Skip to content

Comments

[GHSA-389x-839f-4rhx] - Bumping fixed version for CVE-2025-25193#5386

Closed
renatorpn wants to merge 1 commit intogithub:renatorpn/advisory-improvement-5386from
renatorpn:renatorpn-GHSA-389x-839f-4rhx
Closed

[GHSA-389x-839f-4rhx] - Bumping fixed version for CVE-2025-25193#5386
renatorpn wants to merge 1 commit intogithub:renatorpn/advisory-improvement-5386from
renatorpn:renatorpn-GHSA-389x-839f-4rhx

Conversation

@renatorpn
Copy link

@renatorpn renatorpn commented Mar 21, 2025

The fixed version is wrong, as 4.1.118.Final is still vulnerable. The correct version is 4.1.119.Final.

This PR just updates the GHSA-389x-839f-4rhx to the right fix version.

See commit included in 4.1.119.Final: netty/netty@d1fbda6
See NIST advisory: https://nvd.nist.gov/vuln/detail/CVE-2025-25193

@github-actions github-actions bot changed the base branch from main to renatorpn/advisory-improvement-5386 March 21, 2025 17:44
@renatorpn renatorpn changed the title [GHSA-cj7v-w2c7-cp7c] - Bumping fixed version for CVE-2025-25193 [GHSA-389x-839f-4rhx] - Bumping fixed version for CVE-2025-25193 Mar 21, 2025
@shelbyc
Copy link
Contributor

shelbyc commented Mar 21, 2025

Hi @renatorpn, the tags of netty/netty@d1fbda6 indicate the commit is included in version 4.1.118.Final.
Screenshot 2025-03-21 at 5 51 41 PM
Additionally, https://github.com/netty/netty/commits/netty-4.1.118.Final/ contains netty/netty@d1fbda6 in the list of commits.

Is there anything else that leads you to believe 4.1.118.Final is still vulnerable?

@renatorpn
Copy link
Author

renatorpn commented Mar 21, 2025

Hello @shelbyc, you're absolutely right.

My apologies and sorry for not noticing that before submitting the PR. I should have paid closer attention to the tag. :)

All good - Closing this PR as there's nothing more that leads me to believe this is wrong.

Thank you for your time!

@renatorpn renatorpn closed this Mar 21, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants