Bug 2344788 (CVE-2025-25193) - CVE-2025-25193 netty: Denial of Service attack on windows app using Netty
Summary: CVE-2025-25193 netty: Denial of Service attack on windows app using Netty
Keywords:
Status: NEW
Alias: CVE-2025-25193
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2025-02-10 23:01 UTC by OSIDB Bzimport
Modified: 2025-06-12 06:52 UTC (History)
43 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2025:3357 0 None None None 2025-03-27 16:40:31 UTC
Red Hat Product Errata RHSA-2025:3358 0 None None None 2025-03-27 16:47:14 UTC
Red Hat Product Errata RHSA-2025:3465 0 None None None 2025-04-01 13:10:13 UTC
Red Hat Product Errata RHSA-2025:3467 0 None None None 2025-04-01 13:07:00 UTC
Red Hat Product Errata RHSA-2025:4548 0 None None None 2025-05-06 14:30:35 UTC
Red Hat Product Errata RHSA-2025:4549 0 None None None 2025-05-06 14:31:07 UTC
Red Hat Product Errata RHSA-2025:4550 0 None None None 2025-05-06 14:30:07 UTC
Red Hat Product Errata RHSA-2025:4552 0 None None None 2025-05-06 14:28:22 UTC

Description OSIDB Bzimport 2025-02-10 23:01:17 UTC
Netty, an asynchronous, event-driven network application framework, has a vulnerability in versions up to and including 4.1.118.Final. An unsafe reading of environment file could potentially cause a denial of service in Netty. When loaded on an Windows application, Netty attempts to load a file that does not exist. If an attacker creates such a large file, the Netty application crash. A similar issue was previously reported as CVE-2024-47535. This issue was fixed, but the fix was incomplete in that null-bytes were not counted against the input limit. Commit d1fbda62d3a47835d3fb35db8bd42ecc205a5386 contains an updated fix.

Comment 1 errata-xmlrpc 2025-03-27 16:40:29 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9
  Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8

Via RHSA-2025:3357 https://access.redhat.com/errata/RHSA-2025:3357

Comment 2 errata-xmlrpc 2025-03-27 16:47:12 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform

Via RHSA-2025:3358 https://access.redhat.com/errata/RHSA-2025:3358

Comment 3 errata-xmlrpc 2025-04-01 13:06:58 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform

Via RHSA-2025:3467 https://access.redhat.com/errata/RHSA-2025:3467

Comment 4 errata-xmlrpc 2025-04-01 13:10:11 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7
  Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8
  Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9

Via RHSA-2025:3465 https://access.redhat.com/errata/RHSA-2025:3465

Comment 5 errata-xmlrpc 2025-05-06 14:28:19 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform

Via RHSA-2025:4552 https://access.redhat.com/errata/RHSA-2025:4552

Comment 6 errata-xmlrpc 2025-05-06 14:30:04 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9

Via RHSA-2025:4550 https://access.redhat.com/errata/RHSA-2025:4550

Comment 7 errata-xmlrpc 2025-05-06 14:30:32 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7

Via RHSA-2025:4548 https://access.redhat.com/errata/RHSA-2025:4548

Comment 8 errata-xmlrpc 2025-05-06 14:31:05 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8

Via RHSA-2025:4549 https://access.redhat.com/errata/RHSA-2025:4549


Note You need to log in before you can comment on or make changes to this bug.