RHSA-2024:4566HighCVSS 7.4
Red Hat Security Advisory: OpenJDK 11.0.24 Security Update for Portable Linux Builds
🔗 CVE IDs covered (6)
📋 Description
CVE-2024-21131 — OpenJDK: potential UTF8 size overflow (8314794) CVE-2024-21138 — OpenJDK: Excessive symbol length can lead to infinite loop (8319859) CVE-2024-21140 — OpenJDK: Range Check Elimination (RCE) pre-loop limit overflow (8320548) CVE-2024-21144 — OpenJDK: Pack200 increase loading time due to improper header validation (8322106) CVE-2024-21145 — OpenJDK: Out-of-bounds access in 2D image handling (8324559) CVE-2024-21147 — OpenJDK: RangeCheckElimination array index overflow (8323231)
🎯 Affected products1
- Red Hat Build of OpenJDK 11.0.24
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258
🔗 References (9)
- selfhttps://access.redhat.com/errata/RHSA-2024:4566
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2297961
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2297962
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2297963
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2297964
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2297976
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2297977
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_4566.json