REDHAT-BUG-2014524: Medium severity ORACLE OpenJDK vulnerability
Published Oct 15, 2021
·Updated
A flaw was found in the way the HashMap and the HashSet classes implementations in the Utility component of OpenJDK validated the load factor value during deserialization. A specially crafted serialized data stream could cause a Java application to allocate an excessive amount of memory and possibly terminate on out-of-memory condition when deserialized.
Affected Software
1 affected component
ORACLE OpenJDK
Event History
Oct 15, 2021
Data Sourced
via Red Hat·01:32 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What access does an attacker need to exploit this issue?
An attacker needs to cause a Java application to deserialize a specially crafted serialized data stream. The provided data does not describe any network service, authentication requirement, or other delivery mechanism.
2
Which product is identified in the available vulnerability data?
The affected software is identified as Oracle OpenJDK. The provided data does not list affected OpenJDK versions or specific package builds.