A flaw was found in the Serialization component of OpenJDK. The invokeWriteObject() method of the ObjectStreamClass method failed to catch InstantiationError exception during object stream deserialization, which could cause an unexpected exception to be raised when processing an untrusted serialized input.
Public now via Oracle CPU April 2020: https://www.oracle.com/security-alerts/cpuapr2020.html#AppendixJAVA Fixed in Oracle Java SE 14.0.1, 11.0.7, 8u251, and 7u261.
This issue has been addressed in the following products: Red Hat Enterprise Linux 6 Via RHSA-2020:1508 https://access.redhat.com/errata/RHSA-2020:1508
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2020:1507 https://access.redhat.com/errata/RHSA-2020:1507
This issue has been addressed in the following products: Red Hat Enterprise Linux 6 Via RHSA-2020:1506 https://access.redhat.com/errata/RHSA-2020:1506
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2020:1509 https://access.redhat.com/errata/RHSA-2020:1509
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2020:1512 https://access.redhat.com/errata/RHSA-2020:1512
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2020:1514 https://access.redhat.com/errata/RHSA-2020:1514
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2020-2757
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions Via RHSA-2020:1517 https://access.redhat.com/errata/RHSA-2020:1517
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions Via RHSA-2020:1516 https://access.redhat.com/errata/RHSA-2020:1516
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2020:1515 https://access.redhat.com/errata/RHSA-2020:1515
OpenJDK-11 upstream commit: http://hg.openjdk.java.net/jdk-updates/jdk11u/rev/19f4afec0d04 OpenJDK-8 upstream commit: http://hg.openjdk.java.net/jdk8u/jdk8u/jdk/rev/a75922cb4096 OpenJDK-7 upstream commit: http://hg.openjdk.java.net/jdk7u/jdk7u/jdk/rev/1a95d48e5ff1
This issue has been addressed in the following products: Red Hat Enterprise Linux 6 Supplementary Via RHSA-2020:2236 https://access.redhat.com/errata/RHSA-2020:2236
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Supplementary Via RHSA-2020:2237 https://access.redhat.com/errata/RHSA-2020:2237
This issue has been addressed in the following products: Red Hat Enterprise Linux 6 Supplementary Via RHSA-2020:2239 https://access.redhat.com/errata/RHSA-2020:2239
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Supplementary Via RHSA-2020:2238 https://access.redhat.com/errata/RHSA-2020:2238
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2020:2241 https://access.redhat.com/errata/RHSA-2020:2241