VDB
RHSA-2025%3A3467
RHSA-2025%3A3467
PUBLISHED
CVSS 5.5 MEDIUM
A flaw was found in Netty. An unsafe reading of the environment file could potentially cause a denial of service. When loaded on a Windows application, Netty attempts to load a file that does not exist. If an attacker creates a large file, the Netty application crashes.
Risk Scores
CVSS 3.1
5.5
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat JBoss Enterprise Application Platform 7 |
Timeline
- Apr 1, 2025 CVE Published
- Apr 30, 2026 Distribution Patch
- Apr 30, 2026 Distribution Patch
- Apr 30, 2026 Security Advisory
- Apr 30, 2026 Security Advisory
- Apr 30, 2026 Security Advisory
- Apr 30, 2026 Security Advisory
- Apr 30, 2026 Security Advisory
- Apr 30, 2026 Security Advisory
- Apr 30, 2026 Security Advisory
- Apr 30, 2026 Security Advisory
- May 10, 2026 CVE Updated
References
- https://access.redhat.com/errata/RHSA-2025:3467 advisory
- https://access.redhat.com/security/updates/classification/#important advisory
- https://docs.redhat.com/en/documentation/red_hat_jboss_enterprise_application_platform/7.4 advisory
- https://docs.redhat.com/en/documentation/red_hat_jboss_enterprise_application_platform/7.4/html-single/installation_guide/index advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2323697 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2325538 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2337620 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2344787 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2344788 issue
- https://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_3467.json advisory
- https://access.redhat.com/security/cve/CVE-2024-47535 advisory
- https://www.cve.org/CVERecord?id=CVE-2024-47535 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-47535 advisory
- https://github.com/netty/netty/commit/fbf7a704a82e7449b48bd0bbb679f5661c6d61a3 advisory
- https://github.com/netty/netty/security/advisories/GHSA-xq3w-v528-46rv advisory
- https://access.redhat.com/security/cve/CVE-2024-51127 advisory
- https://www.cve.org/CVERecord?id=CVE-2024-51127 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-51127 advisory
- http://hornetq.com advisory
- https://github.com/JAckLosingHeart/CWE-378/blob/main/CVE-2024-51127.md advisory
…and 28 more