CVE-2025-24970 - Netty SslHandler Native Crash Vulnerability
CVE ID : CVE-2025-24970 Published : Feb. 10, 2025, 10:15 p.m. | 2 hours, 29 minutes ago Description : Netty, an asynchronous, event-driven network application framework, has a vulnerability starting in version 4.1.91.Final and prior to version 4.1.118.Final. When a special crafted packet is received via SslHandler it doesn't correctly handle validation of such a packet in all cases which can lead to a native crash. Version 4.1.118.Final contains a patch. As workaround its possible to either disable the usage of the native SSLEngine or change the code manually. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
![CVE-2025-24970 - Netty SslHandler Native Crash Vulnerability](https://cdn.cvefeed.io/images/cvefeed.io-new.webp)
Published : Feb. 10, 2025, 10:15 p.m. | 2 hours, 29 minutes ago
Description : Netty, an asynchronous, event-driven network application framework, has a vulnerability starting in version 4.1.91.Final and prior to version 4.1.118.Final. When a special crafted packet is received via SslHandler it doesn't correctly handle validation of such a packet in all cases which can lead to a native crash. Version 4.1.118.Final contains a patch. As workaround its possible to either disable the usage of the native SSLEngine or change the code manually.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...