Alerts This Week
Warning Icon 1 631
Alerts This Week
Warning Icon 1 631

Mageia: MGASA-2023-0326 moderate: OpenJDK segmentation fault advisory

mageia
Calendar Grey November 28, 2023
Dist Mageia Esm H88
Updated OpenJDK packages for Java resolve segmentation faults and SSL certificate validation issues on Mageia platforms.
The updated packages fix security vulnerabilities: Segmentation fault in ciMethodBlocks

Summary

The updated packages fix security vulnerabilities:
Segmentation fault in ciMethodBlocks. (CVE-2022-40433)
Certificate path validation issue during client authentication. (CVE-2023-22081)
IOR deserialization issue in CORBA. (CVE-2023-22067)

References

- https://bugs.mageia.org/show_bug.cgi?id=32413

- https://access.redhat.com/errata/RHSA-2023:5732

- https://access.redhat.com/errata/RHSA-2023:5736

- https://www.oracle.com/security-alerts/cpuoct2023.html#AppendixJAVA

- https://www.cve.org/CVERecord?id=CVE-2022-40433

- https://www.cve.org/CVERecord?id=CVE-2023-22081

- https://www.cve.org/CVERecord?id=CVE-2023-22067

Resolution

SRPMS

- 8/core/java-1.8.0-openjdk-1.8.0.392.b08-1.mga8

- 8/core/java-11-openjdk-11.0.21.0.9-1.mga8

- 9/core/java-1.8.0-openjdk-1.8.0.392.b08-1.mga9

- 9/core/java-11-openjdk-11.0.21.0.9-1.mga9

- 9/core/java-latest-openjdk-21.0.1.0.12-1.rolling.1.mga9

Publication date: 28 Nov 2023
URL: https://advisories.mageia.org/MGASA-2023-0326.html
Type: security
CVE: CVE-2022-40433, CVE-2023-22081, CVE-2023-22067

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here