CVE-2025-24970 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

Netty, an asynchronous, event-driven network application framework, has a vulnerability starting in version 4.1.91.Final and prior to version 4.1.118.Final. Whe…
High CVSS: 7.5

CVE-2025-24970

Netty, an asynchronous, event-driven network application framework, has a vulnerability starting in version 4.1.91.Final and prior to version 4.1.118.Final. When a special crafted packet is received via SslHandler it doesn't correctly handle validation of such a packet in all cases which can lead to a native crash. Version 4.1.118.Final contains a patch. As workaround its possible to either disable the usage of the native SSLEngine or change the code manually.
Vendor
Netty
Product
Netty
CWE
CWE-20
Yayın Tarihi
2025-02-10 22:15:38
Güncelleme
2025-09-05 17:20:12
Source Identifier
security-advisories@github.com
KEV Date Added
-

Kategoriler

Referanslar