REDHAT-BUG-1471526: Openjdk vulnerability
It was discovered that the LambdaFormEditor class in the Libraries component of OpenJDK did not correctly perform bounds checks in the permuteArgumentsForm() function. An untrusted Java application or applet could use this flaw to corrupt JVM memory and cause it to crash or, possibly, execute arbitrary code, bypassing Java sandbox restrictions. The problem is triggered when using MethodHandle.permuteArguments().
Upstream report:
https://bugs.openjdk.java.net/browse/JDK-8184119 http://mail.openjdk.java.net/pipermail/jdk9-dev/2017-July/005915.html
OpenJDK 9 upstream commit:
http://hg.openjdk.java.net/jdk9/dev/jdk/rev/9003926e4a8a
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1471526?
The severity of REDHAT-BUG-1471526 is critical, as it can lead to JVM memory corruption and potential remote code execution.
How do I fix REDHAT-BUG-1471526?
To fix REDHAT-BUG-1471526, update to the latest version of OpenJDK that addresses the vulnerability.
What versions of OpenJDK are affected by REDHAT-BUG-1471526?
REDHAT-BUG-1471526 affects multiple versions of OpenJDK, particularly those prior to the fix.
What should I do if I'm using a vulnerable version of OpenJDK related to REDHAT-BUG-1471526?
If using a vulnerable version, it's recommended to upgrade to the patched version immediately to mitigate risks.
Can an attacker exploit REDHAT-BUG-1471526?
Yes, an attacker can exploit REDHAT-BUG-1471526 by using untrusted Java applications to corrupt JVM memory.