RHSA-2022:5701HighCVSS 7.5
Red Hat Security Advisory: java-1.8.0-openjdk security update
🔗 CVE IDs covered (3)
📋 Description
CVE-2022-21540 — OpenJDK: class compilation issue (Hotspot, 8281859) CVE-2022-21541 — OpenJDK: improper restriction of MethodHandle.invokeBasic() (Hotspot, 8281866) CVE-2022-34169 — OpenJDK: integer truncation issue in Xalan-J (JAXP, 8285407)
🎯 Affected products34
- Red Hat Enterprise Linux AppStream E4S (v. 8.1)
- java-1.8.0-openjdk-1:1.8.0.342.b07-1.el8_1.ppc64le as a component of Red Hat Enterprise Linux AppStream E4S (v. 8.1)
- java-1.8.0-openjdk-1:1.8.0.342.b07-1.el8_1.src as a component of Red Hat Enterprise Linux AppStream E4S (v. 8.1)
- java-1.8.0-openjdk-1:1.8.0.342.b07-1.el8_1.x86_64 as a component of Red Hat Enterprise Linux AppStream E4S (v. 8.1)
- java-1.8.0-openjdk-accessibility-1:1.8.0.342.b07-1.el8_1.ppc64le as a component of Red Hat Enterprise Linux AppStream E4S (v. 8.1)
- java-1.8.0-openjdk-accessibility-1:1.8.0.342.b07-1.el8_1.x86_64 as a component of Red Hat Enterprise Linux AppStream E4S (v. 8.1)
- java-1.8.0-openjdk-debuginfo-1:1.8.0.342.b07-1.el8_1.ppc64le as a component of Red Hat Enterprise Linux AppStream E4S (v. 8.1)
- java-1.8.0-openjdk-debuginfo-1:1.8.0.342.b07-1.el8_1.x86_64 as a component of Red Hat Enterprise Linux AppStream E4S (v. 8.1)
- java-1.8.0-openjdk-debugsource-1:1.8.0.342.b07-1.el8_1.ppc64le as a component of Red Hat Enterprise Linux AppStream E4S (v. 8.1)
- java-1.8.0-openjdk-debugsource-1:1.8.0.342.b07-1.el8_1.x86_64 as a component of Red Hat Enterprise Linux AppStream E4S (v. 8.1)
- java-1.8.0-openjdk-demo-1:1.8.0.342.b07-1.el8_1.ppc64le as a component of Red Hat Enterprise Linux AppStream E4S (v. 8.1)
- java-1.8.0-openjdk-demo-1:1.8.0.342.b07-1.el8_1.x86_64 as a component of Red Hat Enterprise Linux AppStream E4S (v. 8.1)
- java-1.8.0-openjdk-demo-debuginfo-1:1.8.0.342.b07-1.el8_1.ppc64le as a component of Red Hat Enterprise Linux AppStream E4S (v. 8.1)
- java-1.8.0-openjdk-demo-debuginfo-1:1.8.0.342.b07-1.el8_1.x86_64 as a component of Red Hat Enterprise Linux AppStream E4S (v. 8.1)
- java-1.8.0-openjdk-demo-slowdebug-debuginfo-1:1.8.0.342.b07-1.el8_1.ppc64le as a component of Red Hat Enterprise Linux AppStream E4S (v. 8.1)
- java-1.8.0-openjdk-demo-slowdebug-debuginfo-1:1.8.0.342.b07-1.el8_1.x86_64 as a component of Red Hat Enterprise Linux AppStream E4S (v. 8.1)
- java-1.8.0-openjdk-devel-1:1.8.0.342.b07-1.el8_1.ppc64le as a component of Red Hat Enterprise Linux AppStream E4S (v. 8.1)
- java-1.8.0-openjdk-devel-1:1.8.0.342.b07-1.el8_1.x86_64 as a component of Red Hat Enterprise Linux AppStream E4S (v. 8.1)
- java-1.8.0-openjdk-devel-debuginfo-1:1.8.0.342.b07-1.el8_1.ppc64le as a component of Red Hat Enterprise Linux AppStream E4S (v. 8.1)
- java-1.8.0-openjdk-devel-debuginfo-1:1.8.0.342.b07-1.el8_1.x86_64 as a component of Red Hat Enterprise Linux AppStream E4S (v. 8.1)
- java-1.8.0-openjdk-devel-slowdebug-debuginfo-1:1.8.0.342.b07-1.el8_1.ppc64le as a component of Red Hat Enterprise Linux AppStream E4S (v. 8.1)
- java-1.8.0-openjdk-devel-slowdebug-debuginfo-1:1.8.0.342.b07-1.el8_1.x86_64 as a component of Red Hat Enterprise Linux AppStream E4S (v. 8.1)
- java-1.8.0-openjdk-headless-1:1.8.0.342.b07-1.el8_1.ppc64le as a component of Red Hat Enterprise Linux AppStream E4S (v. 8.1)
- java-1.8.0-openjdk-headless-1:1.8.0.342.b07-1.el8_1.x86_64 as a component of Red Hat Enterprise Linux AppStream E4S (v. 8.1)
- java-1.8.0-openjdk-headless-debuginfo-1:1.8.0.342.b07-1.el8_1.ppc64le as a component of Red Hat Enterprise Linux AppStream E4S (v. 8.1)
- java-1.8.0-openjdk-headless-debuginfo-1:1.8.0.342.b07-1.el8_1.x86_64 as a component of Red Hat Enterprise Linux AppStream E4S (v. 8.1)
- java-1.8.0-openjdk-headless-slowdebug-debuginfo-1:1.8.0.342.b07-1.el8_1.ppc64le as a component of Red Hat Enterprise Linux AppStream E4S (v. 8.1)
- java-1.8.0-openjdk-headless-slowdebug-debuginfo-1:1.8.0.342.b07-1.el8_1.x86_64 as a component of Red Hat Enterprise Linux AppStream E4S (v. 8.1)
- java-1.8.0-openjdk-javadoc-1:1.8.0.342.b07-1.el8_1.noarch as a component of Red Hat Enterprise Linux AppStream E4S (v. 8.1)
- java-1.8.0-openjdk-javadoc-zip-1:1.8.0.342.b07-1.el8_1.noarch as a component of Red Hat Enterprise Linux AppStream E4S (v. 8.1)
- +4 more not shown
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 All running instances of OpenJDK Java must be restarted for this update to take effect.
🔗 References (6)
- selfhttps://access.redhat.com/errata/RHSA-2022:5701
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2108540
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2108543
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2108554
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2022/rhsa-2022_5701.json