[CLSA-2024:1726773559] Fix of 5 CVEs
Type:
security
Severity:
Low
Release date:
2024-09-19 19:19:33 UTC
Description:
* Backport upstream's fixes from OpenJDK 11.0.23 release. - CVE-2024-21011: possible crash on long exception message in Hotspot. - CVE-2024-21012: incorrect performing a reverse DNS query in ConnectionPool class. - CVE-2024-21068: incorrect applying an unsigned integer left shift in Hotspot. - CVE-2024-21085: incorrect memory size validation by the NativeUnpack class. - CVE-2024-21094: possible C2 compilation error due to incorrect size validation and out of bounds array access in Hotspot.
Updated packages:
  • openjdk-11-demo_11.0.22+7-0ubuntu1~18.04.1+tuxcare.els2_amd64.deb
    sha:fa8571263bcda17bee2f08ab8e85829cfa998803
  • openjdk-11-doc_11.0.22+7-0ubuntu1~18.04.1+tuxcare.els2_all.deb
    sha:e8a240f09d8838592f93f89bff99b4f4ba1f5674
  • openjdk-11-jdk_11.0.22+7-0ubuntu1~18.04.1+tuxcare.els2_amd64.deb
    sha:e53617b7a984ca6f1000b8df034f98ae8090191c
  • openjdk-11-jdk-headless_11.0.22+7-0ubuntu1~18.04.1+tuxcare.els2_amd64.deb
    sha:b1e7dd76a1b8c88c89a569536b31b35bc3f6f4dc
  • openjdk-11-jre_11.0.22+7-0ubuntu1~18.04.1+tuxcare.els2_amd64.deb
    sha:3c85461e51636942552ba75a7dcda6afe42fdfc7
  • openjdk-11-jre-headless_11.0.22+7-0ubuntu1~18.04.1+tuxcare.els2_amd64.deb
    sha:c4779c9f7ff252a01a2f06a7b7a94596d05b0d27
  • openjdk-11-jre-zero_11.0.22+7-0ubuntu1~18.04.1+tuxcare.els2_amd64.deb
    sha:f6ba51fa44120deb59a988ea390e41f7250faacc
  • openjdk-11-source_11.0.22+7-0ubuntu1~18.04.1+tuxcare.els2_all.deb
    sha:ff64534328700d1af05613c46eac377424b1cf87
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.