Resource exhaustion in Netty - CVE-2025-58057
Published: September 3, 2025
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources in BrotliDecoder and some other decompressing decoders. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.
Affected software
SUSE Linux Enterprise Server 15 SP4
Debian Linux
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server 15 SP3
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Enterprise Storage
Development Tools Module
SUSE Package Hub 15
openSUSE Leap
Ubuntu
IBM Operator for Apache Flink
IBM Concert Software
IBM Observability with Instana
PowerVC
IBM SPSS Analytic Server
IT Service Intelligence (ITSI)
IBM Watson Discovery for IBM Cloud Pak for Data
Jira Service Management Data Center
IBM Sterling Connect:Direct Web Services
IBM Sterling Partner Engagement Manager
UCD - IBM UrbanCode Deploy
IBM Maximo Application Suite - Manage Component
Jira Software Data Center
Oracle Enterprise Command Center Framework
IBM Business Automation Workflow
Oracle Cloud Native Session Border Controller
Red Hat build of Quarkus
Netezza Appliance
Astronomer with IBM
DataPower Operations Dashboard
Operations Analytics - Log Analysis
DevOps Plan
Guardium Data Security Center (GDSC)
watsonx Orchestrate with watsonx Assistant Cartridge - UAB Component
Storage Scale
Oracle Business Intelligence Enterprise Edition
Rational Performance Tester
DevOps Test Performance
watsonx Assistant Cartridge
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component
MongoDB Enterprise Advanced with IBM
Guardium Data Protection
Voice Gateway
Communications Unified Assurance
Communications Service Catalog and Design
watsonx.data
Event Streams
IBM DB2
IBM InfoSphere Information Server
Oracle Banking Virtual Account Management
Siebel CRM Deployment
Oracle Communications Cloud Native Core Policy
Oracle Communications Cloud Native Core Service Communication Proxy
netty-tcnative-javadoc
netty-tcnative-debugsource
netty-tcnative
netty (Ubuntu package)
netty (Debian package)
netty-javadoc
netty
AMQ Streams
Splunk AppDynamics Analytics Agent
How to mitigate CVE-2025-58057
IBM Operator for Apache Flink - update to 1.4.5
IBM Concert Software - update to 2.2.0
Netezza Appliance - update to 1.0.0.1
Astronomer with IBM - update to 1.1.0
Voice Gateway - update to 1.0.8.22
DataPower Operations Dashboard - update to 1.0.23.3
IBM Observability with Instana - update to 1.0.308
Operations Analytics - Log Analysis - update to 1.3.8.4
watsonx.data - update to 2.2.2
DevOps Plan - update to 3.0.7
Guardium Data Security Center (GDSC) - update to 3.8.5
IT Service Intelligence (ITSI) - update to 4.21.2
IBM Watson Discovery for IBM Cloud Pak for Data - update to 5.3.0
watsonx Orchestrate with watsonx Assistant Cartridge - UAB Component - update to 5.2.2
Storage Scale - update to 5.2.3.5
Jira Service Management Data Center - addressed in versions 5.12.28, 10.3.11, 11.1.0
IBM Sterling Connect:Direct Web Services - addressed in versions 6.2.0.29, 6.3.0.15, 6.4.0.4
IBM Sterling Partner Engagement Manager - addressed in versions 6.2.3.5, 6.2.4.2
UCD - IBM UrbanCode Deploy - addressed in versions 7.1.2.27, 7.2.3.20, 7.3.2.15, 8.0.1.10, 8.1.2.3
IBM Maximo Application Suite - Manage Component - addressed in versions 8.6.31, 8.7.25, 9.0.18, 9.1.5
Jira Software Data Center - addressed in versions 9.12.28, 10.3.11, 11.1.0
Event Streams - update to 12.2.0
DevOps Test Performance - update to 11.0.7
IBM InfoSphere Information Server - update to 11.7.1.6 Service pack 1
IBM Business Automation Workflow - addressed in versions 24.0.0-IF008, 24.0.1-IF006, 25.0.0-IF003
netty-tcnative-javadoc - update to 2.0.73-150200.3.30.1
netty-tcnative-debugsource - update to 2.0.73-150200.3.30.1
netty-tcnative - update to 2.0.73-150200.3.30.1
AMQ Streams - update to 3.1.0
Red Hat build of Quarkus - addressed in versions 3.15.7, 3.20.3
netty (Ubuntu package) - addressed in versions 1:4.0.34-1ubuntu0.1~esm3, 1:4.1.7-4ubuntu0.1+esm5, 1:4.1.45-1ubuntu0.1~esm4, 1:4.1.48-4+deb11u2ubuntu0.1~esm2, 1:4.1.48-9ubuntu0.1~esm2, 1:4.1.48-10ubuntu0.25.04.2, 1:4.1.48-10ubuntu0.25.10.2
netty (Debian package) - addressed in versions 1:4.1.48-7+deb12u2, 1:4.1.48-10+deb13u1
netty-javadoc - update to 4.1.126-150200.4.34.1
netty - update to 4.1.126-150200.4.34.1
watsonx Assistant Cartridge - update to 5.3.0
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component - update to 5.3.0
MongoDB Enterprise Advanced with IBM - update to 8.0.19
Guardium Data Protection - update to 12.0p50
Splunk AppDynamics Analytics Agent - update to 26.1.0
External References
Related Security Bulletins
- Multiple vulnerabilities in Netty
- SUSE update for netty, netty-tcnative
- Multiple vulnerabilities in IBM DevOps Deploy / IBM UrbanCode Deploy (UCD)
- IBM Sterling Connect:Direct Web Services update for Netty
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Policy
- Multiple vulnerabilities in IBM Voice Gateway
- Jira Software Data Center update for netty:netty-codec-http
- Jira Service Management Data Center update for io.netty:netty-codec-http
- Multiple vulnerabilities in Red Hat build of Quarkus 3.15
- Multiple vulnerabilities in Red Hat build of Quarkus 3.20
- IBM InfoSphere Information Server update for Netty
- IBM PowerVC update for Netty
- Multiple vulnerabilities in IBM Observability with Instana
- Multiple vulnerabilities in IBM Guardium Data Security Center
- Ubuntu update for netty
- IBM watsonx.data update for Netty
- Multiple vulnerabilities in IBM Sterling Partner Engagement Manager Essentials Edition
- Red Hat AMQ Streams update for Apache Kafka
- IBM Netezza Appliance update for Netty
- IBM watsonx Assistant Cartridge and IBM watsonx Orchestrate with watsonx Assistant Cartridge update for Netty
- IBM Rational Performance Tester update for Netty
- Multiple vulnerabilities in IBM Event Streams
- Multiple vulnerabilities in IBM Storage Scale
- Multiple vulnerabilities in Oracle Cloud Native Session Border Controller
- Astronomer with IBM update for Netty
- IBM watsonx Orchestrate with watsonx Assistant Cartridge - UAB Component update for Netty
- Multiple vulnerabilities in IBM Db2
- IBM Watson Discovery Cartridge update for Netty
- Multiple vulnerabilities in IBM Concert Software
- Multiple vulnerabilities in IBM Business Automation Workflow
- Multiple vulnerabilities in IBM Operator for Apache Flink
- Multiple vulnerabilities in IBM Guardium Data Protection
- IBM Maximo Application Suite - Manage Component update for Netty
- Multiple vulnerabilities in MongoDB Enterprise Advanced with IBM
- Debian update for netty
- Splunk AppDynamics Analytics Agent update for third-party components
- Multiple vulnerabilities in IBM Datapower Operations Dashboard
- Multiple vulnerabilities in IBM Operations Analytics - Log Analysis
- Splunk IT Service Intelligence update for third-party components
- Multiple vulnerabilities in Oracle Banking Virtual Account Management
- Multiple vulnerabilities in Oracle Enterprise Command Center Framework
- Multiple vulnerabilities in Communications Service Catalog and Design
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Service Communication Proxy
- Multiple vulnerabilities in Communications Unified Assurance
- Multiple vulnerabilities in Oracle Business Intelligence Enterprise Edition
- Multiple vulnerabilities in Siebel CRM Deployment
- Multiple vulnerabilities in IBM SPSS Analytic Server
- IBM DevOps Plan update for Netty