java-21-openjdk-21.0.2.0.13-1.el8.ML.1

エラータID: AXSA:2024-7439:03

Release date: 
Tuesday, January 23, 2024 - 02:53
Subject: 
java-21-openjdk-21.0.2.0.13-1.el8.ML.1
Affected Channels: 
Asianux Server 8 for x86_64
Severity: 
High
Description: 

The java-21-openjdk packages provide the OpenJDK 21 Java Runtime Environment and the OpenJDK 21 Java Software Development Kit.

Security Fix(es):

* OpenJDK: array out-of-bounds access due to missing range check in C1 compiler (8314468) (CVE-2024-20918)
* OpenJDK: RSA padding issue and timing side-channel attack against TLS (8317547) (CVE-2024-20952)
* OpenJDK: JVM class file verifier flaw allows unverified bytecode execution (8314295) (CVE-2024-20919)
* OpenJDK: range check loop optimization issue (8314307) (CVE-2024-20921)
* OpenJDK: logging of digital signature private keys (8316976) (CVE-2024-20945)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2024-20918
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u391, 8u391-perf, 11.0.21, 17.0.9, 21.0.1; Oracle GraalVM for JDK: 17.0.9, 21.0.1; Oracle GraalVM Enterprise Edition: 20.3.12, 21.3.8 and 22.3.4. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data as well as unauthorized access to critical data or complete access to all Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).
CVE-2024-20919
RESERVED
CVE-2024-20921
RESERVED
CVE-2024-20945
RESERVED
CVE-2024-20952
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versions that are affected are Oracle Java SE: 8u391, 8u391-perf, 11.0.21, 17.0.9, 21.0.1; Oracle GraalVM for JDK: 17.0.9, 21.0.1; Oracle GraalVM Enterprise Edition: 20.3.12, 21.3.8 and 22.3.4. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data as well as unauthorized access to critical data or complete access to all Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. java-21-openjdk-21.0.2.0.13-1.el8.ML.1.src.rpm
    MD5: 4f56ba1927e7d45fd7fcf96e7175bc33
    SHA-256: c20517a28c6c318ecebc8e8271c6370bd509edb019a4ec0af08ebccbda7da2d4
    Size: 65.69 MB

Asianux Server 8 for x86_64
  1. java-21-openjdk-21.0.2.0.13-1.el8.ML.1.x86_64.rpm
    MD5: 396361d84ebb90c9caed24011b71940b
    SHA-256: 3a2dfe8d328d72688d5462ff2b8f199810dc199f9bf2a13b2cd427354d4b7ebd
    Size: 438.93 kB
  2. java-21-openjdk-demo-21.0.2.0.13-1.el8.ML.1.x86_64.rpm
    MD5: 48629319c94dd155618be9b11e064f26
    SHA-256: 6fe8181b6079d1dfe38f9b05bffe5eec8f74a2d60c3392f224988c20c37b2ed3
    Size: 3.16 MB
  3. java-21-openjdk-demo-fastdebug-21.0.2.0.13-1.el8.ML.1.x86_64.rpm
    MD5: 0b2bf1accab2dfd96be1de0681f8f495
    SHA-256: df59e1bd2d29fc1f8b368b1ecc5ae1a6f158af297683a556e8665e66f10fb54f
    Size: 3.16 MB
  4. java-21-openjdk-demo-slowdebug-21.0.2.0.13-1.el8.ML.1.x86_64.rpm
    MD5: 09bc1d2da35e2094f404764257396fae
    SHA-256: 6ce16f3747566ca11b288de0a5f1c87821de1d443cc2ca4cc1c1c5c031752a51
    Size: 3.16 MB
  5. java-21-openjdk-devel-21.0.2.0.13-1.el8.ML.1.x86_64.rpm
    MD5: f50eb7d2e8488127f2177c9fd8429336
    SHA-256: cee153e3aa85d3ff876501c8da3e058a0ea042c51a7e412eec0a344e27d833d9
    Size: 5.16 MB
  6. java-21-openjdk-devel-fastdebug-21.0.2.0.13-1.el8.ML.1.x86_64.rpm
    MD5: e905751f1ac74ba3a8845aabecb2a49d
    SHA-256: 846bbbbb6b1e57fc6a90b9af6bea42792c727902591bd41ac62e38970f0dbd7f
    Size: 5.16 MB
  7. java-21-openjdk-devel-slowdebug-21.0.2.0.13-1.el8.ML.1.x86_64.rpm
    MD5: 69c90f0241cffc777af942bd0bfe768f
    SHA-256: ca2c6bcd290374da198f221113e78827f3ad62303c5446955dcaa15f3b3d8eaa
    Size: 5.16 MB
  8. java-21-openjdk-fastdebug-21.0.2.0.13-1.el8.ML.1.x86_64.rpm
    MD5: 4e78dc4b0349b3e66cb99ca77442e714
    SHA-256: 10586585fec2e2e0f79bbf3c74f27c918cec5ac3e60cc6fbd1d8a3a37a91198e
    Size: 448.35 kB
  9. java-21-openjdk-headless-21.0.2.0.13-1.el8.ML.1.x86_64.rpm
    MD5: 4e71ef0745da0e2778a06f75d8894642
    SHA-256: d8d0145640892ccc2952e83594b69fd7ae11bd74e008b25ae8fd425f68c4a333
    Size: 49.74 MB
  10. java-21-openjdk-headless-fastdebug-21.0.2.0.13-1.el8.ML.1.x86_64.rpm
    MD5: ac1ec3853d4b41d9a2da9aab3358323f
    SHA-256: e711218d831e402b44c3d96da44370d6e3cbf4972d060625ce5a976cc881b8d3
    Size: 54.56 MB
  11. java-21-openjdk-headless-slowdebug-21.0.2.0.13-1.el8.ML.1.x86_64.rpm
    MD5: 83012ecc32a909556c324868ff354e20
    SHA-256: 92cf789d1c704d25f22f475c00c564205a5d571e11f95ef699016b0ea5402a34
    Size: 54.35 MB
  12. java-21-openjdk-javadoc-21.0.2.0.13-1.el8.ML.1.x86_64.rpm
    MD5: 79fab820d8f6ea31ff97e47c35bd0532
    SHA-256: 17952e908515582df4c63fcb9020fb29adb8c3d68d87e75c5eff91d7607709ce
    Size: 16.34 MB
  13. java-21-openjdk-javadoc-zip-21.0.2.0.13-1.el8.ML.1.x86_64.rpm
    MD5: f23e2d1232caa3d804f31310051f8638
    SHA-256: 3953b6a06bc1235b7bc554a1453a7161f738ac3c43cbc747e72f1c01936270d6
    Size: 41.43 MB
  14. java-21-openjdk-jmods-21.0.2.0.13-1.el8.ML.1.x86_64.rpm
    MD5: 312826d0dad8d1c35bd63b95f4dc5524
    SHA-256: 00beb9c4576a8adb24d4a1385cc661f2294c3d7ae14d8188de0b4ecc8eb244aa
    Size: 311.59 MB
  15. java-21-openjdk-jmods-fastdebug-21.0.2.0.13-1.el8.ML.1.x86_64.rpm
    MD5: ba21eacbea449e3dfd24a83a701b3b1a
    SHA-256: 837b3354f564d42028a9aa4783db7d2562e2c6d730f816dcaa3bf87e20a472f4
    Size: 369.19 MB
  16. java-21-openjdk-jmods-slowdebug-21.0.2.0.13-1.el8.ML.1.x86_64.rpm
    MD5: 9ad09c53c9cb0b7127e093054ab4aa57
    SHA-256: 76b451e19bfd8a4030f4e15c230f947832242df5131087e9117e433d56040239
    Size: 290.51 MB
  17. java-21-openjdk-slowdebug-21.0.2.0.13-1.el8.ML.1.x86_64.rpm
    MD5: 5c8bd8a1cd84655dfe42b51992751614
    SHA-256: 7edb796faaa2af4dd56ad24b2de2818434f8ae1cd742427970ffb96a0dfa09ee
    Size: 425.14 kB
  18. java-21-openjdk-src-21.0.2.0.13-1.el8.ML.1.x86_64.rpm
    MD5: 3e86be67d7269c542947a23769886ab0
    SHA-256: d1abdfbf5fefb165ea8f23426a214e6f842dcf07ca419d1264598850ad0bd5bb
    Size: 47.30 MB
  19. java-21-openjdk-src-fastdebug-21.0.2.0.13-1.el8.ML.1.x86_64.rpm
    MD5: e72cc6ead8c1a4e2ff7f32711fa2527b
    SHA-256: 5b71e2e796ac0b7a1ecef45e6cc92b4caa27d7467dbdc937f15618789ddf1d84
    Size: 47.30 MB
  20. java-21-openjdk-src-slowdebug-21.0.2.0.13-1.el8.ML.1.x86_64.rpm
    MD5: 54ece96e085090280dabc5557a5f0f6a
    SHA-256: 15d3742a87e624bca0f372db83dba08bb1d64238e2d51a260edbf057670b48c9
    Size: 47.30 MB
  21. java-21-openjdk-static-libs-21.0.2.0.13-1.el8.ML.1.x86_64.rpm
    MD5: b6efa9f41aca55b3dde8744c7eab0dbf
    SHA-256: 900991c1c178b52736a682990ee8d588a23fa2c323464a10e2c75d664d854e92
    Size: 39.79 MB
  22. java-21-openjdk-static-libs-fastdebug-21.0.2.0.13-1.el8.ML.1.x86_64.rpm
    MD5: 19e79563024843369edea08e972dc7a0
    SHA-256: ab628f5c315ab933322236db8c5ad3d4780befd67bb73b7c3bf109bb95128dfd
    Size: 40.04 MB
  23. java-21-openjdk-static-libs-slowdebug-21.0.2.0.13-1.el8.ML.1.x86_64.rpm
    MD5: f91b2ca0fb1d172b47c169771b4c0a44
    SHA-256: 1cc60c1e132418a7c56c4d8a738173d3f633cfa60e05743a156891beb07def89
    Size: 34.29 MB