Your submission was sent successfully! Close

USN-5388-2: OpenJDK vulnerabilities

26 April 2022

Several security issues were fixed in OpenJDK.

Releases

Packages

Details

It was discovered that OpenJDK incorrectly verified ECDSA signatures. An
attacker could use this issue to bypass the signature verification process.
(CVE-2022-21449)

It was discovered that OpenJDK incorrectly limited memory when compiling a
specially crafted XPath expression. An attacker could possibly use this
issue to cause a denial of service. (CVE-2022-21426)

It was discovered that OpenJDK incorrectly handled converting certain
object arguments into their textual representations. An attacker could
possibly use this issue to cause a denial of service. (CVE-2022-21434)

It was discovered that OpenJDK incorrectly validated the encoded length of
certain object identifiers. An attacker could possibly use this issue to
cause a denial of service. (CVE-2022-21443)

It was discovered that OpenJDK incorrectly validated certain paths. An
attacker could possibly use this issue to bypass the secure validation
feature and expose sensitive information in XML files. (CVE-2022-21476)

It was discovered that OpenJDK incorrectly parsed certain URI strings. An
attacker could possibly use this issue to make applications accept
invalid of malformed URI strings. (CVE-2022-21496)

Related notices

  • USN-5388-1: openjdk-11-demo, openjdk-11-jre-zero, openjdk-11-doc, openjdk-11-jdk-headless, openjdk-lts, openjdk-11-source, openjdk-11-jre-headless, openjdk-11-jre, openjdk-11-jdk
  • USN-5546-1: openjdk-8-jdk, openjdk-17-jre-zero, openjdk-8-source, openjdk-8-demo, openjdk-18, openjdk-8-jre-zero, openjdk-17-source, openjdk-17-jdk-headless, openjdk-11-jre, openjdk-11-jdk, openjdk-18-jre-headless, openjdk-11-demo, openjdk-18-source, openjdk-17, openjdk-17-jre, openjdk-8, openjdk-18-doc, openjdk-18-jre, openjdk-11-doc, openjdk-lts, openjdk-18-jdk-headless, openjdk-17-jdk, openjdk-8-jre-headless, openjdk-18-demo, openjdk-17-jre-headless, openjdk-8-jre, openjdk-18-jdk, openjdk-17-doc, openjdk-11-jre-zero, openjdk-11-jdk-headless, openjdk-8-jdk-headless, openjdk-11-source, openjdk-8-doc, openjdk-11-jre-headless, openjdk-18-jre-zero, openjdk-17-demo
  • USN-5546-2: openjdk-8-jdk, openjdk-8-jdk-headless, openjdk-8-source, openjdk-8-demo, openjdk-8-jre-zero, openjdk-8-doc, openjdk-8-jre-jamvm, openjdk-8-jre-headless, openjdk-8, openjdk-8-jre