Red Hat Security Advisory: OpenJDK 17.0.3 security update for Portable Linux Builds
🔗 CVE IDs covered (6)
📋 Description
CVE-2022-21426 — OpenJDK: Unbounded memory allocation when compiling crafted XPath expressions (JAXP, 8270504) CVE-2022-21434 — OpenJDK: Improper object-to-string conversion in AnnotationInvocationHandler (Libraries, 8277672) CVE-2022-21443 — OpenJDK: Missing check for negative ObjectIdentifier (Libraries, 8275151) CVE-2022-21449 — OpenJDK: Improper ECDSA signature verification (Libraries, 8277233) CVE-2022-21476 — OpenJDK: Defective secure validation in Apache Santuario (Libraries, 8278008) CVE-2022-21496 — OpenJDK: URI parsing inconsistencies (JNDI, 8278972)
🎯 Affected products1
- Red Hat Build of OpenJDK 17.0.3
✅ Remediation
Before applying this update, make sure all previously-released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/documentation/en-us/openjdk/17/html/installing_and_using_openjdk_17_on_rhel/installing-openjdk11-on-rhel8_openjdk#installing-jdk11-on-rhel-using-archive_openjdk
🔗 References (9)
- selfhttps://access.redhat.com/errata/RHSA-2022:1436
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2075788
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2075793
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2075821
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2075836
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2075842
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2075849
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2022/rhsa-2022_1436.json