RHSA-2024:0222HighCVSS 7.4

Red Hat Security Advisory: OpenJDK 8u402 security update

Published
January 17, 2024
Last Modified
September 7, 2026

🔗 CVE IDs covered (6)

📋 Description

CVE-2024-20918 — OpenJDK: array out-of-bounds access due to missing range check in C1 compiler (8314468) CVE-2024-20919 — OpenJDK: JVM class file verifier flaw allows unverified bytecode execution (8314295) CVE-2024-20921 — OpenJDK: range check loop optimization issue (8314307) CVE-2024-20926 — OpenJDK: arbitrary Java code execution in Nashorn (8314284) CVE-2024-20945 — OpenJDK: logging of digital signature private keys (8316976) CVE-2024-20952 — OpenJDK: RSA padding issue and timing side-channel attack against TLS (8317547)

🎯 Affected products1

  • Red Hat Build of OpenJDK 8u402

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258

🔗 References (9)