VDB
RHSA-2025%3A3467
RHSA-2025%3A3467
PUBLISHED
CVSS 5.5 MEDIUM
A flaw was found in Netty. An unsafe reading of the environment file could potentially cause a denial of service. When loaded on a Windows application, Netty attempts to load a file that does not exist. If an attacker creates a large file, the Netty application crashes.
Risk Scores
CVSS 3.1
5.5
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat JBoss Enterprise Application Platform 7 |
Timeline
- Apr 1, 2025 CVE Published
- Apr 30, 2026 Security Advisory
- Apr 30, 2026 Security Advisory
- Apr 30, 2026 Security Advisory
- Apr 30, 2026 Security Advisory
- May 10, 2026 CVE Updated
- May 11, 2026 Distribution Patch
- May 11, 2026 Distribution Patch
- May 11, 2026 Security Advisory
- May 11, 2026 Security Advisory
- May 11, 2026 Security Advisory
- May 11, 2026 Security Advisory
References
- https://docs.redhat.com/en/documentation/red_hat_jboss_enterprise_application_platform/7.4 advisory
- https://docs.redhat.com/en/documentation/red_hat_jboss_enterprise_application_platform/7.4/html-single/installation_guide/index advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2325538 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2337620 issue
- https://nvd.nist.gov/vuln/detail/CVE-2024-47535 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-23367 advisory
- https://github.com/advisories/GHSA-qr6x-62gq-4ccp advisory
- https://access.redhat.com/security/cve/CVE-2025-24970 advisory
- https://www.cve.org/CVERecord?id=CVE-2025-24970 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-24970 advisory
- https://github.com/netty/netty/security/advisories/GHSA-4g8c-wm8x-jfhw advisory
- https://www.cve.org/CVERecord?id=CVE-2025-25193 advisory
- https://github.com/netty/netty/commit/d1fbda62d3a47835d3fb35db8bd42ecc205a5386 advisory
- https://access.redhat.com/security/cve/CVE-2025-48734 advisory
- https://www.cve.org/CVERecord?id=CVE-2025-48734 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-48734 advisory
- https://github.com/apache/commons-beanutils/commit/28ad955a1613ed5885870cc7da52093c1ce739dc advisory
- https://lists.apache.org/thread/s0hb3jkfj5f3ryx6c57zqtfohb0of1g9 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2374804 issue
- https://www.cve.org/CVERecord?id=CVE-2025-52999 advisory
…and 28 more