RHSA-2025:17567HighCVSS 7.5
Red Hat Security Advisory: Red Hat AMQ Broker 7.13.2 release and security update
🔗 CVE IDs covered (3)
📋 Description
CVE-2025-5115 — jetty: HTTP/2 (including DNS over HTTPS) contains a design flaw and is vulnerable to "MadeYouReset" DoS attack through HTTP/2 control frames CVE-2025-27533 — ActiveMQ: ActiveMQ: Unvalidated Buffer Size Allocation CVE-2025-58056 — netty-codec-http: Netty is vulnerable to request smuggling due to incorrect parsing of chunk extensions
🔗 References (18)
- selfhttps://access.redhat.com/errata/RHSA-2025:17567
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://access.redhat.com/security/updates/classification#important
- externalhttps://access.redhat.com/jbossnetwork/restricted/listSoftware.html?downloadType=distributions&product=jboss.amq.broker&version=7.13.2
- externalhttps://docs.redhat.com/en/documentation/red_hat_amq_broker/7.13
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2364684
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2373310
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2392996
- externalhttps://issues.redhat.com/browse/ENTMQBR-10093
- externalhttps://issues.redhat.com/browse/ENTMQBR-10099
- externalhttps://issues.redhat.com/browse/ENTMQBR-9917
- externalhttps://issues.redhat.com/browse/ENTMQBR-9921
- externalhttps://issues.redhat.com/browse/ENTMQBR-9932
- externalhttps://issues.redhat.com/browse/ENTMQBR-9933
- externalhttps://issues.redhat.com/browse/ENTMQBR-9934
- externalhttps://issues.redhat.com/browse/ENTMQBR-9936
- externalhttps://issues.redhat.com/browse/ENTMQBR-9947
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_17567.json