RHSA-2024:4572HighCVSS 7.4
Red Hat Security Advisory: OpenJDK 21.0.4 Security Update for Portable Linux Builds
🔗 CVE IDs covered (5)
📋 Description
CVE-2024-21131 — OpenJDK: potential UTF8 size overflow (8314794) CVE-2024-21138 — OpenJDK: Excessive symbol length can lead to infinite loop (8319859) CVE-2024-21140 — OpenJDK: Range Check Elimination (RCE) pre-loop limit overflow (8320548) CVE-2024-21145 — OpenJDK: Out-of-bounds access in 2D image handling (8324559) CVE-2024-21147 — OpenJDK: RangeCheckElimination array index overflow (8323231)
🎯 Affected products1
- Red Hat Build of OpenJDK 21.0.4
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258
🔗 References (8)
- selfhttps://access.redhat.com/errata/RHSA-2024:4572
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2297961
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2297962
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2297963
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2297976
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2297977
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_4572.json