It was found that the ConnectionPool class implementation in the Networking/HTTP client component of OpenJDK improperly performs a reverse DNS query if the passed argument is an IP address, potentially sending a request over the wrong connection under certain conditions.
This issue has been addressed in the following products: Red Hat Build of OpenJDK 11.0.23 Via RHSA-2024:1820 https://access.redhat.com/errata/RHSA-2024:1820
This issue has been addressed in the following products: Red Hat Build of OpenJDK 17.0.11 Via RHSA-2024:1824 https://access.redhat.com/errata/RHSA-2024:1824
This issue has been addressed in the following products: Red Hat Build of OpenJDK 17.0.11 Via RHSA-2024:1823 https://access.redhat.com/errata/RHSA-2024:1823
This issue has been addressed in the following products: Red Hat Build of OpenJDK 21.0.3 Via RHSA-2024:1827 https://access.redhat.com/errata/RHSA-2024:1827
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions Red Hat Enterprise Linux 8.4 Telecommunications Update Service Red Hat Enterprise Linux 8.6 Extended Update Support Red Hat Enterprise Linux 8.8 Extended Update Support Red Hat Enterprise Linux 8 Red Hat Enterprise Linux 9.0 Extended Update Support Red Hat Enterprise Linux 9.2 Extended Update Support Red Hat Enterprise Linux 9 Via RHSA-2024:1825 https://access.redhat.com/errata/RHSA-2024:1825
This issue has been addressed in the following products: Red Hat Build of OpenJDK 21.0.3 Via RHSA-2024:1826 https://access.redhat.com/errata/RHSA-2024:1826
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Red Hat Enterprise Linux 9 Via RHSA-2024:1828 https://access.redhat.com/errata/RHSA-2024:1828
This issue has been addressed in the following products: Red Hat Build of OpenJDK 11.0.23 Via RHSA-2024:1819 https://access.redhat.com/errata/RHSA-2024:1819
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2024:1821 https://access.redhat.com/errata/RHSA-2024:1821
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions Red Hat Enterprise Linux 8.4 Telecommunications Update Service Red Hat Enterprise Linux 8.8 Extended Update Support Red Hat Enterprise Linux 8 Red Hat Enterprise Linux 9.2 Extended Update Support Red Hat Enterprise Linux 9 Red Hat Enterprise Linux 8.2 Advanced Update Support Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions Red Hat Enterprise Linux 8.2 Telecommunications Update Service Red Hat Enterprise Linux 8.6 Extended Update Support Red Hat Enterprise Linux 9.0 Extended Update Support Via RHSA-2024:1822 https://access.redhat.com/errata/RHSA-2024:1822
OpenJDK-21 upstream commit: https://github.com/openjdk/jdk21u/commit/8eba98ad61905be909b673144b68c6259346665f OpenJDK-17 upstream commit: https://github.com/openjdk/jdk17u/commit/692600074d5262d518e8f8d592de9e9c889b7106 OpenJDK-11 upstream commit: https://github.com/openjdk/jdk11u/commit/4d72038fbca04c71a063810fb1034b1bbcc0268e
Oracle CPU April 2024: https://www.oracle.com/security-alerts/cpuapr2024.html#AppendixJAVA Fixed in Oracle Java SE 11.0.23, 17.0.11, 21.0.3. Release notes: https://www.oracle.com/java/technologies/javase/11-0-23-relnotes.html https://www.oracle.com/java/technologies/javase/17-0-11-relnotes.html https://www.oracle.com/java/technologies/javase/21-0-3-relnotes.html