Red Hat Security Advisory: java-1.8.0-openjdk security update
🔗 CVE IDs covered (12)
📋 Description
CVE-2022-21248 — OpenJDK: Incomplete deserialization class filtering in ObjectInputStream (Serialization, 8264934) CVE-2022-21282 — OpenJDK: Insufficient URI checks in the XSLT TransformerImpl (JAXP, 8270492) CVE-2022-21283 — OpenJDK: Unexpected exception thrown in regex Pattern (Libraries, 8268813) CVE-2022-21293 — OpenJDK: Incomplete checks of StringBuffer and StringBuilder during deserialization (Libraries, 8270392) CVE-2022-21294 — OpenJDK: Incorrect IdentityHashMap size checks during deserialization (Libraries, 8270416) CVE-2022-21296 — OpenJDK: Incorrect access checks in XMLEntityManager (JAXP, 8270498) CVE-2022-21299 — OpenJDK: Infinite loop related to incorrect handling of newlines in XMLEntityScanner (JAXP, 8270646) CVE-2022-21305 — OpenJDK: Array indexing issues in LIRGenerator (Hotspot, 8272014) CVE-2022-21340 — OpenJDK: Excessive resource use when reading JAR manifest attributes (Libraries, 8272026) CVE-2022-21341 — OpenJDK: Insufficient checks when deserializing exceptions in ObjectInputStream (Serialization, 8272236) CVE-2022-21360 — OpenJDK: Excessive memory allocation in BMPImageReader (ImageIO, 8273756) CVE-2022-21365 — OpenJDK: Integer overflow in BMPImageReader (ImageIO, 8273838)
🔗 References (15)
- selfhttps://access.redhat.com/errata/RHSA-2022:0312
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2041400
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2041417
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2041427
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2041435
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2041439
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2041472
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2041491
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2041785
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2041801
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2041878
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2041884
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2041897
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2022/rhsa-2022_0312.json