RHSA-2024:0240HighCVSS 7.5
Red Hat Security Advisory: OpenJDK 17.0.10 security update
🔗 CVE IDs covered (6)
📋 Description
CVE-2024-20918 — OpenJDK: array out-of-bounds access due to missing range check in C1 compiler (8314468) CVE-2024-20919 — OpenJDK: JVM class file verifier flaw allows unverified bytecode execution (8314295) CVE-2024-20921 — OpenJDK: range check loop optimization issue (8314307) CVE-2024-20932 — OpenJDK: incorrect handling of ZIP files with duplicate entries (8276123) CVE-2024-20945 — OpenJDK: logging of digital signature private keys (8316976) CVE-2024-20952 — OpenJDK: RSA padding issue and timing side-channel attack against TLS (8317547)
🎯 Affected products1
- Red Hat Build of OpenJDK 17.0.10
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258
🔗 References (9)
- selfhttps://access.redhat.com/errata/RHSA-2024:0240
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2257720
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2257728
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2257837
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2257853
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2257859
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2257874
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_0240.json