Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

openSUSE 15.3 & 15.4: Security Update for OpenJDK Java 1.8 Important Patch

opensuse
Calendar Grey March 16, 2022
Dist Opensuse Esm H88
A vital patch has been released for openSUSE java-1_8_0-openjdk, tackling 13 vulnerabilities and delivering essential corrections.
An update that solves 13 vulnerabilities and has three fixes is now available

Description

This update for java-1_8_0-openjdk fixes the following issues:

Update to version jdk8u322 (icedtea-3.22.0)

Including the following security fixes:

- CVE-2022-21248, bsc#1194926: Enhance cross VM serialization

- CVE-2022-21283, bsc#1194937: Better String matching

- CVE-2022-21293, bsc#1194935: Improve String constructions

- CVE-2022-21294, bsc#1194934: Enhance construction of Identity maps

- CVE-2022-21282, bsc#1194933: Better resolution of URIs

- CVE-2022-21296, bsc#1194932: Improve SAX Parser configuration management

- CVE-2022-21299, bsc#1194931: Improved scanning of XML entities

- CVE-2022-21305, bsc#1194939: Better array indexing

- CVE-2022-21340, bsc#1194940: Verify Jar Verification

- CVE-2022-21341, bsc#1194941: Improve serial forms for transport

- CVE-2022-21349: Improve Solaris font rendering

- CVE-2022-21360, bsc#1194929: Enhance BMP image support

- CVE-2022-21365, bsc#1194928: Enhanced BMP processing

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.4:

zypper in -t patch openSUSE-SLE-15.4-2022-873=1

- openSUSE Leap 15.3:

zypper in -t patch openSUSE-SLE-15.3-2022-873=1

Package List

- openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64):

java-1_8_0-openjdk-1.8.0.322-3.64.2

java-1_8_0-openjdk-accessibility-1.8.0.322-3.64.2

java-1_8_0-openjdk-debuginfo-1.8.0.322-3.64.2

java-1_8_0-openjdk-debugsource-1.8.0.322-3.64.2

java-1_8_0-openjdk-demo-1.8.0.322-3.64.2

java-1_8_0-openjdk-demo-debuginfo-1.8.0.322-3.64.2

java-1_8_0-openjdk-devel-1.8.0.322-3.64.2

java-1_8_0-openjdk-devel-debuginfo-1.8.0.322-3.64.2

java-1_8_0-openjdk-headless-1.8.0.322-3.64.2

java-1_8_0-openjdk-headless-debuginfo-1.8.0.322-3.64.2

java-1_8_0-openjdk-src-1.8.0.322-3.64.2

- openSUSE Leap 15.4 (noarch):

java-1_8_0-openjdk-javadoc-1.8.0.322-3.64.2

- openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64):

java-1_8_0-openjdk-1.8.0.322-3.64.2

java-1_8_0-openjdk-accessibility-1.8.0.322-3.64.2

java-1_8_0-openjdk-debuginfo-1.8.0.322-3.64.2

java-1_8_0-openjdk-debugsource-1.8.0.322-3.64.2

java-1_8_0-openjdk-demo-1.8.0.322-3.64.2

java-1_8_0-openjdk-demo-debuginfo-1.8.0.322-3.64.2

java-1_8_0-openjdk-devel-1.8.0.322-3.64.2

java-1_8_0-openjdk-de...

Read the Full Advisory

References

https://www.suse.com/security/cve/CVE-2022-21248.html

https://www.suse.com/security/cve/CVE-2022-21282.html

https://www.suse.com/security/cve/CVE-2022-21283.html

https://www.suse.com/security/cve/CVE-2022-21293.html

https://www.suse.com/security/cve/CVE-2022-21294.html

https://www.suse.com/security/cve/CVE-2022-21296.html

https://www.suse.com/security/cve/CVE-2022-21299.html

https://www.suse.com/security/cve/CVE-2022-21305.html

https://www.suse.com/security/cve/CVE-2022-21340.html

https://www.suse.com/security/cve/CVE-2022-21341.html

https://www.suse.com/security/cve/CVE-2022-21349.html

https://www.suse.com/security/cve/CVE-2022-21360.html

https://www.suse.com/security/cve/CVE-2022-21365.html

https://bugzilla.suse.com/1193314

https://bugzilla.suse.com/1193444

https://bugzilla.suse.com/1193491

https://bugzilla.suse.com/1194926

https://bugzilla.suse.com/1194928

https://bugzilla.suse.com/1194929

https://bugzilla.suse.com/1194931

https://bugzilla.suse.com/1194932

https://bugzilla.suse.com/1194933

https://bugzil...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2022:0873-1
Rating: important
Affected Products: openSUSE Leap 15.3 openSUSE Leap 15.4 ble.

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here