🛡️ SUSE-SU-2024:3954-1 — java-21-openjdk (CVE-2024-21208 +3 more)

⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

Security update for java-21-openjdk

This update for java-21-openjdk fixes the following issues:

  • Update to upstream tag jdk-21.0.5+13 (October 2024 CPU)
  • Security fixes

+ JDK-8307383: Enhance DTLS connections

+ JDK-8311208: Improve CDS Support

+ JDK-8328286, CVE-2024-21208, bsc#1231702: Enhance HTTP client

+ JDK-8328544, CVE-2024-21210, bsc#1231711: Improve handling of vectorization

+ JDK-8328726: Better Kerberos support

+ JDK-8331446, CVE-2024-21217, bsc#1231716: Improve deserialization support

+ JDK-8332644, CVE-2024-21235, bsc#1231719: Improve graph optimizations

+ JDK-8335713: Enhance vectorization analysis

  • Other changes

+ JDK-6355567: AdobeMarkerSegment causes failure to read valid JPEG

+ JDK-6967482: TAB-key does not work in JTables after selecting

details-view in JFileChooser

+ JDK-7022325: TEST_BUG: test/java/util/zip/ZipFile/

/ReadLongZipFileName.java leaks files if it fails

+ JDK-8051959: Add thread and timestamp options to

java.security.debug system property

+ JDK-8073061: (fs) Files.copy(foo, bar, REPLACE_EXISTING)

deletes bar even if foo is not readable

+ JDK-8166352: FilePane.createDetailsView() removes JTable TAB,

SHIFT-TAB functionality

+ JDK-8170817: G1: Returning MinTLABSize from

unsafe_max_tlab_alloc causes TLAB flapping

+ JDK-8211847: [aix] java/lang/ProcessHandle/InfoTest.java

fails: 'reported cputime less than expected'

+ JDK-8211854: [aix] java/net/ServerSocket/

/AcceptInheritHandle.java fails: read times out

+ JDK-8222884: ConcurrentClassDescLookup.java times out intermittently

+ JDK-8238169: BasicDirectoryModel getDirectories and

DoChangeContents.run can deadlock

+ JDK-8241550: [macOS] SSLSocketImpl/ReuseAddr.java failed due

to 'BindException: Address already in use'

+ JDK-8242564: javadoc crashes:: class cast exception

com.sun.tools.javac.code.Symtab$6

+ JDK-8260633: [macos] java/awt/dnd/MouseEventAfterStartDragTest/

/MouseEventAfterStartDragTest.html test failed

+ JDK-8261433: Better pkcs11 performance for

libpkcs11:C_EncryptInit/libpkcs11:C_DecryptInit

+ JDK-8269428: java/util/concurrent/ConcurrentHashMap/

/ToArray.java timed out

+ JDK-8269657: Test java/nio/channels/DatagramChannel/

/Loopback.java failed: Unexpected message

+ JDK-8280120: [IR Framework] Add attribute to @IR to

enable/disable IR matching based on the architecture

+ JDK-8280392: java/awt/Focus/NonFocusableWindowTest/

/NonfocusableOwnerTest.java failed with 'RuntimeException: Test failed.'

+ JDK-8280988: [XWayland] Click on title to request focus test failures

+ JDK-8280990: [XWayland] XTest emulated mouse click does not

bring window to front

+ JDK-8283223: gc/stringdedup/TestStringDeduplicationFullGC.java

#Parallel failed with 'RuntimeException: String verification failed'

+ JDK-8287325: AArch64: fix virtual threads with

-XX:UseBranchProtection=pac-ret

+ JDK-8291809: Convert compiler/c2/cr7200264/TestSSE2IntVect.java

to IR verification test

+ JDK-8294148: Support JSplitPane for instructions and test UI

+ JDK-8299058: AssertionError in sun.net.httpserver.ServerImpl

when connection is idle

+ JDK-8299487: Test java/net/httpclient/whitebox/

/SSLTubeTestDriver.java timed out

+ JDK-8299790: os::print_hex_dump is racy

+ JDK-8299813: java/nio/channels/DatagramChannel/Disconnect.java

fails with jtreg test timeout due to lost datagram

+ JDK-8301686: TLS 1.3 handshake fails if server_name doesn't

match resuming session

+ JDK-8303920: Avoid calling out to python in

DataDescriptorSignatureMissing test

+ JDK-8305072: Win32ShellFolder2.compareTo is inconsistent

+ JDK-8305825: getBounds API returns wrong value resulting in

multiple Regression Test Failures on Ubuntu 23.04

+ JDK-8307193: Several Swing jtreg tests use class.forName on L&F classes

+ JDK-8307352: AARCH64: Improve itable_stub

+ JDK-8307778: com/sun/jdi/cds tests fail with jtreg's Virtual

test thread factory

+ JDK-8307788: vmTestbase/gc/gctests/LargeObjects/large003/

/TestDescription.java timed out

+ JDK-8308286: Fix clang warnings in linux code

+ JDK-8308660: C2 compilation hits 'node must be dead' assert

+ JDK-8309067: gtest/AsyncLogGtest.java fails again in

stderrOutput_vm

+ JDK-8309621: [XWayland][Screencast] screen capture failure

with sun.java2d.uiScale other than 1

+ JDK-8309685: Fix -Wconversion warnings in assembler and

register code

+ JDK-8309894: compiler/vectorapi/

/VectorLogicalOpIdentityTest.java fails on SVE system with UseSVE=0

+ JDK-8310072: JComboBox/DisabledComboBoxFontTestAuto: Enabled

and disabled ComboBox does not match in these LAFs: GTK+

+ JDK-8310108: Skip ReplaceCriticalClassesForSubgraphs when

EnableJVMCI is specified

Affected software

SUSE-SU-2024:3954-1 is recorded against 1 package.

  • java-21-openjdk (fixed in 21.0.5.0-150600.3.6.3)

Timeline and source

Published on 8 November 2024 and last revised on 4 February 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

www.suse.com (Advisory)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
www.suse.com (Web)
www.suse.com (Web)
www.suse.com (Web)
www.suse.com (Web)

Details

Severity Unknown
CVSS Score N/A
CVSS Vector N/A
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2024-11-08
Updated 2026-08-20
Modified 2026-02-04
Fix URL N/A

Affected Packages

Software From version Fixed in
java-21-openjdk 21.0.5.0-150600.3.6.3

Similar Threats

Free Vulnerability Check

Is your site affected by SUSE-SU-2024:3954-1?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against SUSE-SU-2024:3954-1 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.

Browse related advisories

All advisoriesSUSESUSE 2024