A flaw was found in the GCTR function implementation in the Security component in OpenJDK version 10. The function is used to implement Galois/Counter Mode (GCM) mode of operation for symmetric block ciphers. The implementation did not detect counter roll over, leading to an insufficient protection of encrypted data.
This only affected OpenJDK 10, which is not currently shipped in Red Hat products.
Public now via Oracle CPU July 2018: http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html#AppendixJAVA The issue was fixed in Oracle JDK 10.0.2.