RHSA-2021:3892: Important: java-11-openjdk security and bug fix update
The java-11-openjdk packages provide the OpenJDK 11 Java Runtime Environment and the OpenJDK 11 Java Software Development Kit.Security Fix(es): OpenJDK: Loop in HttpsServer triggered during TLS session close (JSSE, 8254967) (CVE-2021-35565) OpenJDK: Incorrect principal selection when using Kerberos Constrained Delegation (Libraries, 8266689) (CVE-2021-35567) OpenJDK: Weak ciphers preferred over stronger ones for TLS (JSSE, 8264210) (CVE-2021-35550) OpenJDK: Excessive memory allocation in RTFParser (Swing, 8265167) (CVE-2021-35556) OpenJDK: Excessive memory allocation in RTFReader (Swing, 8265580) (CVE-2021-35559) OpenJDK: Excessive memory allocation in HashMap and HashSet (Utility, 8266097) (CVE-2021-35561) OpenJDK: Certificates with end dates too far in the future can corrupt keystore (Keytool, 8266137) (CVE-2021-35564) OpenJDK: Unexpected exception raised during TLS handshake (JSSE, 8267729) (CVE-2021-35578) OpenJDK: Excessive memory allocation in BMPImageReader (ImageIO, 8267735) (CVE-2021-35586) OpenJDK: Non-constant comparison during TLS handshakes (JSSE, 8269618) (CVE-2021-35603) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Bug Fix(es): Previously, uninstalling the OpenJDK RPMs attempted to remove a client directory that did not exist. This directory is no longer used in java-11-openjdk and all references to it have now been removed. (RHBZ#1698873)
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2021:3892?
The severity of RHSA-2021:3892 is considered important due to the potential impact of the vulnerabilities addressed.
How do I fix RHSA-2021:3892?
To fix RHSA-2021:3892, update the OpenJDK packages to version 11-openjdk-11.0.13.0.8-1.el7_9 or later.
What vulnerabilities are addressed in RHSA-2021:3892?
RHSA-2021:3892 addresses vulnerabilities including CVE-2021-35565, which involves a loop in HttpsServer triggered during TLS session close.
What versions of OpenJDK are affected by RHSA-2021:3892?
The affected versions are all versions below 11-openjdk-11.0.13.0.8-1.el7_9.
Is there any specific software impacted by RHSA-2021:3892?
Yes, RHSA-2021:3892 impacts multiple OpenJDK packages, including java, java-debuginfo, and java-devel.