Red Hat Security Advisory: OpenJDK 8u352 Security Update for Portable Linux Builds
🔗 CVE IDs covered (4)
📋 Description
CVE-2022-21619 — OpenJDK: improper handling of long NTLM client hostnames (Security, 8286526) CVE-2022-21624 — OpenJDK: insufficient randomization of JNDI DNS port numbers (JNDI, 8286910) CVE-2022-21626 — OpenJDK: excessive memory allocation in X.509 certificate parsing (Security, 8286533) CVE-2022-21628 — OpenJDK: HttpServer no connection count limit (Lightweight HTTP Server, 8286918)
🎯 Affected products1
- Red Hat Build of OpenJDK 8u352
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/documentation/en-us/openjdk/8/html/installing_and_using_openjdk_8_for_rhel/assembly_installing-openjdk-8-on-red-hat-enterprise-linux_openjdk#installing-jdk11-on-rhel-using-archive_openjdk
🔗 References (7)
- selfhttps://access.redhat.com/errata/RHSA-2022:7050
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2133745
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2133753
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2133765
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2133769
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2022/rhsa-2022_7050.json