RHSA-2025:1885: Important: Red Hat build of Quarkus 3.15.3.SP1 Security Update
This release of Red Hat Build of Quarkus 3.15.3.SP1 includes security updates.For more information, see the release notes page listed in the References section.Security Fix(es): io.netty/netty-handler: SslHandler doesn't correctly validate packets, which can lead to a native crash when using native SSLEngine (CVE-2025-24970) io.quarkus/quarkus-rest: Quarkus REST Endpoint Request Parameter Leakage Due to Shared Instance (CVE-2025-1247) io.quarkus:quarkus-resteasy: Memory Leak in Quarkus RESTEasy Classic When Client Requests Timeout (CVE-2025-1634)
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2025:1885?
The severity of RHSA-2025:1885 is classified as high due to the potential for compromised packet validation leading to security vulnerabilities.
How do I fix RHSA-2025:1885?
To fix RHSA-2025:1885, update your Red Hat Build of Quarkus to version 3.15.3.SP1 or later.
What specific vulnerability does RHSA-2025:1885 address?
RHSA-2025:1885 addresses a vulnerability in io.netty/netty-handler where SslHandler does not correctly validate packets.
Who is affected by RHSA-2025:1885?
RHSA-2025:1885 affects users of Red Hat Quarkus versions prior to the patched release.
When was RHSA-2025:1885 released?
RHSA-2025:1885 was released in response to security issues identified in Red Hat Quarkus on a specified date.