RHSA-2022:7053MediumCVSS 5.3

Red Hat Security Advisory: OpenJDK 17.0.5 Security Update for Portable Linux Builds

Published
October 20, 2022
Last Modified
September 7, 2026

🔗 CVE IDs covered (6)

📋 Description

CVE-2022-21618 — OpenJDK: improper MultiByte conversion can lead to buffer overflow (JGSS, 8286077) CVE-2022-21619 — OpenJDK: improper handling of long NTLM client hostnames (Security, 8286526) CVE-2022-21624 — OpenJDK: insufficient randomization of JNDI DNS port numbers (JNDI, 8286910) CVE-2022-21626 — OpenJDK: excessive memory allocation in X.509 certificate parsing (Security, 8286533) CVE-2022-21628 — OpenJDK: HttpServer no connection count limit (Lightweight HTTP Server, 8286918) CVE-2022-39399 — OpenJDK: missing SNI caching in HTTP/2 (Networking, 8289366)

🎯 Affected products1

  • Red Hat Build of OpenJDK 17.0.5

✅ Remediation

Before applying this update, make sure all previously-released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/documentation/en-us/openjdk/17/html/installing_and_using_openjdk_17_on_rhel/installing-openjdk11-on-rhel8_openjdk#installing-jdk11-on-rhel-using-archive_openjdk

🔗 References (9)