CVE-2025-4432: Red Hat Enterprise Linux 10

Medium severity, CVSS 5.3. EPSS: 1% chance of exploitation in the next 30 days.

A flaw was found in Rust's Ring package. A panic may be triggered when overflow checking is enabled. In the QUIC protocol, this flaw allows an attacker to induce this panic by sending a specially crafted packet. It will likely occur unintentionally in 1 out of every 2**32 packets sent or received.

Affected products

  • Red Hat Red Hat Enterprise Linux 10
  • Red Hat Red Hat Enterprise Linux 6
  • Red Hat Red Hat Enterprise Linux 7
  • Red Hat Red Hat Enterprise Linux 8
  • Red Hat Red Hat Enterprise Linux 9
  • Red Hat Red Hat Openshift Container Platform 4
  • Red Hat Red Hat Satellite 6
  • Red Hat Red Hat Trusted Artifact Signer
  • Red Hat Red Hat Trusted Profile Analyzer

Published 2025-05-09. Last modified 2026-06-30.