Release date:
2024-11-21 13:52:39 UTC
Description:
* Update to 8u432-ga fixing a number of CVEs
- CVE-2024-20918: missing array range check in C1 compiler leads to
out-of-bounds access
- CVE-2024-20919: unverified bytecode execution because of the flaw in
JVM class file verifier
- CVE-2024-20921: optimization issue of loop range check in IfNode and
LoopNode
- CVE-2024-20926: execution of arbitrary Java code in Nashorn
- CVE-2024-20945: private keys for digital signatures leak to logs
- CVE-2024-20952: RSA padding problem, TLS timing side-channel attack
- CVE-2024-21011: extended Exception message causing a crash
- CVE-2024-21068: Integer overflow in address generation by the C1
compiler
- CVE-2024-21085: excessive memory allocation in Pack200
- CVE-2024-21094: "exceeded _node_regs array" C2 compilation error
- CVE-2024-21131: UTF8 size overflow
- CVE-2024-21138: infinite loop vunlerability in SymbolTable
- CVE-2024-21140: int overflow/underflow in Range Check Elimination
- CVE-2024-21144: invalid header validation leads to Pack200 excessive
loading time
- CVE-2024-21145: out-of-bounds access in MaskFill
- CVE-2024-21147: out-of-bounds array index in Range Check Elimination
- CVE-2024-21208: improper handling of maxHeaderSize in HTTP client
- CVE-2024-21210: integer overflow in array indexing in SuperWord
- CVE-2024-21217: out-of-memory because of unbounded allocation in
MessageFormat
- CVE-2024-21235: incorrect range check because of integer conversion
error in LoopNode
* Update patches
- debian/patches/zero-sh.diff
Updated packages:
-
openjdk-8-demo_8u432-ga-0ubuntu1~16.04+tuxcare.els1_amd64.deb
sha:8019cc68a143d24a414da28840b803225c9199a6
-
openjdk-8-doc_8u432-ga-0ubuntu1~16.04+tuxcare.els1_all.deb
sha:60ea17bd3b212e81e60ee9e37e55d2db9301b9a5
-
openjdk-8-jdk_8u432-ga-0ubuntu1~16.04+tuxcare.els1_amd64.deb
sha:8ea493842f94fd2d8b392af78f94c668ed0d5ea8
-
openjdk-8-jdk-headless_8u432-ga-0ubuntu1~16.04+tuxcare.els1_amd64.deb
sha:debcb674b93e41449123d4615f7bb8cdd7c03799
-
openjdk-8-jre_8u432-ga-0ubuntu1~16.04+tuxcare.els1_amd64.deb
sha:edf78d0a1895bd57c5244d03ebb48a671e4a24d9
-
openjdk-8-jre-headless_8u432-ga-0ubuntu1~16.04+tuxcare.els1_amd64.deb
sha:199cab9229fdf0aa8c072b0fc725f064f9cbe59a
-
openjdk-8-jre-jamvm_8u432-ga-0ubuntu1~16.04+tuxcare.els1_amd64.deb
sha:e1318066eabdea4885fea81d1cb6318af4d3e371
-
openjdk-8-jre-zero_8u432-ga-0ubuntu1~16.04+tuxcare.els1_amd64.deb
sha:472e9a2dea9f43d034974fa9c0705e7caf1409ad
-
openjdk-8-source_8u432-ga-0ubuntu1~16.04+tuxcare.els1_all.deb
sha:c10d56bd0a16b900fc25d334bd48f040b094cf33
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.