacker creates such a large file, the Netty application crash. A similar issue was previously reported as CVE-2024-47535. This issue was fixed, but the fix was incomplete in that null-bytes were not counted against the input limit. Commit d1fbda62d3a47835d3fb35db8bd42ecc205a5386 contains an updated fix.

CVSS3: 5.5
nvd
около 1 года назад

Netty, an asynchronous, event-driven network application framework, has a vulnerability in versions up to and including 4.1.118.Final. An unsafe reading of environment file could potentially cause a denial of service in Netty. When loaded on an Windows application, Netty attempts to load a file that does not exist. If an attacker creates such a large file, the Netty application crash. A similar issue was previously reported as CVE-2024-47535. This issue was fixed, but the fix was incomplete in that null-bytes were not counted against the input limit. Commit d1fbda62d3a47835d3fb35db8bd42ecc205a5386 contains an updated fix.

CVSS3: 5.5
debian
около 1 года назад

Netty, an asynchronous, event-driven network application framework, ha ...

CVSS3: 5.5
github
около 1 года назад

Denial of Service attack on windows app using Netty

CVSS3: 5.5
fstec
около 1 года назад

Уязвимость функции BufferedReader.readLine() сетевого программного средства Netty, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 27%
0.00098
Низкий

5.5 Medium

CVSS3