RHSA-2023:5745MediumCVSS 5.3
Red Hat Security Advisory: OpenJDK 17.0.9 Security Update for Portable Linux Builds
🔗 CVE IDs covered (3)
📋 Description
CVE-2023-2004 — freetype: integer overflowin in tt_hvadvance_adjust() in src/truetype/ttgxvar.c CVE-2023-22025 — OpenJDK: memory corruption issue on x86_64 with AVX-512 (8317121) CVE-2023-22081 — OpenJDK: certificate path validation issue during client authentication (8309966)
🎯 Affected products1
- Red Hat Build of OpenJDK 17.0.9
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258
🔗 References (6)
- selfhttps://access.redhat.com/errata/RHSA-2023:5745
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2186428
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2243627
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2243805
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_5745.json