Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

UBUNTU: 2023:5432-3 Critical: JDK/OpenJRE Vulnerability Patch

suse
Calendar Grey October 26, 2022
Scroller Suse
SUSE Container Security Notice SUSE-CU-2023:4519-1 contains essential updates to address various vulnerabilities.
The container bci/openjdk-devel was updated

Summary

Advisory ID: SUSE-RU-2022:2796-1 Released: Fri Aug 12 14:34:31 2022 Summary: Recommended update for jitterentropy Type: recommended Severity: moderate Advisory ID: SUSE-RU-2022:3328-1 Released: Wed Sep 21 12:48:56 2022 Summary: Recommended update for jitterentropy Type: recommended Severity: moderate Advisory ID: SUSE-SU-2022:3489-1 Released: Sat Oct 1 13:35:24 2022

References

References : 1121365 1180995 1182983 1190651 1190653 1190700 1190888 1191020

1193859 1198471 1198472 1199492 1201293 1202117 1202148 1202870

1203046 1203069 1203438 1204366 1204367 CVE-2022-40303 CVE-2022-40304

CVE-2022-40674

This update for jitterentropy fixes the following issues:

jitterentropy is included in version 3.4.0 (jsc#SLE-24941):

This is a FIPS 140-3 / NIST 800-90b compliant userspace jitter entropy generator library,

used by other FIPS libraries.

1202870

This update for jitterentropy fixes the following issues:

- Hide the non-GNUC constructs that are library internal from the

exported header, to make it usable in builds with strict C99

compliance. (bsc#1202870)

1203438,CVE-2022-40674

This update for expat fixes the following issues:

Severity
important
Lowest
Low
Medium
High
Critical

Container Advisory ID : SUSE-CU-2022:2722-1
Container Tags : bci/openjdk-devel:11 , bci/openjdk-devel:11-36.11 , bci/openjdk-devel:latest
Container Release : 36.11
Severity : important
Type : security

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.