{"id":"GHSA-4g8c-wm8x-jfhw","summary":"SslHandler doesn't correctly validate packets which can lead to native crash when using native SSLEngine","details":"### Impact\nWhen a special crafted packet is received via SslHandler it doesn't correctly handle validation of such a packet in all cases which can lead to a native crash.\n\n### Workarounds\nAs workaround its possible to either disable the usage of the native SSLEngine or changing the code from:\n\n```\nSslContext context = ...;\nSslHandler handler = context.newHandler(....);\n```\n\nto:\n\n```\nSslContext context = ...;\nSSLEngine engine = context.newEngine(....);\nSslHandler handler = new SslHandler(engine, ....);\n```","aliases":["CVE-2025-24970"],"modified":"2026-07-17T21:12:34.420924905Z","published":"2025-02-10T17:38:10Z","database_specific":{"nvd_published_at":"2025-02-10T22:15:38Z","cwe_ids":["CWE-20"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2025-02-10T17:38:10Z"},"references":[{"type":"WEB","url":"https://github.com/netty/netty/security/advisories/GHSA-4g8c-wm8x-jfhw"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-24970"},{"type":"WEB","url":"https://github.com/netty/netty/commit/87f40725155b2f89adfde68c7732f97c153676c4"},{"type":"PACKAGE","url":"https://github.com/netty/netty"},{"type":"WEB","url":"https://security.netapp.com/advisory/ntap-20250221-0005"},{"type":"WEB","url":"https://www.vicarius.io/vsociety/posts/cve-2025-24970-netty-vulnerability-detection"},{"type":"WEB","url":"https://www.vicarius.io/vsociety/posts/cve-2025-24970-netty-vulnerability-mitigation"}],"affected":[{"package":{"name":"io.netty:netty-handler","ecosystem":"Maven","purl":"pkg:maven/io.netty/netty-handler"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.1.91.Final"},{"fixed":"4.1.118.Final"}]}],"versions":["4.1.100.Final","4.1.101.Final","4.1.102.Final","4.1.103.Final","4.1.104.Final","4.1.105.Final","4.1.106.Final","4.1.107.Final","4.1.108.Final","4.1.109.Final","4.1.110.Final","4.1.111.Final","4.1.112.Final","4.1.113.Final","4.1.114.Final","4.1.115.Final","4.1.116.Final","4.1.117.Final","4.1.91.Final","4.1.92.Final","4.1.93.Final","4.1.94.Final","4.1.95.Final","4.1.96.Final","4.1.97.Final","4.1.98.Final","4.1.99.Final"],"database_specific":{"last_known_affected_version_range":"\u003c= 4.1.117.Final","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/02/GHSA-4g8c-wm8x-jfhw/GHSA-4g8c-wm8x-jfhw.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}