RHSA-2024:10926MediumCVSS 4.8
Red Hat Security Advisory: java-1.8.0-ibm security update
🔗 CVE IDs covered (4)
📋 Description
CVE-2024-21208 — JDK: HTTP client improper handling of maxHeaderSize (8328286) CVE-2024-21210 — JDK: Array indexing integer overflow (8328544) CVE-2024-21217 — JDK: Unbounded allocation leads to out-of-memory error (8331446) CVE-2024-21235 — JDK: Integer conversion error leads to incorrect range check (8332644)
🎯 Affected products23
- Red Hat Enterprise Linux Supplementary (v. 8)
- java-1.8.0-ibm-1:1.8.0.8.35-1.el8_10.ppc64le as a component of Red Hat Enterprise Linux Supplementary (v. 8)
- java-1.8.0-ibm-1:1.8.0.8.35-1.el8_10.s390x as a component of Red Hat Enterprise Linux Supplementary (v. 8)
- java-1.8.0-ibm-1:1.8.0.8.35-1.el8_10.x86_64 as a component of Red Hat Enterprise Linux Supplementary (v. 8)
- java-1.8.0-ibm-demo-1:1.8.0.8.35-1.el8_10.ppc64le as a component of Red Hat Enterprise Linux Supplementary (v. 8)
- java-1.8.0-ibm-demo-1:1.8.0.8.35-1.el8_10.s390x as a component of Red Hat Enterprise Linux Supplementary (v. 8)
- java-1.8.0-ibm-demo-1:1.8.0.8.35-1.el8_10.x86_64 as a component of Red Hat Enterprise Linux Supplementary (v. 8)
- java-1.8.0-ibm-devel-1:1.8.0.8.35-1.el8_10.ppc64le as a component of Red Hat Enterprise Linux Supplementary (v. 8)
- java-1.8.0-ibm-devel-1:1.8.0.8.35-1.el8_10.s390x as a component of Red Hat Enterprise Linux Supplementary (v. 8)
- java-1.8.0-ibm-devel-1:1.8.0.8.35-1.el8_10.x86_64 as a component of Red Hat Enterprise Linux Supplementary (v. 8)
- java-1.8.0-ibm-headless-1:1.8.0.8.35-1.el8_10.ppc64le as a component of Red Hat Enterprise Linux Supplementary (v. 8)
- java-1.8.0-ibm-headless-1:1.8.0.8.35-1.el8_10.s390x as a component of Red Hat Enterprise Linux Supplementary (v. 8)
- java-1.8.0-ibm-headless-1:1.8.0.8.35-1.el8_10.x86_64 as a component of Red Hat Enterprise Linux Supplementary (v. 8)
- java-1.8.0-ibm-jdbc-1:1.8.0.8.35-1.el8_10.ppc64le as a component of Red Hat Enterprise Linux Supplementary (v. 8)
- java-1.8.0-ibm-jdbc-1:1.8.0.8.35-1.el8_10.s390x as a component of Red Hat Enterprise Linux Supplementary (v. 8)
- java-1.8.0-ibm-jdbc-1:1.8.0.8.35-1.el8_10.x86_64 as a component of Red Hat Enterprise Linux Supplementary (v. 8)
- java-1.8.0-ibm-plugin-1:1.8.0.8.35-1.el8_10.ppc64le as a component of Red Hat Enterprise Linux Supplementary (v. 8)
- java-1.8.0-ibm-plugin-1:1.8.0.8.35-1.el8_10.x86_64 as a component of Red Hat Enterprise Linux Supplementary (v. 8)
- java-1.8.0-ibm-src-1:1.8.0.8.35-1.el8_10.ppc64le as a component of Red Hat Enterprise Linux Supplementary (v. 8)
- java-1.8.0-ibm-src-1:1.8.0.8.35-1.el8_10.s390x as a component of Red Hat Enterprise Linux Supplementary (v. 8)
- java-1.8.0-ibm-src-1:1.8.0.8.35-1.el8_10.x86_64 as a component of Red Hat Enterprise Linux Supplementary (v. 8)
- java-1.8.0-ibm-webstart-1:1.8.0.8.35-1.el8_10.ppc64le as a component of Red Hat Enterprise Linux Supplementary (v. 8)
- java-1.8.0-ibm-webstart-1:1.8.0.8.35-1.el8_10.x86_64 as a component of Red Hat Enterprise Linux Supplementary (v. 8)
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258