REDHAT-BUG-1823216: Low severity ORACLE OpenJDK vulnerability
A flaw was found in the Serialization component of OpenJDK. The invokeWriteObject() method of the ObjectStreamClass method failed to catch InstantiationError exception during object stream deserialization, which could cause an unexpected exception to be raised when processing an untrusted serialized input.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1823216?
The severity of REDHAT-BUG-1823216 is classified as important, as it can lead to unexpected exceptions during object stream deserialization.
How do I fix REDHAT-BUG-1823216?
To fix REDHAT-BUG-1823216, update to the patched version of Oracle OpenJDK as provided in the security advisories.
Which versions of OpenJDK are affected by REDHAT-BUG-1823216?
REDHAT-BUG-1823216 affects specific versions of Oracle OpenJDK, primarily around version 17.
What is the nature of the flaw in REDHAT-BUG-1823216?
The flaw in REDHAT-BUG-1823216 pertains to the Serialization component failing to handle InstantiationError exceptions during deserialization.
Can REDHAT-BUG-1823216 be exploited remotely?
Yes, REDHAT-BUG-1823216 can potentially be exploited remotely if an application is processing untrusted serialized data.