Gentoo: GLSA-202401-25: OpenJDK: Multiple Vulnerabilities
Summary
Multiple vulnerabilities have been discovered in OpenJDK. Please review
the CVE identifiers referenced below for details.
Resolution
All OpenJDK users should upgrade to the latest versions:
# emerge --sync
# emerge --ask --oneshot --verbose ">=dev-java/openjdk-8.372_p07"
# emerge --ask --oneshot --verbose ">=dev-java/openjdk-11.0.19_p7"
# emerge --ask --oneshot --verbose ">=dev-java/openjdk-17.0.7_p7"
All OpenJDK JRE binary users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose ">=dev-java/openjdk-jre-bin-8.372_p07"
# emerge --ask --oneshot --verbose ">=dev-java/openjdk-jre-bin-11.0.19_p7"
# emerge --ask --oneshot --verbose ">=dev-java/openjdk-jre-bin-17.0.7_p7"
All OpenJDK binary users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose ">=dev-java/openjdk-bin-8.372_p07"
# emerge --ask --oneshot --verbose ">=dev-java/openjdk-bin-11.0.19_p7"
# emerge --ask --oneshot --verbose ">=dev-java/openjdk-bin-17.0.7_p7"
References
[ 1 ] CVE-2022-21540
https://nvd.nist.gov/vuln/detail/CVE-2022-21540
[ 2 ] CVE-2022-21541
https://nvd.nist.gov/vuln/detail/CVE-2022-21541
[ 3 ] CVE-2022-21549
https://nvd.nist.gov/vuln/detail/CVE-2022-21549
[ 4 ] CVE-2022-21618
https://nvd.nist.gov/vuln/detail/CVE-2022-21618
[ 5 ] CVE-2022-21619
https://nvd.nist.gov/vuln/detail/CVE-2022-21619
[ 6 ] CVE-2022-21624
https://nvd.nist.gov/vuln/detail/CVE-2022-21624
[ 7 ] CVE-2022-21626
https://nvd.nist.gov/vuln/detail/CVE-2022-21626
[ 8 ] CVE-2022-21628
https://nvd.nist.gov/vuln/detail/CVE-2022-21628
[ 9 ] CVE-2022-34169
https://nvd.nist.gov/vuln/detail/CVE-2022-34169
[ 10 ] CVE-2022-39399
https://nvd.nist.gov/vuln/detail/CVE-2022-39399
[ 11 ] CVE-2022-42920
https://nvd.nist.gov/vuln/detail/CVE-2022-42920
[ 12 ] CVE-2023-21830
https://nvd.nist.gov/vuln/detail/CVE-2023-21830
[ 13 ] CVE-2023-21835
https://nvd.nist.gov/vuln/detail/CVE-2023-21835
[ 14 ] CVE-2023-21843
https://nvd.nist.gov/vuln/detail/CVE-2023-21843
Availability
This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:
https://security.gentoo.org/glsa/202401-25
Concerns
Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users' machines is of utmost
importance to us. Any security concerns should be addressed to
security@gentoo.org or alternatively, you may file a bug at
https://bugs.gentoo.org.
Synopsis
Multiple vulnerabilities have been discovered in OpenJDK, the worst of
which can lead to remote code execution.
Background
OpenJDK is an open source implementation of the Java programming
language.
Affected Packages
Package Vulnerable Unaffected
------------------------ --------------- ----------------
dev-java/openjdk < 11.0.19_p7:11 >= 11.0.19_p7:11
< 17.0.7_p7:17 >= 17.0.7_p7:17
< 8.372_p07:8 >= 8.372_p07:8
dev-java/openjdk-bin < 11.0.19_p7:11 >= 11.0.19_p7:11
< 17.0.7_p7:17 >= 17.0.7_p7:17
< 8.372_p07:8 >= 8.372_p07:8
dev-java/openjdk-jre-bin < 11.0.19_p7:11 >= 11.0.19_p7:11
< 17.0.7_p7:17 >= 17.0.7_p7:17
< 8.372_p07:8 >= 8.372_p07:8
Impact
Please review the referenced CVE identifiers for details.
Workaround
There is no known workaround at this time.