REDHAT-BUG-2075793: Medium severity Oracle OpenJDK vulnerability

Published Apr 15, 2022
·
Updated

It was discovered that the ObjectIdentifier class in the Libraries component of OpenJDK did not properly validate the encoded length of the object identifier. This could lead to an integer underflow and possibly cause a Java application to throw an out of memory (OOM) exception because of excessive memory allocation.

Affected Software

1 affected component
Oracle OpenJDK

Event History

Apr 15, 2022
Data Sourced
via Red Hat·11:18 AM
DescriptionSeverityAffected Software

Frequently Asked Questions

1

What would an attacker need to provide to trigger this issue?

An attacker would need to cause the affected Java application to process an object identifier with an improperly encoded length. The malformed encoding can cause an integer underflow and excessive memory allocation.

2

What is the likely impact to an affected application?

The application may attempt excessive memory allocation and throw an out-of-memory exception. This can disrupt the availability of the Java application.

3

How can I determine whether remediation is available for my environment?

Check the referenced Red Hat security advisories RHSA-2022:1441, RHSA-2022:1443, and RHSA-2022:1444 for the affected and fixed OpenJDK packages applicable to your system.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203