This update for java-11-openjdk fixes the following issues:
- CVE-2022-21248: Fixed incomplete deserialization class filtering in
ObjectInputStream. (bnc#1194926)
- CVE-2022-21277: Fixed incorrect reading of TIFF files in
TIFFNullDecompressor. (bnc#1194930)
- CVE-2022-21282: Fixed Insufficient URI checks in the XSLT
TransformerImpl. (bnc#1194933)
- CVE-2022-21283: Fixed unexpected exception thrown in regex Pattern.
(bnc#1194937)
- CVE-2022-21291: Fixed Incorrect marking of writeable fields.
(bnc#1194925)
- CVE-2022-21293: Fixed Incomplete checks of StringBuffer and
StringBuilder during deserialization. (bnc#1194935)
- CVE-2022-21294: Fixed Incorrect IdentityHashMap size checks during
deserialization. (bnc#1194934)
- CVE-2022-21296: Fixed Incorrect access checks in XMLEntityManager.
(bnc#1194932)
- CVE-2022-21299: Fixed Infinite loop related to incorrect handling of
newlines in XMLEntityScanner. (bnc#1194931)
...
Read the Full AdvisoryPatch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 15.3:
zypper in -t patch openSUSE-SLE-15.3-2022-816=1
- openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64):
java-11-openjdk-11.0.14.0-3.74.2
java-11-openjdk-accessibility-11.0.14.0-3.74.2
java-11-openjdk-accessibility-debuginfo-11.0.14.0-3.74.2
java-11-openjdk-debugsource-11.0.14.0-3.74.2
java-11-openjdk-demo-11.0.14.0-3.74.2
java-11-openjdk-devel-11.0.14.0-3.74.2
java-11-openjdk-headless-11.0.14.0-3.74.2
java-11-openjdk-jmods-11.0.14.0-3.74.2
java-11-openjdk-src-11.0.14.0-3.74.2
- openSUSE Leap 15.3 (noarch):
java-11-openjdk-javadoc-11.0.14.0-3.74.2
https://www.suse.com/security/cve/CVE-2022-21248.html
https://www.suse.com/security/cve/CVE-2022-21277.html
https://www.suse.com/security/cve/CVE-2022-21282.html
https://www.suse.com/security/cve/CVE-2022-21283.html
https://www.suse.com/security/cve/CVE-2022-21291.html
https://www.suse.com/security/cve/CVE-2022-21293.html
https://www.suse.com/security/cve/CVE-2022-21294.html
https://www.suse.com/security/cve/CVE-2022-21296.html
https://www.suse.com/security/cve/CVE-2022-21299.html
https://www.suse.com/security/cve/CVE-2022-21305.html
https://www.suse.com/security/cve/CVE-2022-21340.html
https://www.suse.com/security/cve/CVE-2022-21341.html
https://www.suse.com/security/cve/CVE-2022-21360.html
https://www.suse.com/security/cve/CVE-2022-21365.html
https://www.suse.com/security/cve/CVE-2022-21366.html
https://bugzilla.suse.com/1194925
https://bugzilla.suse.com/1194926
https://bugzilla.suse.com/1194927
https://bugzilla.suse.com/1194928
https://bugzilla.suse.com/1194929
https://bugzilla.suse.com/1194930
https:/...
Read the Full AdvisoryGet the latest Linux and open source security news straight to your inbox.