RHSA-2024:8129: Moderate: OpenJDK 21.0.5 Security Update for Windows Builds
Moderate: OpenJDK 21.0.5 Security Update for Windows Builds
Other sources
The OpenJDK 21 packages provide the OpenJDK 21 Java Runtime Environment and the OpenJDK 21 Java Software Development Kit.<br>This release of the Red Hat build of OpenJDK 21 (21.0.5) for Windows serves as a replacement for the Red Hat build of OpenJDK 21 (21.0.4) and includes security and bug fixes. For further information, refer to the release notes linked to in the References section.<br>Security Fix(es):<br><li> giflib: Heap-Buffer Overflow during Image Saving in DumpScreen2RGB Function (CVE-2023-48161)</li> <li> OpenJDK: Array indexing integer overflow (8328544) (CVE-2024-21210)</li> <li> OpenJDK: HTTP client improper handling of maxHeaderSize (8328286) (CVE-2024-21208)</li> <li> OpenJDK: Unbounded allocation leads to out-of-memory error (8331446) (CVE-2024-21217)</li> <li> OpenJDK: Integer conversion error leads to incorrect range check (8332644) (CVE-2024-21235)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:8129?
The severity of RHSA-2024:8129 is classified as moderate.
How do I fix RHSA-2024:8129?
To fix RHSA-2024:8129, update to the latest version of OpenJDK as provided in the security advisory.
What software is affected by RHSA-2024:8129?
RHSA-2024:8129 affects the Red Hat OpenJDK Java (for Middleware) package.
What is the main purpose of RHSA-2024:8129?
The main purpose of RHSA-2024:8129 is to provide a security update for vulnerabilities in OpenJDK 21.0.5.
Is upgrading required for RHSA-2024:8129?
Yes, upgrading is required to mitigate the security risks associated with RHSA-2024:8129.