RHSA-2024:0267 -- Redhat java-17-openjdkID: oval:org.secpod.oval:def:509063 | Date: (C)2024-03-04 (M)2024-04-29 |
Class: PATCH | Family: unix |
The java-17-openjdk packages provide the OpenJDK 17 Java Runtime Environment and the OpenJDK 17 Java Software Development Kit. Security Fix: OpenJDK: array out-of-bounds access due to missing range check in C1 compiler OpenJDK: incorrect handling of ZIP files with duplicate entries OpenJDK: RSA padding issue and timing side-channel attack against TLS OpenJDK: JVM class file verifier flaw allows unverified bytecode execution OpenJDK: range check loop optimization issue OpenJDK: logging of digital signature private keys For more details about the security issue, including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page listed in the References section. Bug Fix: When Transparent Huge Pages are unconditionally enabled on a system, Java applications using many threads were found to have a large Resident Set Size . This was due to a race between the kernel transforming thread stack memory into huge pages and the Java Virtual Machine shattering these pages into smaller ones when adding a guard page. This release resolves this issue by getting glibc to insert a guard page and prevent the creation of huge pages
Platform: |
Red Hat Enterprise Linux 9 |
Red Hat Enterprise Linux 8 |