First published: Mon Jan 17 2022(Updated: )
It was discovered that the implementation of the IdentityHashMap class in the Libraries component of OpenJDK did properly validate the value of its size attribute when creating object instance from a serialized form. A specially-crafted input could cause a Java application to use an excessive amount of memory when deserialized.
Affected Software | Affected Version | How to fix |
---|---|---|
OpenJDK |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-2041427 is categorized as moderate.
To fix REDHAT-BUG-2041427, ensure you update to the latest version of OpenJDK that includes the necessary patches.
REDHAT-BUG-2041427 affects applications using the IdentityHashMap class in the Libraries component of OpenJDK.
REDHAT-BUG-2041427 is a deserialization vulnerability that can lead to excessive resource consumption.
Yes, REDHAT-BUG-2041427 can be exploited remotely if an application is exposed to specially-crafted serialized input.