🛡️ USN-7338-1 — openjdk-17-crac

⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

openjdk-17-crac vulnerabilities

Andy Boothe discovered that the Networking component of CRaC JDK 17 did not

properly handle access under certain circumstances. An unauthenticated

attacker could possibly use this issue to cause a denial of service.

(CVE-2024-21208)

It was discovered that the Hotspot component of CRaC JDK 17 did not

properly handle vectorization under certain circumstances. An

unauthenticated attacker could possibly use this issue to access

unauthorized resources and expose sensitive information.

(CVE-2024-21210, CVE-2024-21235)

It was discovered that the Serialization component of CRaC JDK 17 did not

properly handle deserialization under certain circumstances. An

unauthenticated attacker could possibly use this issue to cause a denial

of service. (CVE-2024-21217)

It was discovered that the Hotspot component of CRaC JDK 17 did not

properly handle API access under certain circumstances. An unauthenticated

attacker could possibly use this issue to access unauthorized resources

and expose sensitive information. (CVE-2025-21502)

In addition to security fixes, the updated packages contain bug fixes, new

features, and possibly incompatible changes.

Please see the following for more information:

https://openjdk.org/groups/vulnerability/advisories/2024-10-15

https://openjdk.org/groups/vulnerability/advisories/2025-01-21

Affected software

USN-7338-1 is recorded against 1 package.

  • openjdk-17-crac (fixed in 17.0.14+7-0ubuntu1~24.10)

Timeline and source

Published on 11 March 2025 and last revised on 4 February 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

ubuntu.com (Advisory)
ubuntu.com (Report)
ubuntu.com (Report)
ubuntu.com (Report)
ubuntu.com (Report)
ubuntu.com (Report)

Details

Severity Unknown
CVSS Score N/A
CVSS Vector N/A
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2025-03-11
Updated 2026-08-12
Modified 2026-02-04
Fix URL N/A

Affected Packages

Software From version Fixed in
openjdk-17-crac 17.0.14+7-0ubuntu1~24.10

Free Vulnerability Check

Is your site affected by USN-7338-1?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against USN-7338-1 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.