RHSA-2021:3961: Important: OpenJDK 8u312 Windows Builds release and security update
The OpenJDK 8 packages provide the OpenJDK 8 Java Runtime Environment and the OpenJDK 8 Java Software Development Kit.This release of the Red Hat build of OpenJDK 8 (1.8.0.312) for Windows serves as a replacement for the Red Hat build of OpenJDK 8 (1.8.0.302) and includes security and bug fixes, and enhancements. For further information, refer to the release notes linked to in the References section.Security Fix(es): OpenJDK: Loop in HttpsServer triggered during TLS session close (JSSE, 8254967) (CVE-2021-35565) OpenJDK: Incorrect principal selection when using Kerberos Constrained Delegation (Libraries, 8266689) (CVE-2021-35567) OpenJDK: Weak ciphers preferred over stronger ones for TLS (JSSE, 8264210) (CVE-2021-35550) OpenJDK: Excessive memory allocation in RTFParser (Swing, 8265167) (CVE-2021-35556) OpenJDK: Excessive memory allocation in RTFReader (Swing, 8265580) (CVE-2021-35559) OpenJDK: Excessive memory allocation in HashMap and HashSet (Utility, 8266097) (CVE-2021-35561) OpenJDK: Certificates with end dates too far in the future can corrupt keystore (Keytool, 8266137) (CVE-2021-35564) OpenJDK: Unexpected exception raised during TLS handshake (JSSE, 8267729) (CVE-2021-35578) OpenJDK: Excessive memory allocation in BMPImageReader (ImageIO, 8267735) (CVE-2021-35586) OpenJDK: Incomplete validation of inner class references in ClassFileParser (Hotspot, 8268071) (CVE-2021-35588) OpenJDK: Non-constant comparison during TLS handshakes (JSSE, 8269618) (CVE-2021-35603) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Event History
Frequently Asked Questions
What is the severity of RHSA-2021:3961?
The vulnerability identified by RHSA-2021:3961 has been classified with a critical severity rating.
How do I fix RHSA-2021:3961?
To resolve the issues related to RHSA-2021:3961, you should upgrade to the updated OpenJDK 8 packages provided in the advisory.
What software is affected by RHSA-2021:3961?
RHSA-2021:3961 affects the Red Hat build of OpenJDK 8 for Windows.
When was RHSA-2021:3961 released?
RHSA-2021:3961 was released to address security vulnerabilities on the date of the advisory publication.
Are there known exploits for RHSA-2021:3961?
Yes, there are known exploits associated with the vulnerabilities addressed in RHSA-2021:3961.