Bugzilla will be upgraded to version 5.0. The upgrade date is tentatively scheduled for 2 December 2018, pending final testing and feedback.
Bug 1600925 - (CVE-2018-2952) CVE-2018-2952 OpenJDK: insufficient index validation in PatternSyntaxException getMessage() (Concurrency, 8199547)
CVE-2018-2952 OpenJDK: insufficient index validation in PatternSyntaxExceptio...
Status: CLOSED ERRATA
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
medium Severity medium
: ---
: ---
Assigned To: Red Hat Product Security
impact=moderate,public=20180717,repor...
: Security
Depends On: 1594253 1594254 1594255 1594256 1594257 1594258 1602113 1602114 1602115 1602116 1602117 1602118 1608811 1608812 1618719 1618720 1618721 1619180 1619181 1619182 1624844 1624845 1624868 1625243
Blocks: 1594250
  Show dependency treegraph
 
Reported: 2018-07-13 08:02 EDT by Tomas Hoger
Modified: 2018-10-24 17:39 EDT (History)
5 users (show)

See Also:
Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2018-09-17 11:14:41 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)


External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2018:2241 None None None 2018-07-23 10:37 EDT
Red Hat Product Errata RHSA-2018:2242 None None None 2018-07-23 11:04 EDT
Red Hat Product Errata RHSA-2018:2253 None None None 2018-07-24 17:13 EDT
Red Hat Product Errata RHSA-2018:2254 None None None 2018-07-24 17:09 EDT
Red Hat Product Errata RHSA-2018:2255 None None None 2018-07-24 17:13 EDT
Red Hat Product Errata RHSA-2018:2256 None None None 2018-07-24 17:09 EDT
Red Hat Product Errata RHSA-2018:2283 None None None 2018-07-30 10:53 EDT
Red Hat Product Errata RHSA-2018:2286 None None None 2018-07-30 11:19 EDT
Red Hat Product Errata RHSA-2018:2568 None None None 2018-08-27 10:20 EDT
Red Hat Product Errata RHSA-2018:2569 None None None 2018-08-27 10:21 EDT
Red Hat Product Errata RHSA-2018:2575 None None None 2018-08-28 15:19 EDT
Red Hat Product Errata RHSA-2018:2576 None None None 2018-08-28 15:20 EDT
Red Hat Product Errata RHSA-2018:2712 None None None 2018-09-17 10:50 EDT
Red Hat Product Errata RHSA-2018:2713 None None None 2018-09-17 10:54 EDT
Red Hat Product Errata RHSA-2018:3007 None None None 2018-10-24 17:38 EDT
Red Hat Product Errata RHSA-2018:3008 None None None 2018-10-24 17:39 EDT

  None (edit)
Description Tomas Hoger 2018-07-13 08:02:52 EDT
It was discovered that the implementation of the PatternSyntaxException class in the Concurrency component of OpenJDK failed to sufficiently validate the 'index' value (to ensure it's not greater than the regular expression length) in the getMessage() method.  An instance of the class with invalid index value, for example one created via deserialization on an untrusted input, could cause a Java application to use an excessive amount of memory.
Comment 1 Tomas Hoger 2018-07-17 17:22:00 EDT
Public now via Oracle CPU July 2018:

http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html#AppendixJAVA

The issue was fixed in Oracle JDK 10.0.2, 8u181, 7u191, and 6u201.
Comment 2 Tomas Hoger 2018-07-18 05:14:57 EDT
OpenJDK-8 upstream commit:

http://hg.openjdk.java.net/jdk8u/jdk8u/jdk/rev/baac18e216fb
Comment 3 errata-xmlrpc 2018-07-23 10:37:12 EDT
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 6

Via RHSA-2018:2241 https://access.redhat.com/errata/RHSA-2018:2241
Comment 4 errata-xmlrpc 2018-07-23 11:04:03 EDT
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7

Via RHSA-2018:2242 https://access.redhat.com/errata/RHSA-2018:2242
Comment 5 errata-xmlrpc 2018-07-24 17:09:10 EDT
This issue has been addressed in the following products:

  Oracle Java for Red Hat Enterprise Linux 7

Via RHSA-2018:2254 https://access.redhat.com/errata/RHSA-2018:2254
Comment 6 errata-xmlrpc 2018-07-24 17:09:27 EDT
This issue has been addressed in the following products:

  Oracle Java for Red Hat Enterprise Linux 6

Via RHSA-2018:2256 https://access.redhat.com/errata/RHSA-2018:2256
Comment 7 errata-xmlrpc 2018-07-24 17:13:03 EDT
This issue has been addressed in the following products:

  Oracle Java for Red Hat Enterprise Linux 7

Via RHSA-2018:2253 https://access.redhat.com/errata/RHSA-2018:2253
Comment 8 errata-xmlrpc 2018-07-24 17:13:26 EDT
This issue has been addressed in the following products:

  Oracle Java for Red Hat Enterprise Linux 6

Via RHSA-2018:2255 https://access.redhat.com/errata/RHSA-2018:2255
Comment 9 errata-xmlrpc 2018-07-30 10:53:00 EDT
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 6

Via RHSA-2018:2283 https://access.redhat.com/errata/RHSA-2018:2283
Comment 10 errata-xmlrpc 2018-07-30 11:19:27 EDT
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7

Via RHSA-2018:2286 https://access.redhat.com/errata/RHSA-2018:2286
Comment 11 errata-xmlrpc 2018-08-27 10:20:43 EDT
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7 Supplementary

Via RHSA-2018:2568 https://access.redhat.com/errata/RHSA-2018:2568
Comment 12 errata-xmlrpc 2018-08-27 10:21:13 EDT
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7 Supplementary

Via RHSA-2018:2569 https://access.redhat.com/errata/RHSA-2018:2569
Comment 13 errata-xmlrpc 2018-08-28 15:19:07 EDT
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 6 Supplementary

Via RHSA-2018:2575 https://access.redhat.com/errata/RHSA-2018:2575
Comment 14 errata-xmlrpc 2018-08-28 15:20:50 EDT
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 6 Supplementary

Via RHSA-2018:2576 https://access.redhat.com/errata/RHSA-2018:2576
Comment 18 errata-xmlrpc 2018-09-17 10:50:42 EDT
This issue has been addressed in the following products:

  Red Hat Satellite 5.6
  Red Hat Satellite 5.7

Via RHSA-2018:2712 https://access.redhat.com/errata/RHSA-2018:2712
Comment 19 errata-xmlrpc 2018-09-17 10:53:57 EDT
This issue has been addressed in the following products:

  Red Hat Satellite 5.8

Via RHSA-2018:2713 https://access.redhat.com/errata/RHSA-2018:2713
Comment 20 errata-xmlrpc 2018-10-24 17:38:44 EDT
This issue has been addressed in the following products:

  Oracle Java for Red Hat Enterprise Linux 7

Via RHSA-2018:3007 https://access.redhat.com/errata/RHSA-2018:3007
Comment 21 errata-xmlrpc 2018-10-24 17:39:19 EDT
This issue has been addressed in the following products:

  Oracle Java for Red Hat Enterprise Linux 6

Via RHSA-2018:3008 https://access.redhat.com/errata/RHSA-2018:3008

Note You need to log in before you can comment on or make changes to this bug.