RHSA-2022:1438HighCVSS 7.5

Red Hat Security Advisory: OpenJDK 8u332 security update for Portable Linux Builds

Published
April 28, 2022
Last Modified
September 7, 2026

🔗 CVE IDs covered (5)

📋 Description

CVE-2022-21426 — OpenJDK: Unbounded memory allocation when compiling crafted XPath expressions (JAXP, 8270504) CVE-2022-21434 — OpenJDK: Improper object-to-string conversion in AnnotationInvocationHandler (Libraries, 8277672) CVE-2022-21443 — OpenJDK: Missing check for negative ObjectIdentifier (Libraries, 8275151) CVE-2022-21476 — OpenJDK: Defective secure validation in Apache Santuario (Libraries, 8278008) CVE-2022-21496 — OpenJDK: URI parsing inconsistencies (JNDI, 8278972)

🎯 Affected products1

  • Red Hat Build of OpenJDK 8u332

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/documentation/en-us/openjdk/8/html/installing_and_using_openjdk_8_for_rhel/assembly_installing-openjdk-8-on-red-hat-enterprise-linux_openjdk#installing-jdk11-on-rhel-using-archive_openjdk

🔗 References (8)