RHSA-2024:4560: Important: java-1.8.0-openjdk security update
Important: java-1.8.0-openjdk security update
Other sources
The java-1.8.0-openjdk packages provide the OpenJDK 8 Java Runtime Environment and the OpenJDK 8 Java Software Development Kit.<br>Security Fix(es):<br><li> OpenJDK: RangeCheckElimination array index overflow (8323231) (CVE-2024-21147)</li> <li> OpenJDK: potential UTF8 size overflow (8314794) (CVE-2024-21131)</li> <li> OpenJDK: Excessive symbol length can lead to infinite loop (8319859) (CVE-2024-21138)</li> <li> OpenJDK: Range Check Elimination (RCE) pre-loop limit overflow (8320548) (CVE-2024-21140)</li> <li> OpenJDK: Pack200 increase loading time due to improper header validation (8322106) (CVE-2024-21144)</li> <li> OpenJDK: Out-of-bounds access in 2D image handling (8324559) (CVE-2024-21145)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:4560?
The severity of RHSA-2024:4560 is classified as important.
How do I fix RHSA-2024:4560?
To fix RHSA-2024:4560, update to the version 1.8.0-openjdk-1.8.0.422.b05-1.el7_9 or later.
Which systems are affected by RHSA-2024:4560?
RHSA-2024:4560 affects Red Hat Enterprise Linux Server in various architectures including IBM Power, big endian, and z Systems.
What is the nature of the vulnerability in RHSA-2024:4560?
The vulnerability in RHSA-2024:4560 is related to an array index overflow issue in OpenJDK, referenced as CVE-2024-21147.
Is RHSA-2024:4560 applicable only to Java applications?
RHSA-2024:4560 pertains specifically to the OpenJDK 8 Java Runtime Environment and Development Kit.