{"id":"CLSA-2025-1742319123","summary":"java-11-openjdk: Fix of 11 CVEs","details":"- Upgrade to openjdk-11.0.26+4. The following CVEs were fixed:\n- CVE-2024-21131: potential UTF8 size overflow\n- CVE-2024-21138: excessive symbol length can lead to infinite loop\n- CVE-2024-21140: range Check Elimination (RCE) pre-loop limit overflow\n- CVE-2024-21144: Pack200 increase loading time due to improper header\n  validation\n- CVE-2024-21145: out-of-bounds access in 2D image handling\n- CVE-2024-21147: RangeCheckElimination array index overflow\n- CVE-2024-21208: HTTP client improper handling of maxHeaderSize\n- CVE-2024-21210: array indexing integer overflow\n- CVE-2024-21217: unbounded allocation leads to out-of-memory error\n- CVE-2024-21235: integer conversion error leads to incorrect range check\n- CVE-2025-21502: enhance array handling","modified":"2026-05-27T11:18:23.588148570Z","published":"2025-03-18T17:32:09Z","upstream":["CVE-2024-21131","CVE-2024-21138","CVE-2024-21140","CVE-2024-21144","CVE-2024-21145","CVE-2024-21147","CVE-2024-21208","CVE-2024-21210","CVE-2024-21217","CVE-2024-21235","CVE-2025-21502"],"references":[{"type":"ADVISORY","url":"https://errata.tuxcare.com/centos7-els/CLSA-2025-1742319123.html"}],"affected":[{"package":{"name":"java-11-openjdk","ecosystem":"TuxCare:CentOS:7","purl":"pkg:rpm/tuxcare/java-11-openjdk?distro=centos-7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:11.0.26.0.4-1.el7_9.tuxcare.els1"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos7els/CLSA-2025-1742319123.json"}},{"package":{"name":"java-11-openjdk-debug","ecosystem":"TuxCare:CentOS:7","purl":"pkg:rpm/tuxcare/java-11-openjdk-debug?distro=centos-7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:11.0.26.0.4-1.el7_9.tuxcare.els1"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos7els/CLSA-2025-1742319123.json"}},{"package":{"name":"java-11-openjdk-demo","ecosystem":"TuxCare:CentOS:7","purl":"pkg:rpm/tuxcare/java-11-openjdk-demo?distro=centos-7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:11.0.26.0.4-1.el7_9.tuxcare.els1"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos7els/CLSA-2025-1742319123.json"}},{"package":{"name":"java-11-openjdk-demo-debug","ecosystem":"TuxCare:CentOS:7","purl":"pkg:rpm/tuxcare/java-11-openjdk-demo-debug?distro=centos-7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:11.0.26.0.4-1.el7_9.tuxcare.els1"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos7els/CLSA-2025-1742319123.json"}},{"package":{"name":"java-11-openjdk-devel","ecosystem":"TuxCare:CentOS:7","purl":"pkg:rpm/tuxcare/java-11-openjdk-devel?distro=centos-7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:11.0.26.0.4-1.el7_9.tuxcare.els1"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos7els/CLSA-2025-1742319123.json"}},{"package":{"name":"java-11-openjdk-devel-debug","ecosystem":"TuxCare:CentOS:7","purl":"pkg:rpm/tuxcare/java-11-openjdk-devel-debug?distro=centos-7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:11.0.26.0.4-1.el7_9.tuxcare.els1"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos7els/CLSA-2025-1742319123.json"}},{"package":{"name":"java-11-openjdk-headless","ecosystem":"TuxCare:CentOS:7","purl":"pkg:rpm/tuxcare/java-11-openjdk-headless?distro=centos-7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:11.0.26.0.4-1.el7_9.tuxcare.els1"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos7els/CLSA-2025-1742319123.json"}},{"package":{"name":"java-11-openjdk-headless-debug","ecosystem":"TuxCare:CentOS:7","purl":"pkg:rpm/tuxcare/java-11-openjdk-headless-debug?distro=centos-7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:11.0.26.0.4-1.el7_9.tuxcare.els1"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos7els/CLSA-2025-1742319123.json"}},{"package":{"name":"java-11-openjdk-javadoc","ecosystem":"TuxCare:CentOS:7","purl":"pkg:rpm/tuxcare/java-11-openjdk-javadoc?distro=centos-7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:11.0.26.0.4-1.el7_9.tuxcare.els1"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos7els/CLSA-2025-1742319123.json"}},{"package":{"name":"java-11-openjdk-javadoc-debug","ecosystem":"TuxCare:CentOS:7","purl":"pkg:rpm/tuxcare/java-11-openjdk-javadoc-debug?distro=centos-7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:11.0.26.0.4-1.el7_9.tuxcare.els1"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos7els/CLSA-2025-1742319123.json"}},{"package":{"name":"java-11-openjdk-javadoc-zip","ecosystem":"TuxCare:CentOS:7","purl":"pkg:rpm/tuxcare/java-11-openjdk-javadoc-zip?distro=centos-7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:11.0.26.0.4-1.el7_9.tuxcare.els1"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos7els/CLSA-2025-1742319123.json"}},{"package":{"name":"java-11-openjdk-javadoc-zip-debug","ecosystem":"TuxCare:CentOS:7","purl":"pkg:rpm/tuxcare/java-11-openjdk-javadoc-zip-debug?distro=centos-7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:11.0.26.0.4-1.el7_9.tuxcare.els1"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos7els/CLSA-2025-1742319123.json"}},{"package":{"name":"java-11-openjdk-jmods","ecosystem":"TuxCare:CentOS:7","purl":"pkg:rpm/tuxcare/java-11-openjdk-jmods?distro=centos-7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:11.0.26.0.4-1.el7_9.tuxcare.els1"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos7els/CLSA-2025-1742319123.json"}},{"package":{"name":"java-11-openjdk-jmods-debug","ecosystem":"TuxCare:CentOS:7","purl":"pkg:rpm/tuxcare/java-11-openjdk-jmods-debug?distro=centos-7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:11.0.26.0.4-1.el7_9.tuxcare.els1"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos7els/CLSA-2025-1742319123.json"}},{"package":{"name":"java-11-openjdk-src","ecosystem":"TuxCare:CentOS:7","purl":"pkg:rpm/tuxcare/java-11-openjdk-src?distro=centos-7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:11.0.26.0.4-1.el7_9.tuxcare.els1"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos7els/CLSA-2025-1742319123.json"}},{"package":{"name":"java-11-openjdk-src-debug","ecosystem":"TuxCare:CentOS:7","purl":"pkg:rpm/tuxcare/java-11-openjdk-src-debug?distro=centos-7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:11.0.26.0.4-1.el7_9.tuxcare.els1"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos7els/CLSA-2025-1742319123.json"}},{"package":{"name":"java-11-openjdk-static-libs","ecosystem":"TuxCare:CentOS:7","purl":"pkg:rpm/tuxcare/java-11-openjdk-static-libs?distro=centos-7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:11.0.26.0.4-1.el7_9.tuxcare.els1"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos7els/CLSA-2025-1742319123.json"}},{"package":{"name":"java-11-openjdk-static-libs-debug","ecosystem":"TuxCare:CentOS:7","purl":"pkg:rpm/tuxcare/java-11-openjdk-static-libs-debug?distro=centos-7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:11.0.26.0.4-1.el7_9.tuxcare.els1"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos7els/CLSA-2025-1742319123.json"}}],"schema_version":"1.7.5"}