RHSA-2025:8258: Important: Red Hat build of Quarkus 3.20.1 release
Important: Red Hat build of Quarkus 3.20.1 release
Other sources
This release of Red Hat build of Quarkus 3.20.1 includes the following CVE fix: io.netty/netty-handler: SslHandler doesn't correctly validate packets which can lead to native crash when using native SSLEngine [quarkus-3.20] (CVE-2025-24970) For more information, see the release notes page listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2025:8258?
RHSA-2025:8258 is classified as important due to a critical vulnerability in the SslHandler component.
How does RHSA-2025:8258 affect Red Hat build of Quarkus?
RHSA-2025:8258 affects the Red Hat build of Quarkus through vulnerabilities in the SslHandler that can lead to native crashes.
How do I fix RHSA-2025:8258?
You can fix RHSA-2025:8258 by updating to the patched version of Red Hat build of Quarkus 3.20.1.
What are the potential risks of not addressing RHSA-2025:8258?
Not addressing RHSA-2025:8258 may expose your application to crashes and potential security threats due to improper packet validation.
Is there a workaround for RHSA-2025:8258 while waiting for an update?
There is no official workaround for RHSA-2025:8258; it is recommended to apply the update to mitigate the vulnerability.