QID 242868

Date Published: 2024-02-07

QID 242868: Red Hat Update for java-17-openjdk (RHSA-2024:0244)

The java-17-openjdk packages provide the openjdk 17 java runtime environment and the openjdk 17 java software development kit...Security Fix(es):

    openjdk: array out-of-bounds access due to missing range check in c1 compiler (8314468) (cve-2024-20918).
    Openjdk: incorrect handling of zip files with duplicate entries (8276123) (cve-2024-20932).
    Openjdk: rsa padding issue and timing side-channel attack against tls (8317547) (cve-2024-20952).
    Openjdk: jvm class file verifier flaw allows unverified bytecode execution (8314295) (cve-2024-20919).
    Openjdk: range check loop optimization issue (8314307) (cve-2024-20921).
    Openjdk: logging of digital signature private keys (8316976) (cve-2024-20945).
Affected Products:
    Red Hat enterprise linux for x86_64 - extended update support 9.0 x86_64.
    Red hat enterprise linux for ibm z systems - extended update support 9.0 s390x.
    Red hat enterprise linux for power, little endian - extended update support 9.0 ppc64le.
    Red hat enterprise linux for arm 64 - extended update support 9.0 aarch64.
    Red hat enterprise linux server for power le - update services for sap solutions 9.0 ppc64le.
    Red hat enterprise linux for x86_64 - update services for sap solutions 9.0 x86_64.
    Red hat codeready linux builder for x86_64 - extended update support 9.0 x86_64.
    Red hat codeready linux builder for power, little endian - extended update support 9.0 ppc64le.
    Red hat codeready linux builder for ibm z systems - extended update support 9.0 s390x.
    Red hat codeready linux builder for arm 64 - extended update support 9.0 aarch64.
    Red hat enterprise linux server for arm 64 - 4 years of updates 9.0 aarch64.
    Red hat enterprise linux server for ibm z systems - 4 years of updates 9.0 s390x.
.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5.4 severity.
  • Solution
    Refer to Red Hat security advisory RHSA-2024:0244 for updates and patch information.
    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    RHSA-2024:0244 Red Hat Enterprise Linux URL Logo access.redhat.com/errata/RHSA-2024:0244