CVE-2025-25193

Netty, an asynchronous, event-driven network application framework, has a vulnerability in versions up to and including 4.1.118.Final. An unsafe reading of environment file could potentially cause a denial of service in Netty. When loaded on an Windows application, Netty attempts to load a file that does not exist. If an attacker creates such a large file, the Netty application crash. A similar issue was previously reported as CVE-2024-47535. This issue was fixed, but the fix was incomplete in that null-bytes were not counted against the input limit. Commit d1fbda62d3a47835d3fb35db8bd42ecc205a5386 contains an updated fix.
Configurations

Configuration 1 (hide)

cpe:2.3:a:netty:netty:*:*:*:*:*:*:*:*

History

26 Mar 2025, 13:14

Type Values Removed Values Added
First Time Netty
Netty netty
CPE cpe:2.3:a:netty:netty:*:*:*:*:*:*:*:*
References () https://github.com/netty/netty/commit/d1fbda62d3a47835d3fb35db8bd42ecc205a5386 - () https://github.com/netty/netty/commit/d1fbda62d3a47835d3fb35db8bd42ecc205a5386 - Patch, Third Party Advisory
References () https://github.com/netty/netty/security/advisories/GHSA-389x-839f-4rhx - () https://github.com/netty/netty/security/advisories/GHSA-389x-839f-4rhx - Third Party Advisory
References () https://security.netapp.com/advisory/ntap-20250221-0006/ - () https://security.netapp.com/advisory/ntap-20250221-0006/ - Third Party Advisory

21 Feb 2025, 18:15

Type Values Removed Values Added
References
  • () https://security.netapp.com/advisory/ntap-20250221-0006/ -

11 Feb 2025, 16:15

Type Values Removed Values Added
References () https://github.com/netty/netty/security/advisories/GHSA-389x-839f-4rhx - () https://github.com/netty/netty/security/advisories/GHSA-389x-839f-4rhx -
Summary
  • (es) Netty, un framework de aplicación de red asincrónico y controlado por eventos, tiene una vulnerabilidad en las versiones hasta la 4.1.118.Final incluida. Una lectura no segura del archivo de entorno podría causar una denegación de servicio en Netty. Cuando se carga en una aplicación de Windows, Netty intenta cargar un archivo que no existe. Si un atacante crea un archivo tan grande, la aplicación Netty se bloquea. Anteriormente se informó de un problema similar como CVE-2024-47535. Este problema se solucionó, pero la solución estaba incompleta porque los bytes nulos no se contabilizaban en el límite de entrada. El commit d1fbda62d3a47835d3fb35db8bd42ecc205a5386 contiene una solución actualizada.

10 Feb 2025, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-10 22:15

Updated : 2025-03-26 13:14


NVD link : CVE-2025-25193

Mitre link : CVE-2025-25193

CVE.ORG link : CVE-2025-25193


JSON object : View

Products Affected

netty

  • netty
CWE
CWE-400

Uncontrolled Resource Consumption