A flaw was found in the Serialization component of OpenJDK. A reference to an uninitialized class descriptor encountered during object stream deserialization could cause an unexpected exception to be raised when processing an untrusted serialized input.
Public now via Oracle CPU April 2020: https://www.oracle.com/security-alerts/cpuapr2020.html#AppendixJAVA Fixed in Oracle Java SE 14.0.1, 11.0.7, 8u251, and 7u261.
This issue has been addressed in the following products: Red Hat Enterprise Linux 6 Via RHSA-2020:1508 https://access.redhat.com/errata/RHSA-2020:1508
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2020:1507 https://access.redhat.com/errata/RHSA-2020:1507
This issue has been addressed in the following products: Red Hat Enterprise Linux 6 Via RHSA-2020:1506 https://access.redhat.com/errata/RHSA-2020:1506
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2020:1509 https://access.redhat.com/errata/RHSA-2020:1509
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2020:1512 https://access.redhat.com/errata/RHSA-2020:1512
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2020:1514 https://access.redhat.com/errata/RHSA-2020:1514
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2020-2756
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions Via RHSA-2020:1517 https://access.redhat.com/errata/RHSA-2020:1517
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions Via RHSA-2020:1516 https://access.redhat.com/errata/RHSA-2020:1516
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2020:1515 https://access.redhat.com/errata/RHSA-2020:1515
OpenJDK-11 upstream commit: http://hg.openjdk.java.net/jdk-updates/jdk11u/rev/1cec4823607e OpenJDK-8 upstream commit: http://hg.openjdk.java.net/jdk8u/jdk8u/jdk/rev/db82be4e049c OpenJDK-7 upstream commit: http://hg.openjdk.java.net/jdk7u/jdk7u/jdk/rev/c39602abdf2f
This issue has been addressed in the following products: Red Hat Enterprise Linux 6 Supplementary Via RHSA-2020:2236 https://access.redhat.com/errata/RHSA-2020:2236
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Supplementary Via RHSA-2020:2237 https://access.redhat.com/errata/RHSA-2020:2237
This issue has been addressed in the following products: Red Hat Enterprise Linux 6 Supplementary Via RHSA-2020:2239 https://access.redhat.com/errata/RHSA-2020:2239
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Supplementary Via RHSA-2020:2238 https://access.redhat.com/errata/RHSA-2020:2238
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2020:2241 https://access.redhat.com/errata/RHSA-2020:2241