RHSA-2022:0229MediumCVSS 5.3

Red Hat Security Advisory: OpenJDK 11.0.14 security update for Windows Builds

Published
January 24, 2022
Last Modified
August 4, 2026

🔗 CVE IDs covered (15)

📋 Description

CVE-2022-21248 — OpenJDK: Incomplete deserialization class filtering in ObjectInputStream (Serialization, 8264934) CVE-2022-21277 — OpenJDK: Incorrect reading of TIFF files in TIFFNullDecompressor (ImageIO, 8270952) CVE-2022-21282 — OpenJDK: Insufficient URI checks in the XSLT TransformerImpl (JAXP, 8270492) CVE-2022-21283 — OpenJDK: Unexpected exception thrown in regex Pattern (Libraries, 8268813) CVE-2022-21291 — OpenJDK: Incorrect marking of writeable fields (Hotspot, 8270386) CVE-2022-21293 — OpenJDK: Incomplete checks of StringBuffer and StringBuilder during deserialization (Libraries, 8270392) CVE-2022-21294 — OpenJDK: Incorrect IdentityHashMap size checks during deserialization (Libraries, 8270416) CVE-2022-21296 — OpenJDK: Incorrect access checks in XMLEntityManager (JAXP, 8270498) CVE-2022-21299 — OpenJDK: Infinite loop related to incorrect handling of newlines in XMLEntityScanner (JAXP, 8270646) CVE-2022-21305 — OpenJDK: Array indexing issues in LIRGenerator (Hotspot, 8272014) CVE-2022-21340 — OpenJDK: Excessive resource use when reading JAR manifest attributes (Libraries, 8272026) CVE-2022-21341 — OpenJDK: Insufficient checks when deserializing exceptions in ObjectInputStream (Serialization, 8272236) CVE-2022-21360 — OpenJDK: Excessive memory allocation in BMPImageReader (ImageIO, 8273756) CVE-2022-21365 — OpenJDK: Integer overflow in BMPImageReader (ImageIO, 8273838) CVE-2022-21366 — OpenJDK: Excessive memory allocation in TIFF*Decompressor (ImageIO, 8274096)

🎯 Affected products1

  • Red Hat Build of OpenJDK 11.0.14

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/documentation/en-us/openjdk/11/html/installing_and_using_openjdk_11_for_windows/index

🔗 References (18)