A flaw was found in the Nashorn JavaScript engine in the Scripting component of OpenJDK. The state machine of the regular expression Parser did not correctly handle empty string nodes in certain cases, which could cause an unexpected exception to be raised when processing a specially crafted regular expression.
Public now via Oracle CPU April 2020: https://www.oracle.com/security-alerts/cpuapr2020.html#AppendixJAVA Fixed in Oracle Java SE 14.0.1, 11.0.7, and 8u251.
This issue has been addressed in the following products: Red Hat Enterprise Linux 6 Via RHSA-2020:1506 https://access.redhat.com/errata/RHSA-2020:1506
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2020:1509 https://access.redhat.com/errata/RHSA-2020:1509
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2020:1512 https://access.redhat.com/errata/RHSA-2020:1512
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2020:1514 https://access.redhat.com/errata/RHSA-2020:1514
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2020-2755
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions Via RHSA-2020:1517 https://access.redhat.com/errata/RHSA-2020:1517
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions Via RHSA-2020:1516 https://access.redhat.com/errata/RHSA-2020:1516
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2020:1515 https://access.redhat.com/errata/RHSA-2020:1515
OpenJDK-11 upstream commit: http://hg.openjdk.java.net/jdk-updates/jdk11u/rev/ebd67451925e OpenJDK-8 upstream commit: http://hg.openjdk.java.net/jdk8u/jdk8u/nashorn/rev/2f5ad880fd33
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Supplementary Via RHSA-2020:2237 https://access.redhat.com/errata/RHSA-2020:2237
This issue has been addressed in the following products: Red Hat Enterprise Linux 6 Supplementary Via RHSA-2020:2239 https://access.redhat.com/errata/RHSA-2020:2239
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2020:2241 https://access.redhat.com/errata/RHSA-2020:2241