---
title: "CVE-2017-10102\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2017-10102?format=md
keywords: index, follow
---

# CVE-2017-10102

Publication date 20 July 2017

Last updated 25 August 2025

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**9.0 · Critical**

[Score breakdown](https://ubuntu.com/security/CVE-2017-10102?format=md#impact-score)

Toggle side navigation

## Description

Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE
(subcomponent: RMI). Supported versions that are affected are Java SE:
6u151, 7u141 and 8u131; Java SE Embedded: 8u131. Difficult to exploit
vulnerability allows unauthenticated attacker with network access via
multiple protocols to compromise Java SE, Java SE Embedded. While the
vulnerability is in Java SE, Java SE Embedded, attacks may significantly
impact additional products. Successful attacks of this vulnerability can
result in takeover of Java SE, Java SE Embedded. Note: This vulnerability
can only be exploited by supplying data to APIs in the specified Component
without using Untrusted Java Web Start applications or Untrusted Java
applets, such as through a web service. CVSS 3.0 Base Score 9.0
(Confidentiality, Integrity and Availability impacts). CVSS Vector:
(CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H).

### From the Ubuntu Security Team

It was discovered that the Distributed Garbage Collector (DGC)
in OpenJDK did not properly track references in some situations. A
remote attacker could possibly use this to execute arbitrary code.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| openjdk-6 | 22.04 LTS jammy | Not in release |
| 21.10 impish | Not in release |
| 21.04 hirsute | Not in release |
| 20.10 groovy | Not in release |
| 20.04 LTS focal | Not in release |
| 19.10 eoan | Not in release |
| 19.04 disco | Not in release |
| 18.10 cosmic | Not in release |
| 18.04 LTS bionic | Not in release |
| 17.10 artful | Not in release |
| 17.04 zesty | Not in release |
| 16.10 yakkety | Not in release |
| 16.04 LTS xenial | Not in release |
| 14.04 LTS trusty | Not in release |
| openjdk-7 | 22.04 LTS jammy | Not in release |
| 21.10 impish | Not in release |
| 21.04 hirsute | Not in release |
| 20.10 groovy | Not in release |
| 20.04 LTS focal | Not in release |
| 19.10 eoan | Not in release |
| 19.04 disco | Not in release |
| 18.10 cosmic | Not in release |
| 18.04 LTS bionic | Not in release |
| 17.10 artful | Not in release |
| 17.04 zesty | Not in release |
| 16.10 yakkety | Not in release |
| 16.04 LTS xenial | Not in release |
| 14.04 LTS trusty | Fixed 7u151-2.6.11-0ubuntu1.14.04.1 |
| openjdk-8 | 22.04 LTS jammy | Not affected |
| 21.10 impish | Not affected |
| 21.04 hirsute | Not affected |
| 20.10 groovy | Not affected |
| 20.04 LTS focal | Not affected |
| 19.10 eoan | Not affected |
| 19.04 disco | Not affected |
| 18.10 cosmic | Not affected |
| 18.04 LTS bionic | Not affected |
| 17.10 artful | Not affected |
| 17.04 zesty | Fixed 8u131-b11-2ubuntu1.17.04.2 |
| 16.10 yakkety | Ignored end of life |
| 16.04 LTS xenial | Fixed 8u131-b11-2ubuntu1.16.04.2 |
| 14.04 LTS trusty | Not in release |
| openjdk-9 | 22.04 LTS jammy | Not in release |
| 21.10 impish | Not in release |
| 21.04 hirsute | Not in release |
| 20.10 groovy | Not in release |
| 20.04 LTS focal | Not in release |
| 19.10 eoan | Not in release |
| 19.04 disco | Not in release |
| 18.10 cosmic | Not in release |
| 18.04 LTS bionic | Not in release |
| 17.10 artful | Not affected |
| 17.04 zesty | Ignored end of life |
| 16.10 yakkety | Ignored end of life |
| 16.04 LTS xenial | Not affected |
| 14.04 LTS trusty | Not in release |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)
* [Patch details](https://ubuntu.com/security/CVE-2017-10102?format=md#patch-details)

### Patch details

For informational purposes only. We recommend not to cherry-pick updates. [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)

| Package | Patch details |
| --- | --- |
| openjdk-8 | * Upstream:   <http://hg.openjdk.java.net/jdk8u/jdk8u/jdk/rev/070e24b47ae0> |

## Severity score breakdown

CVSS version:
CVSS v3.0

**Base score**

9.0 · Critical

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Network |
  | Attack complexity | High |
  | Privileges required | None |
  | User interaction | None |
  | Scope | Changed |
  | Confidentiality impact | High |
  | Integrity impact | High |
  | Availability impact | High |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 9.0 · Critical |
  | Exploitability score | - |
  | Impact score | - |

**Vector:** CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-10102)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2017-10102)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2017-10102)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2017-10102)

### Related Ubuntu Security Notices (USN)

+ [USN-3396-1](https://usn.ubuntu.com/USN-3396-1)
+ OpenJDK 7 vulnerabilities
+ 18 August 2017

+ [USN-3366-1](https://usn.ubuntu.com/USN-3366-1)
+ OpenJDK 8 vulnerabilities
+ 26 July 2017

### Other references

* <http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html#AppendixJAVA>
* <https://www.cve.org/CVERecord?id=CVE-2017-10102>
