CVE-2025-24898 is a use-after-free vulnerability in the rust-openssl library, specifically within the ssl::select_next_proto function. This flaw can occur when the server buffer's lifetime is shorter than the client's, potentially leading to a server crash or the disclosure of arbitrary memory contents. Rated as Medium severity (CVSS 6.3), exploitation requires a high attack complexity but does not need user interaction or privileges, and could result in low confidentiality and availability impacts. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Sfackler | Rust-Openssl | >= 0.10.0, < 0.10.70CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.