{"id":"CLSA-2024-1732197150","summary":"Fix of 20 CVEs","details":"   * Update to 8u432-ga fixing a number of CVEs\n     - CVE-2024-20918: missing array range check in C1 compiler leads to\n       out-of-bounds access\n     - CVE-2024-20919: unverified bytecode execution because of the flaw in\n       JVM class file verifier\n     - CVE-2024-20921: optimization issue of loop range check in IfNode and\n       LoopNode\n     - CVE-2024-20926: execution of arbitrary Java code in Nashorn\n     - CVE-2024-20945: private keys for digital signatures leak to logs\n     - CVE-2024-20952: RSA padding problem, TLS timing side-channel attack\n     - CVE-2024-21011: extended Exception message causing a crash\n     - CVE-2024-21068: Integer overflow in address generation by the C1\n       compiler\n     - CVE-2024-21085: excessive memory allocation in Pack200\n     - CVE-2024-21094: \"exceeded _node_regs array\" C2 compilation error\n     - CVE-2024-21131: UTF8 size overflow\n     - CVE-2024-21138: infinite loop vunlerability in SymbolTable\n     - CVE-2024-21140: int overflow/underflow in Range Check Elimination\n     - CVE-2024-21144: invalid header validation leads to Pack200 excessive\n       loading time\n     - CVE-2024-21145: out-of-bounds access in MaskFill\n     - CVE-2024-21147: out-of-bounds array index in Range Check Elimination\n     - CVE-2024-21208: improper handling of maxHeaderSize in HTTP client\n     - CVE-2024-21210: integer overflow in array indexing in SuperWord\n     - CVE-2024-21217: out-of-memory because of unbounded allocation in\n       MessageFormat\n     - CVE-2024-21235: incorrect range check because of integer conversion\n       error in LoopNode\n   * Update patches\n     - debian/patches/zero-sh.diff","modified":"2026-06-04T09:46:46.972356516Z","published":"2024-11-21T13:52:39Z","upstream":["CVE-2024-20918","CVE-2024-20919","CVE-2024-20921","CVE-2024-20926","CVE-2024-20945","CVE-2024-20952","CVE-2024-21011","CVE-2024-21068","CVE-2024-21085","CVE-2024-21094","CVE-2024-21131","CVE-2024-21138","CVE-2024-21140","CVE-2024-21144","CVE-2024-21145","CVE-2024-21147","CVE-2024-21208","CVE-2024-21210","CVE-2024-21217","CVE-2024-21235"],"references":[{"type":"ADVISORY","url":"https://errata.cloudlinux.com/ubuntu16-els/CLSA-2024-1732197150.html"}],"affected":[{"package":{"name":"openjdk-8-demo","ecosystem":"TuxCare:Ubuntu:16.04","purl":"pkg:deb/tuxcare/openjdk-8-demo?distro=ubuntu-16.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"8u432-ga-0ubuntu1~16.04+tuxcare.els1"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu16.04els/CLSA-2024-1732197150.json"}},{"package":{"name":"openjdk-8-doc","ecosystem":"TuxCare:Ubuntu:16.04","purl":"pkg:deb/tuxcare/openjdk-8-doc?distro=ubuntu-16.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"8u432-ga-0ubuntu1~16.04+tuxcare.els1"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu16.04els/CLSA-2024-1732197150.json"}},{"package":{"name":"openjdk-8-jdk","ecosystem":"TuxCare:Ubuntu:16.04","purl":"pkg:deb/tuxcare/openjdk-8-jdk?distro=ubuntu-16.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"8u432-ga-0ubuntu1~16.04+tuxcare.els1"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu16.04els/CLSA-2024-1732197150.json"}},{"package":{"name":"openjdk-8-jdk-headless","ecosystem":"TuxCare:Ubuntu:16.04","purl":"pkg:deb/tuxcare/openjdk-8-jdk-headless?distro=ubuntu-16.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"8u432-ga-0ubuntu1~16.04+tuxcare.els1"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu16.04els/CLSA-2024-1732197150.json"}},{"package":{"name":"openjdk-8-jre","ecosystem":"TuxCare:Ubuntu:16.04","purl":"pkg:deb/tuxcare/openjdk-8-jre?distro=ubuntu-16.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"8u432-ga-0ubuntu1~16.04+tuxcare.els1"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu16.04els/CLSA-2024-1732197150.json"}},{"package":{"name":"openjdk-8-jre-headless","ecosystem":"TuxCare:Ubuntu:16.04","purl":"pkg:deb/tuxcare/openjdk-8-jre-headless?distro=ubuntu-16.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"8u432-ga-0ubuntu1~16.04+tuxcare.els1"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu16.04els/CLSA-2024-1732197150.json"}},{"package":{"name":"openjdk-8-jre-jamvm","ecosystem":"TuxCare:Ubuntu:16.04","purl":"pkg:deb/tuxcare/openjdk-8-jre-jamvm?distro=ubuntu-16.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"8u432-ga-0ubuntu1~16.04+tuxcare.els1"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu16.04els/CLSA-2024-1732197150.json"}},{"package":{"name":"openjdk-8-jre-zero","ecosystem":"TuxCare:Ubuntu:16.04","purl":"pkg:deb/tuxcare/openjdk-8-jre-zero?distro=ubuntu-16.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"8u432-ga-0ubuntu1~16.04+tuxcare.els1"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu16.04els/CLSA-2024-1732197150.json"}},{"package":{"name":"openjdk-8-source","ecosystem":"TuxCare:Ubuntu:16.04","purl":"pkg:deb/tuxcare/openjdk-8-source?distro=ubuntu-16.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"8u432-ga-0ubuntu1~16.04+tuxcare.els1"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu16.04els/CLSA-2024-1732197150.json"}}],"schema_version":"1.7.5"}