Bug#1093878: Q about 8u442 applicability of JDK-8330045 (Enhance array handling) / CVE-2025-21502

Thorsten Glaser tg at evolvis.org
Sun Feb 9 19:32:40 GMT 2025


Hi,

I’ve got this report against openjdk-8 in Debian about CVE-2025-21502
and I cannot find whether this even affects openjdk-8 at all, nor if
it’s fixed in 8u442.

There are links to commits in 21/17/11 and a page saying Oracle’s
8u431-perf is affected with the fix in 8u441-perf, but without a
link to a commit saying so ☹

I also cannot read JDK-8330045 (wants a login, in contrast to the
other JDK-####### bugs I peeked into).

So, what’s the state of this?

Thanks in advance,
//mirabilos
-- 
> Hi, does anyone sell openbsd stickers by themselves and not packaged
> with other products?
No, the only way I've seen them sold is for $40 with a free OpenBSD CD.
	-- Haroon Khalid and Steve Shockley in gmane.os.openbsd.misc



More information about the pkg-java-maintainers mailing list