VDB
BDU%3A2025-03389
BDU%3A2025-03389
PUBLISHED
CVSS 7.800000190734863 HIGH
Уязвимость сетевого программного средства Netty, связанная с неправильной проверкой входных данных, позволяющая нарушителю вызвать отказ в обслуживании
Risk Scores
CVSS 2.0
7.800000190734863
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Novell Inc., Red Hat Inc., Сообщество свободного программного обеспечения, ООО «Ред Софт», Apache Software Foundation, Google Inc | openSUSE Tumbleweed, Red Hat AMQ Broker, Debian GNU/Linux, РЕД ОС (запись в едином реестре российских программ №3751), SUSE Linux Enterprise Server for SAP Applications, SUSE Enterprise Storage, Suse Linux Enterprise Server, SUSE Linux Enterprise High Performance Computing, OpenShift Serverless, Logging subsystem for Red Hat OpenShift, Red Hat build of Apache Camel for Quarkus, Suse Linux Enterprise Desktop, SUSE Linux Enterprise Module for Package Hub, OpenSUSE Leap, SUSE Linux Enterprise Module for Development Tools, Cryostat, Red Hat build of Apache Camel for Spring Boot, netty, Red Hat build of Quarkus, Red Hat AMQ Clients, Android Studio |
Timeline
- Mar 27, 2025 CVE Published
- Feb 10, 2026 CVE Updated
References
- https://redos.red-soft.ru/support/secure/ url
- https://github.com/netty/netty/commit/87f40725155b2f89adfde68c7732f97c153676c4_x0001_ url
- https://github.com/netty/netty/security/advisories/GHSA-4g8c-wm8x-jfhw url
- https://security-tracker.debian.org/tracker/CVE-2025-24970 url
- https://access.redhat.com/security/cve/cve-2025-24970 url
- https://www.suse.com/security/cve/CVE-2025-24970.html url
- https://www.vicarius.io/vsociety/posts/cve-2025-24970-netty-vulnerability-detection url
- http://repo.red-soft.ru/redos/7.3c/x86_64/updates/ advisory