Unrated severityNVD Advisory· Published Apr 27, 2022· Updated Aug 4, 2024
CVE-2021-41041
CVE-2021-41041
Description
In Eclipse Openj9 before version 0.32.0, Java 8 & 11 fail to throw the exception captured during bytecode verification when verification is triggered by a MethodHandle invocation, allowing unverified methods to be invoked using MethodHandles.
Affected products
7- osv-coords6 versionspkg:rpm/opensuse/java-11-openj9&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/java-11-openj9&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/java-1_8_0-openj9&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/java-1_8_0-openj9&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/java-1_8_0-openj9&distro=openSUSE%20Tumbleweedpkg:rpm/suse/java-11-openj9&distro=SUSE%20Package%20Hub%2015%20SP6
< 11.0.26.0-bp156.4.3.1+ 5 more
- (no CPE)range: < 11.0.26.0-bp156.4.3.1
- (no CPE)range: < 11.0.15.0-1.1
- (no CPE)range: < 1.8.0.345-150200.3.24.1
- (no CPE)range: < 1.8.0.345-150200.3.24.1
- (no CPE)range: < 1.8.0.332-1.1
- (no CPE)range: < 11.0.26.0-bp156.4.3.1
- The Eclipse Foundation/Eclipse OpenJ9v5Range: unspecified
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- bugs.eclipse.org/bugs/show_bug.cgimitrex_refsource_CONFIRM
- github.com/eclipse-openj9/openj9/pull/14935mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.