RHSA-2023:4210MediumCVSS 7.5

Red Hat Security Advisory: OpenJDK 17.0.8 Security Update for Portable Linux Builds

Published
July 20, 2023
Last Modified
September 7, 2026

🔗 CVE IDs covered (7)

📋 Description

CVE-2023-22006 — OpenJDK: HTTP client insufficient file name validation (8302475) CVE-2023-22036 — OpenJDK: ZIP file parsing infinite loop (8302483) CVE-2023-22041 — OpenJDK: weakness in AES implementation (8308682) CVE-2023-22044 — OpenJDK: modulo operator array indexing issue (8304460) CVE-2023-22045 — OpenJDK: array indexing integer overflow issue (8304468) CVE-2023-22049 — OpenJDK: improper handling of slash characters in URI-to-path conversion (8305312) CVE-2023-25193 — harfbuzz: allows attackers to trigger O(n^2) growth via consecutive marks

🎯 Affected products1

  • Red Hat Build of OpenJDK 17.0.8

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258

🔗 References (11)