RHSA-2022:1445HighCVSS 7.5

Red Hat Security Advisory: java-17-openjdk security and bug fix update

Published
April 20, 2022
Last Modified
June 25, 2026

🔗 CVE IDs covered (6)

📋 Description

CVE-2022-21426 — OpenJDK: Unbounded memory allocation when compiling crafted XPath expressions (JAXP, 8270504) CVE-2022-21434 — OpenJDK: Improper object-to-string conversion in AnnotationInvocationHandler (Libraries, 8277672) CVE-2022-21443 — OpenJDK: Missing check for negative ObjectIdentifier (Libraries, 8275151) CVE-2022-21449 — OpenJDK: Improper ECDSA signature verification (Libraries, 8277233) CVE-2022-21476 — OpenJDK: Defective secure validation in Apache Santuario (Libraries, 8278008) CVE-2022-21496 — OpenJDK: URI parsing inconsistencies (JNDI, 8278972)

🔗 References (11)