Netty, an asynchronous, event-driven network application framework, has a vulnerability starting in version 4.1.91.Final and prior to version 4.1.118.Final. When a special crafted packet is received via SslHandler it doesn't correctly handle validation of such a packet in all cases which can lead to a native crash. Version 4.1.118.Final contains a patch. As workaround its possible to either disable the usage of the native SSLEngine or change the code manually.
This issue has been addressed in the following products: Red Hat build of Quarkus 3.15.3.SP1 Via RHSA-2025:1885 https://access.redhat.com/errata/RHSA-2025:1885
This issue has been addressed in the following products: Red Hat build of Quarkus 3.8.6.SP3 Via RHSA-2025:1884 https://access.redhat.com/errata/RHSA-2025:1884
This issue has been addressed in the following products: Red Hat Build of Apache Camel 4.8 for Quarkus 3.15 Via RHSA-2025:2067 https://access.redhat.com/errata/RHSA-2025:2067
This issue has been addressed in the following products: Red Hat Data Grid Via RHSA-2025:2663 https://access.redhat.com/errata/RHSA-2025:2663
This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8 Via RHSA-2025:3357 https://access.redhat.com/errata/RHSA-2025:3357
This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform Via RHSA-2025:3358 https://access.redhat.com/errata/RHSA-2025:3358
This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform Via RHSA-2025:3467 https://access.redhat.com/errata/RHSA-2025:3467
This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7 Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 Via RHSA-2025:3465 https://access.redhat.com/errata/RHSA-2025:3465
This issue has been addressed in the following products: RHINT Camel-K 1.10.10 Via RHSA-2025:3540 https://access.redhat.com/errata/RHSA-2025:3540
This issue has been addressed in the following products: Red Hat build of Apache Camel 4.8.5 for Spring Boot Via RHSA-2025:3543 https://access.redhat.com/errata/RHSA-2025:3543
This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform Via RHSA-2025:4552 https://access.redhat.com/errata/RHSA-2025:4552
This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 Via RHSA-2025:4550 https://access.redhat.com/errata/RHSA-2025:4550
This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7 Via RHSA-2025:4548 https://access.redhat.com/errata/RHSA-2025:4548
This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 Via RHSA-2025:4549 https://access.redhat.com/errata/RHSA-2025:4549
This issue has been addressed in the following products: HawtIO HawtIO 4.2.0 Via RHSA-2025:8761 https://access.redhat.com/errata/RHSA-2025:8761