IBM JDK 8 SR5 FP40 (8.0.5.40) fixes a flaw described by upstream as: Eclipse OpenJ9 could allow a local attacker to gain elevated privileges on the system, caused by an out-of-bounds write in the String.getBytes method. An attacker could exploit this vulnerability to corrupt memory and write to any 32-bit address or beyond the end of a byte array within Java code run under a SecurityManager. OpenJ9 upstream bug: https://bugs.eclipse.org/bugs/show_bug.cgi?id=549075 OpenJ9 upstream merge request and commit: https://github.com/eclipse/openj9/pull/6501 https://github.com/eclipse/openj9/commit/426e321c22c76a157312d862acc6b14114b51f95 References: https://www-01.ibm.com/support/docview.wss?uid=ibm10960422 https://developer.ibm.com/javasdk/support/security-vulnerabilities/#IBM_Security_Update_July_2019
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Supplementary Via RHSA-2019:2585 https://access.redhat.com/errata/RHSA-2019:2585
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2019:2590 https://access.redhat.com/errata/RHSA-2019:2590
This issue has been addressed in the following products: Red Hat Enterprise Linux 6 Supplementary Via RHSA-2019:2592 https://access.redhat.com/errata/RHSA-2019:2592
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2019-11772
This issue has been addressed in the following products: Red Hat Satellite 5.8 Via RHSA-2019:2737 https://access.redhat.com/errata/RHSA-2019:2737