Bug 2027791 (CVE-2021-41035)

Summary: CVE-2021-41035 IBM JDK: IllegalAccessError exception not thrown for MethodHandles that invoke inaccessible interface methods
Product: [Other] Security Response Reporter: Tomas Hoger <thoger>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: java-qa
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2022-02-01 16:01:41 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2026908, 2026909, 2026910, 2026911, 2061507, 2070466    
Bug Blocks: 2011827    

Description Tomas Hoger 2021-11-30 16:39:54 UTC
IBM JDK 7 SR11 (7.0.11.0), 7.1 SR5 (7.1.5.0), and 8 SR7 (8.0.7.0) fix a flaw in OpenJ9 VM described by upstream as:

In Eclipse Openj9 before version 0.29.0, the JVM does not throw IllegalAccessError for MethodHandles that invoke inaccessible interface methods.

References:

https://www.ibm.com/support/pages/java-sdk-security-vulnerabilities#IBM_Security_Update_November_2021
https://bugs.eclipse.org/bugs/show_bug.cgi?id=576395
https://github.com/eclipse-openj9/openj9/pull/13740
https://gitlab.eclipse.org/eclipsefdn/emo-team/emo/-/issues/104

Comment 1 Tomas Hoger 2021-11-30 16:42:46 UTC
IBM has not published their full CVSS vector yet, only the CVSS score of 5.3.

Eclipse Foundation's CVE request issue does include any CVSS score or impact rating form the OpenJ9 upstream:

https://gitlab.eclipse.org/eclipsefdn/emo-team/emo/-/issues/104

Comment 2 Tomas Hoger 2021-12-02 13:22:39 UTC
In reply to comment #1:
> IBM has not published their full CVSS vector yet, only the CVSS score of 5.3.

IBM CVSS score is now available via their security bulletin:

https://www.ibm.com/support/pages/node/6522860

which notes:

CVEID:   CVE-2021-41035
DESCRIPTION:   Eclipse Openj9 could provide weaker than expected security, caused by the failure to throw IllegalAccessError for MethodHandles that invoke inaccessible interface methods. An attacker could exploit this vulnerability to launch further attacks on the system.
CVSS Base score: 5.3
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)

Comment 3 errata-xmlrpc 2021-12-08 16:19:44 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7 Supplementary

Via RHSA-2021:5030 https://access.redhat.com/errata/RHSA-2021:5030

Comment 4 errata-xmlrpc 2022-01-27 14:10:13 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7 Supplementary

Via RHSA-2022:0310 https://access.redhat.com/errata/RHSA-2022:0310

Comment 5 errata-xmlrpc 2022-02-01 15:13:03 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2022:0345 https://access.redhat.com/errata/RHSA-2022:0345

Comment 6 Product Security DevOps Team 2022-02-01 16:01:40 UTC
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):

https://access.redhat.com/security/cve/cve-2021-41035