Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Debian DSA-5128-1 Critical: OpenJDK-17 Information Disclosure Risk

debian
Calendar Grey May 3, 2022
Debian Logo
Multiple weaknesses in OpenJDK Java environment could lead to exposure of sensitive data or service disruptions. It is advised to upgrade.
Several vulnerabilities have been discovered in the OpenJDK Java runtime, which may result in information disclosure, incorrect validation of ECDSA signatures or denial of service

Summary

Several vulnerabilities have been discovered in the OpenJDK Java runtime,
which may result in information disclosure, incorrect validation of ECDSA
signatures or denial of service.

For the stable distribution (bullseye), these problems have been fixed in
version 17.0.3+7-1~deb11u1.

We recommend that you upgrade your openjdk-17 packages.

For the detailed security status of openjdk-17 please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/openjdk-17

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/



Severity
critical
Lowest
Low
Medium
High
Critical

Package: openjdk-17
CVE ID: CVE-2022-21426 CVE-2022-21434 CVE-2022-21443 CVE-2022-21449

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here