Alerts This Week
Warning Icon 1 681
Alerts This Week
Warning Icon 1 681

Critical Java Security Issues Addressed in Mageia 9 MGASA-2024-0061

mageia
Calendar Grey March 15, 2024
Dist Mageia Esm H88
Revised software components for Mageia 9 tackle vulnerabilities such as buffer overflows and timing infiltration.
The updated packages fix security vulnerabilities: Array out-of-bounds access due to missing range check in C1 compiler

Summary

The updated packages fix security vulnerabilities: Array out-of-bounds access due to missing range check in C1 compiler. (CVE-2024-20918) RSA padding issue and timing side-channel attack against TLS. (CVE-2024-20952) Arbitrary Java code execution in Nashorn. (CVE-2024-20926) JVM class file verifier flaw allows unverified bytecode execution. (CVE-2024-20919) Range check loop optimization issue. (CVE-2024-20921) Logging of digital signature private keys. (CVE-2024-20945)

References

- https://bugs.mageia.org/show_bug.cgi?id=32724

- https://access.redhat.com/errata/RHSA-2024:0225

- https://access.redhat.com/errata/RHSA-2024:0234

- https://access.redhat.com/errata/RHSA-2024:0249

- https://www.cve.org/CVERecord?id=CVE-2024-20918

- https://www.cve.org/CVERecord?id=CVE-2024-20952

- https://www.cve.org/CVERecord?id=CVE-2024-20926

- https://www.cve.org/CVERecord?id=CVE-2024-20919

- https://www.cve.org/CVERecord?id=CVE-2024-20921

- https://www.cve.org/CVERecord?id=CVE-2024-20945

Resolution

SRPMS

- 9/core/java-11-openjdk-11.0.22.0.7-1.mga9

- 9/core/java-1.8.0-openjdk-1.8.0.402.b06-1.mga9

- 9/core/java-latest-openjdk-21.0.2.0.13-1.rolling.1.mga9

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 15 Mar 2024
URL: https://advisories.mageia.org/MGASA-2024-0061.html
Type: security
CVE: CVE-2024-20918, CVE-2024-20952, CVE-2024-20926, CVE-2024-20919, CVE-2024-20921, CVE-2024-20945

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here