First published: Mon Jul 17 2017(Updated: )
It was discovered that the implementation of the BasicAttribute class in OpenJDK did not limit the amount of memory allocated when creating object instance from a serialized form. A specially-crafted serialized input stream could cause JVM to consume an excessive amount of memory.
Affected Software | Affected Version | How to fix |
---|---|---|
OpenJDK |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-1471888 is high due to its potential for excessive memory consumption.
To fix REDHAT-BUG-1471888, update to the latest patched version of OpenJDK that resolves this memory allocation issue.
REDHAT-BUG-1471888 affects systems running OpenJDK with vulnerabilities in the BasicAttribute class.
The risks of REDHAT-BUG-1471888 include application crashes and denial of service caused by excessive memory usage.
Currently, there is no documented workaround for REDHAT-BUG-1471888, making updates the recommended course of action.