[CLSA-2024:1726773716] Fix CVE(s): CVE-2024-21011, CVE-2024-21068, CVE-2024-21085, CVE-2024-21094
Type:
security
Severity:
Low
Release date:
2024-09-19 19:22:04 UTC
Description:
* Backport upstream's fixes from OpenJDK 8u412 release. - CVE-2024-21011: possible crash on long exception message in Hotspot. - CVE-2024-21068: incorrect applying an unsigned integer left shift in Hotspot. - CVE-2024-21085: incorrect memory size validation by the NativeUnpack class. - CVE-2024-21094: possible C2 compilation error due to incorrect size validation and out of bounds array access in Hotspot.
Updated packages:
  • openjdk-8-demo_8u402-ga-0ubuntu1~18.04+tuxcare.els2_amd64.deb
    sha:f08aca228bbe9bcc2f5a591fb85274accd5ca1ab
  • openjdk-8-doc_8u402-ga-0ubuntu1~18.04+tuxcare.els2_all.deb
    sha:9dc0bcf616a74ae6ebef93cd59e5a4f4ac05d163
  • openjdk-8-jdk_8u402-ga-0ubuntu1~18.04+tuxcare.els2_amd64.deb
    sha:8703ec0390d7237329e637087e3ad53ad8077319
  • openjdk-8-jdk-headless_8u402-ga-0ubuntu1~18.04+tuxcare.els2_amd64.deb
    sha:ccad9ee3f4e6be1a95f4194a6a4cc736bff3aca8
  • openjdk-8-jre_8u402-ga-0ubuntu1~18.04+tuxcare.els2_amd64.deb
    sha:a188c7091f95d4b0fea94a9059d603058c0dadca
  • openjdk-8-jre-headless_8u402-ga-0ubuntu1~18.04+tuxcare.els2_amd64.deb
    sha:8f04d8eac708bce9361c72094daecc0d05c27c6d
  • openjdk-8-jre-zero_8u402-ga-0ubuntu1~18.04+tuxcare.els2_amd64.deb
    sha:a4f5435ef20b389827336ce71683c74a4e7f8820
  • openjdk-8-source_8u402-ga-0ubuntu1~18.04+tuxcare.els2_all.deb
    sha:5770c53c5eba473240a50b3e63e5093481037b31
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.