REDHAT-BUG-2075793: Medium severity Oracle OpenJDK vulnerability
It was discovered that the ObjectIdentifier class in the Libraries component of OpenJDK did not properly validate the encoded length of the object identifier. This could lead to an integer underflow and possibly cause a Java application to throw an out of memory (OOM) exception because of excessive memory allocation.
Affected Software
Event History
Frequently Asked Questions
What would an attacker need to provide to trigger this issue?
An attacker would need to cause the affected Java application to process an object identifier with an improperly encoded length. The malformed encoding can cause an integer underflow and excessive memory allocation.
What is the likely impact to an affected application?
The application may attempt excessive memory allocation and throw an out-of-memory exception. This can disrupt the availability of the Java application.
How can I determine whether remediation is available for my environment?
Check the referenced Red Hat security advisories RHSA-2022:1441, RHSA-2022:1443, and RHSA-2022:1444 for the affected and fixed OpenJDK packages applicable to your system.