MGASA-2020-0069
The updated packages fix security vulnerabilities: Improper checks of SASL message properties in GssKrb5Base (Security, 8226352) (CVE-2020-2590) Incorrect exception processing during deserialization in BeanContextSupport (Serialization, 8224909) (CVE-2020-2583) Incorrect isBuiltinStreamHandler causing URL normalization issues (Networking, 8228548) (CVE-2020-2593) Use of unsafe RSA-MD5 checkum in Kerberos TGS (Security, 8229951) (CVE-2020-2601) Serialization filter changes via jdk.serialFilter property modification (Serialization, 8231422) (CVE-2020-2604) Excessive memory usage in OID processing in X.509 certificate parsing (Libraries, 8234037) (CVE-2020-2654) Incomplete enforcement of maxDatagramSockets limit in DatagramChannelImpl (Networking, 8231795) (CVE-2020-2659)
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mageia:7 | java-1.8.0-openjdk | 0, 0 |
Timeline
- Jan 30, 2020 CVE Published
- Apr 16, 2026 CVE Updated
- May 1, 2026 Distribution Patch
- May 1, 2026 Security Advisory