CVE-2025-4432: Red Hat Enterprise Linux 10
Medium severity, CVSS 5.3. EPSS: 1% chance of exploitation in the next 30 days.
A flaw was found in Rust's Ring package. A panic may be triggered when overflow checking is enabled. In the QUIC protocol, this flaw allows an attacker to induce this panic by sending a specially crafted packet. It will likely occur unintentionally in 1 out of every 2**32 packets sent or received.
Affected products
- Red Hat Red Hat Enterprise Linux 10
- Red Hat Red Hat Enterprise Linux 6
- Red Hat Red Hat Enterprise Linux 7
- Red Hat Red Hat Enterprise Linux 8
- Red Hat Red Hat Enterprise Linux 9
- Red Hat Red Hat Openshift Container Platform 4
- Red Hat Red Hat Satellite 6
- Red Hat Red Hat Trusted Artifact Signer
- Red Hat Red Hat Trusted Profile Analyzer
Published 2025-05-09. Last modified 2026-06-30.