Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-3996 | SslHandler doesn't correctly validate packets which can lead to native crash when using native SSLEngine |
Github GHSA |
GHSA-4g8c-wm8x-jfhw | SslHandler doesn't correctly validate packets which can lead to native crash when using native SSLEngine |
Fri, 05 Sep 2025 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Netapp
Netapp active Iq Unified Manager Netapp oncommand Insight Netty Netty netty |
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:linux:*:* cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:* cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:windows:*:* cpe:2.3:a:netapp:oncommand_insight:-:*:*:*:*:*:*:* cpe:2.3:a:netty:netty:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Netapp
Netapp active Iq Unified Manager Netapp oncommand Insight Netty Netty netty |
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 01 Jul 2025 02:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat amq Streams
|
|
| CPEs | cpe:/a:redhat:amq_streams:2.9::el9 | |
| Vendors & Products |
Redhat amq Streams
|
Wed, 11 Jun 2025 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat apache Camel Hawtio
|
|
| CPEs | cpe:/a:redhat:apache_camel_hawtio:4.2::el6 | |
| Vendors & Products |
Redhat rhboac Hawtio
|
Redhat apache Camel Hawtio
|
Tue, 10 Jun 2025 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat rhboac Hawtio
|
|
| CPEs | cpe:/a:redhat:rhboac_hawtio:4 | |
| Vendors & Products |
Redhat rhboac Hawtio
|
Tue, 03 Jun 2025 02:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/a:redhat:quarkus:3.20::el8 |
Wed, 16 Apr 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Thu, 03 Apr 2025 03:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat apache Camel Spring Boot
Redhat camel K |
|
| CPEs | cpe:/a:redhat:apache_camel_spring_boot:4.8.5 cpe:/a:redhat:camel_k:1.10.10 |
|
| Vendors & Products |
Redhat apache Camel Spring Boot
Redhat camel K |
Wed, 02 Apr 2025 03:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/a:redhat:jboss_enterprise_application_platform:7.4 cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el7 cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el8 cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el9 |
Fri, 28 Mar 2025 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat jboss Enterprise Application Platform
|
|
| CPEs | cpe:/a:redhat:jboss_enterprise_application_platform:8.0 cpe:/a:redhat:jboss_enterprise_application_platform:8.0::el8 cpe:/a:redhat:jboss_enterprise_application_platform:8.0::el9 |
|
| Vendors & Products |
Redhat jboss Enterprise Application Platform
|
Wed, 12 Mar 2025 07:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat jboss Data Grid
Redhat openshift Ai |
|
| CPEs | cpe:/a:redhat:jboss_data_grid:8 cpe:/a:redhat:openshift_ai:2.18::el8 |
|
| Vendors & Products |
Redhat jboss Data Grid
Redhat openshift Ai |
Tue, 04 Mar 2025 03:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat camel Quarkus
|
|
| CPEs | cpe:/a:redhat:camel_quarkus:3.15 | |
| Vendors & Products |
Redhat camel Quarkus
|
Fri, 28 Feb 2025 03:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat
Redhat quarkus |
|
| CPEs | cpe:/a:redhat:quarkus:3.15::el8 cpe:/a:redhat:quarkus:3.8::el8 |
|
| Vendors & Products |
Redhat
Redhat quarkus |
Fri, 21 Feb 2025 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 11 Feb 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 11 Feb 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Mon, 10 Feb 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Netty, an asynchronous, event-driven network application framework, has a vulnerability starting in version 4.1.91.Final and prior to version 4.1.118.Final. When a special crafted packet is received via SslHandler it doesn't correctly handle validation of such a packet in all cases which can lead to a native crash. Version 4.1.118.Final contains a patch. As workaround its possible to either disable the usage of the native SSLEngine or change the code manually. | |
| Title | SslHandler doesn't correctly validate packets which can lead to native crash when using native SSLEngine | |
| Weaknesses | CWE-20 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-04-16T15:37:17.191Z
Reserved: 2025-01-29T15:18:03.210Z
Link: CVE-2025-24970
Updated: 2025-04-16T15:37:17.191Z
Status : Analyzed
Published: 2025-02-10T22:15:38.057
Modified: 2025-09-05T17:20:12.260
Link: CVE-2025-24970
OpenCVE Enrichment
No data.
EUVD
Github GHSA