RHSA-2021:3889: Important: java-1.8.0-openjdk security and bug fix update
The java-1.8.0-openjdk packages provide the OpenJDK 8 Java Runtime Environment and the OpenJDK 8 Java Software Development Kit.<br>Security Fix(es):<br><li> OpenJDK: Loop in HttpsServer triggered during TLS session close (JSSE, 8254967) (CVE-2021-35565)</li> <li> OpenJDK: Incorrect principal selection when using Kerberos Constrained Delegation (Libraries, 8266689) (CVE-2021-35567)</li> <li> OpenJDK: Weak ciphers preferred over stronger ones for TLS (JSSE, 8264210) (CVE-2021-35550)</li> <li> OpenJDK: Excessive memory allocation in RTFParser (Swing, 8265167) (CVE-2021-35556)</li> <li> OpenJDK: Excessive memory allocation in RTFReader (Swing, 8265580) (CVE-2021-35559)</li> <li> OpenJDK: Excessive memory allocation in HashMap and HashSet (Utility, 8266097) (CVE-2021-35561)</li> <li> OpenJDK: Certificates with end dates too far in the future can corrupt keystore (Keytool, 8266137) (CVE-2021-35564)</li> <li> OpenJDK: Unexpected exception raised during TLS handshake (JSSE, 8267729) (CVE-2021-35578)</li> <li> OpenJDK: Excessive memory allocation in BMPImageReader (ImageIO, 8267735) (CVE-2021-35586)</li> <li> OpenJDK: Incomplete validation of inner class references in ClassFileParser (Hotspot, 8268071) (CVE-2021-35588)</li> <li> OpenJDK: Non-constant comparison during TLS handshakes (JSSE, 8269618) (CVE-2021-35603)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.<br>Bug Fix(es):<br><li> A defensive security change in an earlier OpenJDK update led to a performance degradation when using the Scanner class. This was due to the change being applied to many common cases that did not need this protection. With this update, we provide the original behaviour for these cases. (RHBZ#1862929)</li>
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2021:3889?
The severity of RHSA-2021:3889 is classified as a critical vulnerability.
How do I fix RHSA-2021:3889?
To fix RHSA-2021:3889, upgrade to the patched version 1.8.0-openjdk-1.8.0.312.b07-1.el7_9 or higher.
What vulnerabilities are addressed in RHSA-2021:3889?
RHSA-2021:3889 addresses vulnerabilities such as CVE-2021-35565 affecting the OpenJDK.
Is RHSA-2021:3889 applicable to all OpenJDK installations?
RHSA-2021:3889 is applicable specifically to versions of OpenJDK 8 provided by Red Hat.
What products are affected by RHSA-2021:3889?
Affected products include various packages of OpenJDK 8, specifically version 1.8.0.312.b07-1.el7_9 from Red Hat.