[CLSA-2024:1732197150] Fix of 20 CVEs
Type:
security
Severity:
Important
Release date:
2024-11-21 13:52:39 UTC
Description:
* Update to 8u432-ga fixing a number of CVEs - CVE-2024-20918: missing array range check in C1 compiler leads to out-of-bounds access - CVE-2024-20919: unverified bytecode execution because of the flaw in JVM class file verifier - CVE-2024-20921: optimization issue of loop range check in IfNode and LoopNode - CVE-2024-20926: execution of arbitrary Java code in Nashorn - CVE-2024-20945: private keys for digital signatures leak to logs - CVE-2024-20952: RSA padding problem, TLS timing side-channel attack - CVE-2024-21011: extended Exception message causing a crash - CVE-2024-21068: Integer overflow in address generation by the C1 compiler - CVE-2024-21085: excessive memory allocation in Pack200 - CVE-2024-21094: "exceeded _node_regs array" C2 compilation error - CVE-2024-21131: UTF8 size overflow - CVE-2024-21138: infinite loop vunlerability in SymbolTable - CVE-2024-21140: int overflow/underflow in Range Check Elimination - CVE-2024-21144: invalid header validation leads to Pack200 excessive loading time - CVE-2024-21145: out-of-bounds access in MaskFill - CVE-2024-21147: out-of-bounds array index in Range Check Elimination - CVE-2024-21208: improper handling of maxHeaderSize in HTTP client - CVE-2024-21210: integer overflow in array indexing in SuperWord - CVE-2024-21217: out-of-memory because of unbounded allocation in MessageFormat - CVE-2024-21235: incorrect range check because of integer conversion error in LoopNode * Update patches - debian/patches/zero-sh.diff
Updated packages:
  • openjdk-8-demo_8u432-ga-0ubuntu1~16.04+tuxcare.els1_amd64.deb
    sha:8019cc68a143d24a414da28840b803225c9199a6
  • openjdk-8-doc_8u432-ga-0ubuntu1~16.04+tuxcare.els1_all.deb
    sha:60ea17bd3b212e81e60ee9e37e55d2db9301b9a5
  • openjdk-8-jdk_8u432-ga-0ubuntu1~16.04+tuxcare.els1_amd64.deb
    sha:8ea493842f94fd2d8b392af78f94c668ed0d5ea8
  • openjdk-8-jdk-headless_8u432-ga-0ubuntu1~16.04+tuxcare.els1_amd64.deb
    sha:debcb674b93e41449123d4615f7bb8cdd7c03799
  • openjdk-8-jre_8u432-ga-0ubuntu1~16.04+tuxcare.els1_amd64.deb
    sha:edf78d0a1895bd57c5244d03ebb48a671e4a24d9
  • openjdk-8-jre-headless_8u432-ga-0ubuntu1~16.04+tuxcare.els1_amd64.deb
    sha:199cab9229fdf0aa8c072b0fc725f064f9cbe59a
  • openjdk-8-jre-jamvm_8u432-ga-0ubuntu1~16.04+tuxcare.els1_amd64.deb
    sha:e1318066eabdea4885fea81d1cb6318af4d3e371
  • openjdk-8-jre-zero_8u432-ga-0ubuntu1~16.04+tuxcare.els1_amd64.deb
    sha:472e9a2dea9f43d034974fa9c0705e7caf1409ad
  • openjdk-8-source_8u432-ga-0ubuntu1~16.04+tuxcare.els1_all.deb
    sha:c10d56bd0a16b900fc25d334bd48f040b094cf33
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.