Alerts This Week
Warning Icon 1 1,179
Alerts This Week
Warning Icon 1 1,179

Gentoo: GLSA-202412-07: OpenJDK: Security Advisory Updates

gentoo
Calendar Grey December 7, 2024
Dist Gentoo Esm H88
Secure your system by patching OpenJDK against critical issues highlighted in high-severity Gentoo advisory GLSA 202412-07.
Multiple vulnerabilities have been discovered in OpenJDK, the worst of which could lead to remote code execution.

Summary

Multiple vulnerabilities have been discovered in OpenJDK. Please review the CVE identifiers referenced below for details.

Resolution

All OpenJDK users should upgrade to the latest version:
# emerge --sync # emerge --ask --oneshot --verbose ">=dev-java/openjdk-8.422_p05:8" # emerge --ask --oneshot --verbose ">=dev-java/openjdk-11.0.24_p8:11" # emerge --ask --oneshot --verbose ">=dev-java/openjdk-17.0.12_p7:17"
All OpenJDK users should upgrade to the latest version:
# emerge --sync # emerge --ask --oneshot --verbose ">=dev-java/openjdk-jre-bin-8.442_p05:8" # emerge --ask --oneshot --verbose ">=dev-java/openjdk-jre-bin-11.0.24_p8:11" # emerge --ask --oneshot --verbose ">=dev-java/openjdk-jre-bin-17.0.12_p7:17"
All OpenJDK users should upgrade to the latest version:
# emerge --sync # emerge --ask --oneshot --verbose ">=dev-java/openjdk-bin-8.442_p05:8" # emerge --ask --oneshot --verbose ">=dev-java/openjdk-bin-11.0.24_p8:11" # emerge --ask --oneshot --verbose ">=dev-java/openjdk-bin-17.0.12_p7:17"

References

[ 1 ] CVE-2023-22006 https://nvd.nist.gov/vuln/detail/CVE-2023-22006 [ 2 ] CVE-2023-22025 https://nvd.nist.gov/vuln/detail/CVE-2023-22025 [ 3 ] CVE-2023-22036 https://nvd.nist.gov/vuln/detail/CVE-2023-22036 [ 4 ] CVE-2023-22041 https://nvd.nist.gov/vuln/detail/CVE-2023-22041 [ 5 ] CVE-2023-22044 https://nvd.nist.gov/vuln/detail/CVE-2023-22044 [ 6 ] CVE-2023-22045 https://nvd.nist.gov/vuln/detail/CVE-2023-22045 [ 7 ] CVE-2023-22049 https://nvd.nist.gov/vuln/detail/CVE-2023-22049 [ 8 ] CVE-2023-22067 https://nvd.nist.gov/vuln/detail/CVE-2023-22067 [ 9 ] CVE-2023-22081 https://nvd.nist.gov/vuln/detail/CVE-2023-22081 [ 10 ] CVE-2024-20918 https://nvd.nist.gov/vuln/detail/CVE-2024-20918 [ 11 ] CVE-2024-20919 https://nvd.nist.gov/vuln/detail/CVE-2024-20919 [ 12 ] CVE-2024-20921 https://nvd.nist.gov/vuln/detail/CVE-2024-20921 [ 13 ] CVE-2024-20926 https://nvd.nist.gov/vuln/detail/CVE-2024-20926 [ 14 ] CVE-2024-20...

Read the Full Advisory

Availability

This GLSA and any updates to it are available for viewing at the Gentoo Security Website:
https://security.gentoo.org/glsa/202412-07
style>.gentoo_availability{display:block;}

Concerns

Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to security@gentoo.org or alternatively, you may file a bug at https://bugs.gentoo.org.

Severity: High
Title: OpenJDK: Multiple Vulnerabilities
Date: December 07, 2024
Bugs: #912719, #916211, #925020, #941689
ID: 202412-07

Topics%20covered

Topics Covered

No topics assigned

Synopsis

Multiple vulnerabilities have been discovered in OpenJDK, the worst of which could lead to remote code execution.

Background

OpenJDK is an open source implementation of the Java programming language.

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Package Vulnerable Unaffected ------------------------ --------------- ---------------- dev-java/openjdk < 11.0.24_p8:11 >= 11.0.24_p8:11 < 17.0.12_p7:17 >= 17.0.12_p7:17 < 8.422_p05:8 >= 8.422_p05:8 dev-java/openjdk-bin < 11.0.24_p8:11 >= 11.0.24_p8:11 < 17.0.12_p7:17 >= 17.0.12_p7:17 < 8.422_p05:8 >= 8.422_p05:8 dev-java/openjdk-jre-bin < 11.0.24_p8:11 >= 11.0.24_p8:11 < 17.0.12_p7:17 >= 17.0.12_p7:17 < 8.422_p05:8 >= 8.422_p05:8

Impact

Please review the referenced CVE identifiers for details.

Workaround

There is no known workaround at this time.

Your message here