Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

SUSE: 2023:3665-1 Important: bci/openjdk-devel DoS Issue

suse
Calendar Grey November 2, 2023
Dist Suse Esm H88
SUSE enhances bci/openjdk-devel, tackling memory corruption and DoS vulnerabilities; refer to critical updates for specifics.
The container bci/openjdk-devel was updated

Summary

Advisory ID: SUSE-SU-2023:4289-1 Released: Tue Oct 31 09:15:08 2023 Summary: Security update for java-17-openjdk Type: security Severity: important Advisory ID: SUSE-RU-2023:4310-1 Released: Tue Oct 31 14:10:47 2023 Summary: Recommended update for libtirpc Type: recommended Severity: moderate

References

References : 1196647 1214790 1216339 1216374 CVE-2023-22025 CVE-2023-22081

1214790,1216339,1216374,CVE-2023-22025,CVE-2023-22081

This update for java-17-openjdk fixes the following issues:

- Updated to JDK 17.0.9+9 (October 2023 CPU):

- CVE-2023-22081: Fixed a partial denial of service issue that could

be triggered via HTTPS (bsc#1216374).

- CVE-2023-22025: Fixed a memory corruption issue in applications

using AVX-512 (bsc#1216339).

Please visit the Oracle Release Notes page for the full changelog:

https://www.oracle.com/java/technologies/javase/17all-relnotes.html

1196647

This Update for libtirpc to 1.3.4, fixing the following issues:

Update to 1.3.4 (bsc#1199467)

* binddynport.c honor ip_local_reserved_ports

- replaces: binddynport-honor-ip_local_reserved_ports.patch

Severity
important
Lowest
Low
Medium
High
Critical

Container Advisory ID : SUSE-CU-2023:3665-1
Container Tags : bci/openjdk-devel:17 , bci/openjdk-devel:17-12.57 , bci/openjdk-devel:latest
Container Release : 12.57
Severity : important
Type : security

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here