First published: Sun Apr 14 2024(Updated: )
A flaw was found in the Pack200 archive format in OpenJDK. The NativeUnpack class did not properly validate the memory size when allocating a buffer, potentially leading to an excessive memory allocation and denial of service condition.
Credit: secalert_us@oracle.com secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
debian/openjdk-11 | 11.0.24+8-2~deb11u1 11.0.26+4-1~deb11u1 11.0.26+4-1 | |
debian/openjdk-8 | 8u442-ga-1 | |
IBM Spectrum Protect | <=8.1.0.0 - 8.1.23.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-21085 has been classified with a moderate severity level due to its potential to cause denial of service.
To remediate CVE-2024-21085, update OpenJDK to versions 11.0.24+8-2~deb11u1 or later for OpenJDK 11, or 8u432-b06-2 or later for OpenJDK 8.
CVE-2024-21085 affects OpenJDK 8 and OpenJDK 11, as well as IBM's Storage Protect Backup-Archive Client versions up to 8.1.23.0.
CVE-2024-21085 is a denial of service vulnerability caused by improper memory allocation in the Pack200 archive format of OpenJDK.
As of now, there is no publicly disclosed exploit for CVE-2024-21085, though it presents a risk of denial of service.