REDHAT-BUG-2041427: Medium severity openjdk vulnerability
It was discovered that the implementation of the IdentityHashMap class in the Libraries component of OpenJDK did properly validate the value of its size attribute when creating object instance from a serialized form. A specially-crafted input could cause a Java application to use an excessive amount of memory when deserialized.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2041427?
The severity of REDHAT-BUG-2041427 is categorized as moderate.
How do I fix REDHAT-BUG-2041427?
To fix REDHAT-BUG-2041427, ensure you update to the latest version of OpenJDK that includes the necessary patches.
What does REDHAT-BUG-2041427 affect?
REDHAT-BUG-2041427 affects applications using the IdentityHashMap class in the Libraries component of OpenJDK.
What type of vulnerability is REDHAT-BUG-2041427?
REDHAT-BUG-2041427 is a deserialization vulnerability that can lead to excessive resource consumption.
Is REDHAT-BUG-2041427 exploitable remotely?
Yes, REDHAT-BUG-2041427 can be exploited remotely if an application is exposed to specially-crafted serialized input.