Bug 2250255 (CVE-2023-5676) - CVE-2023-5676 IBM JDK: Eclipse OpenJ9 JVM denial of service
Summary: CVE-2023-5676 IBM JDK: Eclipse OpenJ9 JVM denial of service
Keywords:
Status: NEW
Alias: CVE-2023-5676
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks: 2242826
TreeView+ depends on / blocked
 
Reported: 2023-11-17 10:41 UTC by Mauro Matteo Cascella
Modified: 2024-02-20 08:57 UTC (History)
0 users

Fixed In Version: java-1.8.0-ibm 8.0.8.15
Doc Type: If docs needed, set a value
Doc Text:
Eclipse OpenJ9 is vulnerable to a denial of service, caused by a flaw when a shutdown signal (SIGTERM, SIGINT or SIGHUP) is received before the JVM has finished initializing. By sending a specially crafted request, a local authenticated attacker could exploit this vulnerability to cause an infinite busy hang on a spinlock or a segmentation fault.
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2024:0866 0 None None None 2024-02-19 17:59:27 UTC
Red Hat Product Errata RHSA-2024:0879 0 None None None 2024-02-20 08:57:33 UTC

Description Mauro Matteo Cascella 2023-11-17 10:41:06 UTC
IBM JDK 7 R1 SR5 FP20 (7.1.5.20) and 8 SR8 FP15 (8.0.8.15) fix a flaw described by upstream as:

Eclipse OpenJ9 is vulnerable to a denial of service, caused by a flaw when a shutdown signal (SIGTERM, SIGINT or SIGHUP) is received before the JVM has finished initializing. By sending a specially crafted request, a local authenticated attacker could exploit this vulnerability to cause an infinite busy hang on a spinlock or a segmentation fault.

OpenJ9 upstream references:
https://github.com/eclipse-openj9/openj9/pull/18085
https://gitlab.eclipse.org/security/cve-assignement/-/issues/13

IBM JDK references:
https://www.ibm.com/support/pages/node/7078433
https://www.ibm.com/support/pages/apar/IJ49075
https://www.ibm.com/support/pages/java-sdk-security-vulnerabilities#IBM_Security_Update_November_2023

Comment 2 errata-xmlrpc 2024-02-19 17:59:26 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2024:0866 https://access.redhat.com/errata/RHSA-2024:0866

Comment 3 errata-xmlrpc 2024-02-20 08:57:31 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7 Supplementary

Via RHSA-2024:0879 https://access.redhat.com/errata/RHSA-2024:0879


Note You need to log in before you can comment on or make changes to this bug.