PT-2025-6111 · Netty+4 · Netty+6

Johnou

·

Published

2025-02-10

·

Updated

2026-05-18

·

CVE-2025-24970

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Netty versions 4.1.91.Final through 4.1.117.Final
Description The vulnerability is related to the Netty framework, an asynchronous, event-driven network application framework. It occurs when a special crafted packet is received via SslHandler, which does not correctly handle validation of such a packet in all cases, leading to a native crash. This issue can be exploited by an unauthenticated attacker to expose assets in the environment susceptible to exploitation, with no impact to confidentiality, no impact to integrity, but high impact to availability, and requires no user interaction.
Recommendations For Netty versions 4.1.91.Final through 4.1.117.Final, upgrade to version 4.1.118.Final or later. As a temporary workaround, consider disabling the usage of the native SSLEngine or change the code manually to correctly handle the validation of special crafted packets received via SslHandler. For Confluence Data Center and Server 8.5, upgrade to a release greater than or equal to 8.5.20. For Confluence Data Center and Server 9.2, upgrade to a release greater than or equal to 9.2.2. For Confluence Data Center and Server 9.3, upgrade to a release greater than or equal to 9.3.2. For Bamboo Data Center and Server 9.6, upgrade to a release greater than or equal to 9.6.11. For Bamboo Data Center and Server 10.2, upgrade to a release greater than or equal to 10.2.2.

Exploit

Fix

DoS

RCE

Resource Exhaustion

Weakness Enumeration

Related Identifiers

BDU:2025-02529
BDU:2025-03389
CLEANSTART-2026-DD05788
CLEANSTART-2026-GH89210
CLEANSTART-2026-JU62349
CLEANSTART-2026-JW30455
CLEANSTART-2026-MM00120
CLEANSTART-2026-SQ91016
CLEANSTART-2026-SV95049
CLEANSTART-2026-VH41554
CLEANSTART-2026-WG59699
CLEANSTART-2026-WK99982
CVE-2025-24970
GHSA-4G8C-WM8X-JFHW
OPENSUSE-SU-2025:14765-1
OPENSUSE-SU-2025_0590-1
RHSA-2025:3357
RHSA-2025:3465
RHSA-2025:4548
RHSA-2025:4549
RHSA-2025:4550
SUSE-SU-2025:0590-1
SUSE-SU-2025_0590-1

Affected Products

Bamboo
Bitbucket
Confluence
Debian
Netty
Red Os
Suse