CVE-2023-5676: Eclipse OpenJ9 possible infinite busy hang
IBM JDK 7 R1 SR5 FP20 (7.1.5.20) and 8 SR8 FP15 (8.0.8.15) fix a flaw described by upstream as: Eclipse OpenJ9 is vulnerable to a denial of service, caused by a flaw when a shutdown signal (SIGTERM, SIGINT or SIGHUP) is received before the JVM has finished initializing. By sending a specially crafted request, a local authenticated attacker could exploit this vulnerability to cause an infinite busy hang on a spinlock or a segmentation fault. OpenJ9 upstream references: https://github.com/eclipse-openj9/openj9/pull/18085 https://gitlab.eclipse.org/security/cve-assignement/-/issues/13 IBM JDK references: https://www.ibm.com/support/pages/node/7078433 https://www.ibm.com/support/pages/apar/IJ49075 https://www.ibm.com/support/pages/java-sdk-security-vulnerabilities#IBM_Security_Update_November_2023
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for Eclipse OpenJ9?
The vulnerability ID for Eclipse OpenJ9 is CVE-2023-5676.
What is the severity of CVE-2023-5676?
The severity of CVE-2023-5676 is medium with a severity value of 5.9.
How can the JVM in Eclipse OpenJ9 be forced into an infinite busy hang?
The JVM in Eclipse OpenJ9 can be forced into an infinite busy hang if a shutdown signal (SIGTERM, SIGINT, or SIGHUP) is received before the JVM has finished initializing.
Which version of Eclipse OpenJ9 is affected by CVE-2023-5676?
Eclipse OpenJ9 before version 0.41.0 is affected by CVE-2023-5676.
Are there any references for CVE-2023-5676?
Yes, you can find references for CVE-2023-5676 at the following links: [Link 1](https://github.com/eclipse-openj9/openj9/pull/18085), [Link 2](https://gitlab.eclipse.org/security/cve-assignement/-/issues/13).