Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

SUSE Linux 12 SP5: 2023:4614-1 important: Java memory issues

suse
Calendar Grey November 29, 2023
Dist Suse Esm H88
SUSE issues critical update for Java, addressing major security flaws, coupled with instructions for implementation and revisions.
* bsc#1204264 * bsc#1216339 * bsc#1216374 * bsc#1216379 * bsc#1216640

Summary

## This update for java-1_8_0-ibm fixes the following issues: * Update to Java 8.0 Service Refresh 8 Fix Pack 15: * Oracle October 17 2023 CPU [bsc#1216640] Security fixes: * CVE-2023-22081: Fixed enhanced TLS connections (bsc#1216374) * CVE-2023-22067: Fixed IOR deserialization issue in CORBA (bsc#1216379) * CVE-2023-22025: Fixed memory corruption issue on x86_64 with AVX-512 (bsc#1216339) * CVE-2023-5676: Fixed receiving a signal before initialization may lead to an infinite loop or unexpected crash (bsc#1217214) Bug fixes: * IBM Java idlj compiler switch definition because IBM java idlj seems to confuse char and wchar for typedef types (bsc#1204264). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch".

References

* bsc#1204264

* bsc#1216339

* bsc#1216374

* bsc#1216379

* bsc#1216640

* bsc#1217214

Cross-

* CVE-2023-22025

* CVE-2023-22067

* CVE-2023-22081

* CVE-2023-5676

CVSS scores:

* CVE-2023-22025 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N

* CVE-2023-22025 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N

* CVE-2023-22067 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

* CVE-2023-22067 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

* CVE-2023-22081 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

* CVE-2023-22081 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

* CVE-2023-5676 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H

* CVE-2023-5676 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2023:4614-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here