RHSA-2024:4561: Important: OpenJDK 8u422 Windows Security Update
Important: OpenJDK 8u422 Windows Security Update
Other sources
The OpenJDK 8 packages provide the OpenJDK 8 Java Runtime Environment and the OpenJDK 8 Java Software Development Kit.<br>This release of the Red Hat build of OpenJDK 8 (8u422) for Windows serves as a replacement for the Red Hat build of OpenJDK 8 (8u412) and includes security and bug fixes, and enhancements. For further information, refer to the release notes linked to in the References section.<br>Security Fix(es):<br><li> OpenJDK: RangeCheckElimination array index overflow (8323231) (CVE-2024-21147)</li> <li> OpenJDK: potential UTF8 size overflow (8314794) (CVE-2024-21131)</li> <li> OpenJDK: Excessive symbol length can lead to infinite loop (8319859) (CVE-2024-21138)</li> <li> OpenJDK: Range Check Elimination (RCE) pre-loop limit overflow (8320548) (CVE-2024-21140)</li> <li> OpenJDK: Pack200 increase loading time due to improper header validation (8322106) (CVE-2024-21144)</li> <li> OpenJDK: Out-of-bounds access in 2D image handling (8324559) (CVE-2024-21145)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:4561?
The severity of RHSA-2024:4561 is classified as important.
How do I fix RHSA-2024:4561?
To fix RHSA-2024:4561, update your OpenJDK to version 8u422.
What versions are affected by RHSA-2024:4561?
RHSA-2024:4561 affects the Red Hat build of OpenJDK 8 prior to version 8u422.
What are the risks of not patching RHSA-2024:4561?
Not patching RHSA-2024:4561 may expose systems to security vulnerabilities and potential exploits.
Is RHSA-2024:4561 specific to Windows?
Yes, RHSA-2024:4561 specifically addresses a security update for the OpenJDK 8 on Windows.