USN-6929-1: OpenJDK 8 vulnerabilities
It was discovered that the Hotspot component of OpenJDK 8 was not properly bounding certain UTF-8 strings, which could lead to a buffer overflow. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2024-21131) It was discovered that the Hotspot component of OpenJDK 8 could be made to run into an infinite loop. If an automated system were tricked into processing excessively large symbols, an attacker could possibly use this issue to cause a denial of service. (CVE-2024-21138) It was discovered that the Hotspot component of OpenJDK 8 did not properly perform range check elimination. An attacker could possibly use this issue to cause a denial of service, execute arbitrary code or bypass Java sandbox restrictions. (CVE-2024-21140) Yakov Shafranovich discovered that the Concurrency component of OpenJDK 8 incorrectly performed header validation in the Pack200 archive format. An attacker could possibly use this issue to cause a denial of service. (CVE-2024-21144) Sergey Bylokhov discovered that OpenJDK 8 did not properly manage memory when handling 2D images. An attacker could possibly use this issue to obtain sensitive information. (CVE-2024-21145) It was discovered that the Hotspot component of OpenJDK 8 incorrectly handled memory when performing range check elimination under certain circumstances. An attacker could possibly use this issue to cause a denial of service, execute arbitrary code or bypass Java sandbox restrictions. (CVE-2024-21147)
Affected Software
Event History
Child vulnerabilities
Contains the following vulnerabilities.
Frequently Asked Questions
What is the severity of USN-6929-1?
The severity of USN-6929-1 is critical due to the potential for buffer overflow leading to denial of service or arbitrary code execution.
How do I fix USN-6929-1?
To fix USN-6929-1, upgrade to the affected packages versions 8u422-b05-1~24.04 or newer on Ubuntu 24.04.
What systems are affected by USN-6929-1?
USN-6929-1 affects Ubuntu 20.04, 22.04, and 24.04 systems running OpenJDK 8.
Can USN-6929-1 lead to remote code execution?
Yes, USN-6929-1 can potentially allow an attacker to execute arbitrary code remotely.
What should I do if I can't update due to USN-6929-1?
If unable to update due to USN-6929-1, consider implementing temporary security measures, such as restricting access to affected services.