CVE-2025-24970: SslHandler doesn't correctly validate packets which can lead to native crash when using native SSLEngine
(updated )
When a special crafted packet is received via SslHandler it doesn’t correctly handle validation of such a packet in all cases which can lead to a native crash.
References
- github.com/advisories/GHSA-4g8c-wm8x-jfhw
- github.com/netty/netty
- github.com/netty/netty/commit/87f40725155b2f89adfde68c7732f97c153676c4
- github.com/netty/netty/security/advisories/GHSA-4g8c-wm8x-jfhw
- nvd.nist.gov/vuln/detail/CVE-2025-24970
- security.netapp.com/advisory/ntap-20250221-0005
- www.vicarius.io/vsociety/posts/cve-2025-24970-netty-vulnerability-detection
- www.vicarius.io/vsociety/posts/cve-2025-24970-netty-vulnerability-mitigation
Code Behaviors & Features
Detect and mitigate CVE-2025-24970 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →