Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

SUSE: 2022:1730-1 Important: Bci/Openjdk Security Threats

suse
Calendar Grey August 2, 2022
Dist Suse Esm H88
Urgent security patch for bci/openjdk tackling multiple significant bugs and weaknesses found in NSS.
The container bci/openjdk was updated

Summary

Advisory ID: SUSE-SU-2022:2595-1 Released: Fri Jul 29 16:00:42 2022 Summary: Security update for mozilla-nss Type: security Severity: important

References

References : 1192079 1192080 1192086 1192087 1192228 1198486 1200027 CVE-2022-31741

1192079,1192080,1192086,1192087,1192228,1198486,1200027,CVE-2022-31741

This update for mozilla-nss fixes the following issues:

Various FIPS 140-3 related fixes were backported from SUSE Linux Enterprise 15 SP4:

- Makes the PBKDF known answer test compliant with NIST SP800-132. (bsc#1192079).

- FIPS: Add on-demand integrity tests through sftk_FIPSRepeatIntegrityCheck()

(bsc#1198980).

- FIPS: mark algorithms as approved/non-approved according to security policy

(bsc#1191546, bsc#1201298).

- FIPS: remove hard disabling of unapproved algorithms. This requirement is now

fulfilled by the service level indicator (bsc#1200325).

- Run test suite at build time, and make it pass (bsc#1198486).

Severity
important
Lowest
Low
Medium
High
Critical

Container Advisory ID : SUSE-CU-2022:1730-1
Container Tags : bci/openjdk:11 , bci/openjdk:11-12.27 , bci/openjdk:latest
Container Release : 12.27
Severity : important
Type : security

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here