First published: Tue Oct 19 2021(Updated: )
A flaw was found in the way the ClassFileParser class implementation in the Hotspot component of OpenJDK performed validation of inner class index values. A specially-crafted class file could cause a Java virtual machine to crash when loaded.
Credit: secalert_us@oracle.com secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/java | <1.8.0-openjdk-1:1.8.0.312.b07-1.el7_9 | 1.8.0-openjdk-1:1.8.0.312.b07-1.el7_9 |
redhat/java | <1.8.0-openjdk-1:1.8.0.312.b07-1.el8_4 | 1.8.0-openjdk-1:1.8.0.312.b07-1.el8_4 |
redhat/java | <1.8.0-openjdk-1:1.8.0.312.b07-1.el8_1 | 1.8.0-openjdk-1:1.8.0.312.b07-1.el8_1 |
redhat/java | <1.8.0-openjdk-1:1.8.0.312.b07-1.el8_2 | 1.8.0-openjdk-1:1.8.0.312.b07-1.el8_2 |
Oracle GraalVM | =20.3.3 | |
Oracle GraalVM | =21.2.0 | |
Oracle OpenJDK | =7-update311 | |
Oracle OpenJDK | =8-update301 | |
Netapp Active Iq Unified Manager Vmware Vsphere | ||
Netapp Active Iq Unified Manager Windows | ||
NetApp E-Series SANtricity OS Controller | >=11.0.0<=11.70.1 | |
Netapp E-series Santricity Storage Manager | ||
Netapp E-series Santricity Web Services Web Services Proxy | ||
Netapp Hci Management Node | ||
NetApp OnCommand Insight | ||
NetApp OnCommand Workflow Automation | ||
Netapp Santricity Unified Manager | ||
Netapp Snapmanager Oracle | ||
Netapp Snapmanager Sap | ||
Netapp Solidfire | ||
Fedoraproject Fedora | =33 | |
Fedoraproject Fedora | =34 | |
Fedoraproject Fedora | =35 | |
Debian Debian Linux | =9.0 | |
IBM QRadar SIEM | <=7.5.0 GA | |
IBM QRadar SIEM | <=7.4.3 GA - 7.4.3 FP4 | |
IBM QRadar SIEM | <=7.3.3 GA - 7.3.3 FP10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
The severity of CVE-2021-35588 is low (3.1).
The affected software for CVE-2021-35588 includes Java SE 7u311, 8u301, Oracle GraalVM Enterprise Edition 20.3.3 and 21.2.0.
To fix CVE-2021-35588, update to the following versions: Java SE 1.8.0-openjdk-1:1.8.0.312.b07-1.el7_9, Java SE 1.8.0-openjdk-1:1.8.0.312.b07-1.el8_4, Oracle GraalVM Enterprise Edition 20.3.3 and 21.2.0.
Yes, there are patches available. Please refer to the references for more information.
The Common Weakness Enumeration (CWE) for CVE-2021-35588 is CWE-20.