CVE-2023-5676
published 2023-11-15CVE-2023-5676: In Eclipse OpenJ9 before version 0.41.0, the JVM can be forced into an infinite busy hang on a spinlock or a segmentation fault if a shutdown signal (SIGTERM…
PriorityP425medium5.9CVSS 3.1
AVNACHPRNUINSUCNINAH
EPSS
0.41%
32.9th percentile
In Eclipse OpenJ9 before version 0.41.0, the JVM can be forced into an infinite busy hang on a spinlock or a segmentation fault if a shutdown signal (SIGTERM, SIGINT or SIGHUP) is received before the JVM has finished initializing.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| eclipse | openj9 | < 0.41.0 | 0.41.0 |
| eclipse_foundation | openj9 | < 0.41.0 | 0.41.0 |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
vendor_redhat4.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5ch2-qvr7-76ch: In Eclipse OpenJ9 before version 0
ghsa_unreviewed·2023-11-15
CVE-2023-5676 [MEDIUM] CWE-362 GHSA-5ch2-qvr7-76ch: In Eclipse OpenJ9 before version 0
In Eclipse OpenJ9 before version 0.41.0, the JVM can be forced into an infinite busy hang on a spinlock or a segmentation fault if a shutdown signal (SIGTERM, SIGINT or SIGHUP) is received before the JVM has finished initializing.
Red Hat
JDK: Eclipse OpenJ9 JVM denial of service
vendor_redhat·2023-11-15·CVSS 4.1
CVE-2023-5676 [MEDIUM] CWE-364 JDK: Eclipse OpenJ9 JVM denial of service
JDK: Eclipse OpenJ9 JVM denial of service
In Eclipse OpenJ9 before version 0.41.0, the JVM can be forced into an infinite busy hang on a spinlock or a segmentation fault if a shutdown signal (SIGTERM, SIGINT or SIGHUP) is received before the JVM has finished initializing.
Eclipse OpenJ9 is vulnerable to a denial of service, caused by a flaw when a shutdown signal (SIGTERM, SIGINT or SIGHUP) is received before the JVM has finished initializing. By sending a specially crafted request, a local authenticated attacker could exploit this vulnerability to cause an infinite busy hang on a spinlock or a segmentation fault.
Package: java-1.7.1-ibm (Red Hat Enterprise Linux 7) - Out of support scope
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-11-15
Published