RHSA-2022:0306MediumCVSS 5.3

Red Hat Security Advisory: java-1.8.0-openjdk security update

Published
January 27, 2022
Last Modified
August 4, 2026

🔗 CVE IDs covered (12)

📋 Description

CVE-2022-21248 — OpenJDK: Incomplete deserialization class filtering in ObjectInputStream (Serialization, 8264934) CVE-2022-21282 — OpenJDK: Insufficient URI checks in the XSLT TransformerImpl (JAXP, 8270492) CVE-2022-21283 — OpenJDK: Unexpected exception thrown in regex Pattern (Libraries, 8268813) CVE-2022-21293 — OpenJDK: Incomplete checks of StringBuffer and StringBuilder during deserialization (Libraries, 8270392) CVE-2022-21294 — OpenJDK: Incorrect IdentityHashMap size checks during deserialization (Libraries, 8270416) CVE-2022-21296 — OpenJDK: Incorrect access checks in XMLEntityManager (JAXP, 8270498) CVE-2022-21299 — OpenJDK: Infinite loop related to incorrect handling of newlines in XMLEntityScanner (JAXP, 8270646) CVE-2022-21305 — OpenJDK: Array indexing issues in LIRGenerator (Hotspot, 8272014) CVE-2022-21340 — OpenJDK: Excessive resource use when reading JAR manifest attributes (Libraries, 8272026) CVE-2022-21341 — OpenJDK: Insufficient checks when deserializing exceptions in ObjectInputStream (Serialization, 8272236) CVE-2022-21360 — OpenJDK: Excessive memory allocation in BMPImageReader (ImageIO, 8273756) CVE-2022-21365 — OpenJDK: Integer overflow in BMPImageReader (ImageIO, 8273838)

🎯 Affected products100

  • Red Hat Enterprise Linux Client (v. 7)
  • Red Hat Enterprise Linux Client Optional (v. 7)
  • Red Hat Enterprise Linux ComputeNode Optional (v. 7)
  • Red Hat Enterprise Linux Server (v. 7)
  • Red Hat Enterprise Linux Server Optional (v. 7)
  • Red Hat Enterprise Linux Workstation (v. 7)
  • Red Hat Enterprise Linux Workstation Optional (v. 7)
  • java-1.8.0-openjdk-1:1.8.0.322.b06-1.el7_9.i686 as a component of Red Hat Enterprise Linux Client (v. 7)
  • java-1.8.0-openjdk-1:1.8.0.322.b06-1.el7_9.i686 as a component of Red Hat Enterprise Linux Server (v. 7)
  • java-1.8.0-openjdk-1:1.8.0.322.b06-1.el7_9.i686 as a component of Red Hat Enterprise Linux Workstation (v. 7)
  • java-1.8.0-openjdk-1:1.8.0.322.b06-1.el7_9.ppc64 as a component of Red Hat Enterprise Linux Server (v. 7)
  • java-1.8.0-openjdk-1:1.8.0.322.b06-1.el7_9.ppc64le as a component of Red Hat Enterprise Linux Server (v. 7)
  • java-1.8.0-openjdk-1:1.8.0.322.b06-1.el7_9.s390x as a component of Red Hat Enterprise Linux Server (v. 7)
  • java-1.8.0-openjdk-1:1.8.0.322.b06-1.el7_9.src as a component of Red Hat Enterprise Linux Client (v. 7)
  • java-1.8.0-openjdk-1:1.8.0.322.b06-1.el7_9.src as a component of Red Hat Enterprise Linux Server (v. 7)
  • java-1.8.0-openjdk-1:1.8.0.322.b06-1.el7_9.src as a component of Red Hat Enterprise Linux Workstation (v. 7)
  • java-1.8.0-openjdk-1:1.8.0.322.b06-1.el7_9.x86_64 as a component of Red Hat Enterprise Linux Client (v. 7)
  • java-1.8.0-openjdk-1:1.8.0.322.b06-1.el7_9.x86_64 as a component of Red Hat Enterprise Linux Server (v. 7)
  • java-1.8.0-openjdk-1:1.8.0.322.b06-1.el7_9.x86_64 as a component of Red Hat Enterprise Linux Workstation (v. 7)
  • java-1.8.0-openjdk-accessibility-1:1.8.0.322.b06-1.el7_9.i686 as a component of Red Hat Enterprise Linux Client Optional (v. 7)
  • java-1.8.0-openjdk-accessibility-1:1.8.0.322.b06-1.el7_9.i686 as a component of Red Hat Enterprise Linux ComputeNode Optional (v. 7)
  • java-1.8.0-openjdk-accessibility-1:1.8.0.322.b06-1.el7_9.i686 as a component of Red Hat Enterprise Linux Server Optional (v. 7)
  • java-1.8.0-openjdk-accessibility-1:1.8.0.322.b06-1.el7_9.i686 as a component of Red Hat Enterprise Linux Workstation Optional (v. 7)
  • java-1.8.0-openjdk-accessibility-1:1.8.0.322.b06-1.el7_9.ppc64 as a component of Red Hat Enterprise Linux Server Optional (v. 7)
  • java-1.8.0-openjdk-accessibility-1:1.8.0.322.b06-1.el7_9.ppc64le as a component of Red Hat Enterprise Linux Server Optional (v. 7)
  • java-1.8.0-openjdk-accessibility-1:1.8.0.322.b06-1.el7_9.s390x as a component of Red Hat Enterprise Linux Server Optional (v. 7)
  • java-1.8.0-openjdk-accessibility-1:1.8.0.322.b06-1.el7_9.x86_64 as a component of Red Hat Enterprise Linux Client Optional (v. 7)
  • java-1.8.0-openjdk-accessibility-1:1.8.0.322.b06-1.el7_9.x86_64 as a component of Red Hat Enterprise Linux ComputeNode Optional (v. 7)
  • java-1.8.0-openjdk-accessibility-1:1.8.0.322.b06-1.el7_9.x86_64 as a component of Red Hat Enterprise Linux Server Optional (v. 7)
  • java-1.8.0-openjdk-accessibility-1:1.8.0.322.b06-1.el7_9.x86_64 as a component of Red Hat Enterprise Linux Workstation Optional (v. 7)
  • +70 more not shown

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 All running instances of OpenJDK Java must be restarted for this update to take effect.

🔗 References (16)