Bug 2027791 (CVE-2021-41035) - CVE-2021-41035 IBM JDK: IllegalAccessError exception not thrown for MethodHandles that invoke inaccessible interface methods
Summary: CVE-2021-41035 IBM JDK: IllegalAccessError exception not thrown for MethodHan...
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2021-41035
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2026908 2026909 2026910 2026911 2061507 2070466
Blocks: 2011827
TreeView+ depends on / blocked
 
Reported: 2021-11-30 16:39 UTC by Tomas Hoger
Modified: 2022-04-06 11:58 UTC (History)
1 user (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2022-02-01 16:01:41 UTC
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2021:5030 0 None None None 2021-12-08 16:19:45 UTC
Red Hat Product Errata RHSA-2022:0310 0 None None None 2022-01-27 14:10:15 UTC
Red Hat Product Errata RHSA-2022:0345 0 None None None 2022-02-01 15:13:05 UTC

Description Tomas Hoger 2021-11-30 16:39:54 UTC
IBM JDK 7 SR11 (7.0.11.0), 7.1 SR5 (7.1.5.0), and 8 SR7 (8.0.7.0) fix a flaw in OpenJ9 VM described by upstream as:

In Eclipse Openj9 before version 0.29.0, the JVM does not throw IllegalAccessError for MethodHandles that invoke inaccessible interface methods.

References:

https://www.ibm.com/support/pages/java-sdk-security-vulnerabilities#IBM_Security_Update_November_2021
https://bugs.eclipse.org/bugs/show_bug.cgi?id=576395
https://github.com/eclipse-openj9/openj9/pull/13740
https://gitlab.eclipse.org/eclipsefdn/emo-team/emo/-/issues/104

Comment 1 Tomas Hoger 2021-11-30 16:42:46 UTC
IBM has not published their full CVSS vector yet, only the CVSS score of 5.3.

Eclipse Foundation's CVE request issue does include any CVSS score or impact rating form the OpenJ9 upstream:

https://gitlab.eclipse.org/eclipsefdn/emo-team/emo/-/issues/104

Comment 2 Tomas Hoger 2021-12-02 13:22:39 UTC
In reply to comment #1:
> IBM has not published their full CVSS vector yet, only the CVSS score of 5.3.

IBM CVSS score is now available via their security bulletin:

https://www.ibm.com/support/pages/node/6522860

which notes:

CVEID:   CVE-2021-41035
DESCRIPTION:   Eclipse Openj9 could provide weaker than expected security, caused by the failure to throw IllegalAccessError for MethodHandles that invoke inaccessible interface methods. An attacker could exploit this vulnerability to launch further attacks on the system.
CVSS Base score: 5.3
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)

Comment 3 errata-xmlrpc 2021-12-08 16:19:44 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7 Supplementary

Via RHSA-2021:5030 https://access.redhat.com/errata/RHSA-2021:5030

Comment 4 errata-xmlrpc 2022-01-27 14:10:13 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7 Supplementary

Via RHSA-2022:0310 https://access.redhat.com/errata/RHSA-2022:0310

Comment 5 errata-xmlrpc 2022-02-01 15:13:03 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2022:0345 https://access.redhat.com/errata/RHSA-2022:0345

Comment 6 Product Security DevOps Team 2022-02-01 16:01:40 UTC
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):

https://access.redhat.com/security/cve/cve-2021-41035


Note You need to log in before you can comment on or make changes to this bug.