USN-6810-1: OpenJDK 8 vulnerabilities
It was discovered that the Hotspot component of OpenJDK 8 incorrectly handled certain exceptions with specially crafted long messages. An attacker could possibly use this issue to cause a denial of service. (CVE-2024-21011) Vladimir Kondratyev discovered that the Hotspot component of OpenJDK 8 incorrectly handled address offset calculations in the C1 compiler. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2024-21068) Yakov Shafranovich discovered that OpenJDK 8 did not properly manage memory in the Pack200 archive format. An attacker could possibly use this issue to cause a denial of service. (CVE-2024-21085) It was discovered that the Hotspot component of OpenJDK 8 incorrectly handled array accesses in the C2 compiler. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2024-21094)
Affected Software
Event History
Child vulnerabilities
Contains the following vulnerabilities.
Frequently Asked Questions
What is the severity of USN-6810-1?
The severity of USN-6810-1 is identified as a potential denial of service vulnerability.
How do I fix USN-6810-1?
To fix USN-6810-1, update the OpenJDK packages to the versions 8u412-ga-1 or newer.
What products are affected by USN-6810-1?
The affected products by USN-6810-1 include OpenJDK 8 packages on Ubuntu 18.04, 20.04, 22.04, 23.10, and 24.04.
What components are involved in USN-6810-1?
USN-6810-1 involves the Hotspot component of OpenJDK 8.
Is there an exploit for USN-6810-1?
Yes, an attacker could exploit USN-6810-1 to induce a denial of service by using specially crafted long messages.