Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

Ubuntu 22.10: USN-5898-1 Critical: OpenJDK Serialization Security Issues

ubuntu
Calendar Grey February 28, 2023
Scroller Ubuntu
Numerous vulnerabilities in OpenJDK have been addressed for Ubuntu distributions, encompassing problems related to serialization and the audio subsystem.
Several security issues were fixed in OpenJDK.

Summary

Several security issues were fixed in OpenJDK.

Software Description:

- openjdk-8: Open Source Java implementation

Details:

It was discovered that the Serialization component of OpenJDK did not

properly handle the deserialization of some CORBA objects. An attacker

could possibly use this to bypass Java sandbox restrictions.

(CVE-2023-21830)

Markus Loewe discovered that the Java Sound subsystem in OpenJDK did not

properly validate the origin of a Soundbank. An attacker could use this to

specially craft an untrusted Java application or applet that could load a

Soundbank from an attacker controlled remote URL. (CVE-2023-21843)

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 22.10:
  openjdk-8-jdk                   8u362-ga-0ubuntu1~22.10
  openjdk-8-jre                   8u362-ga-0ubuntu1~22.10
  openjdk-8-jre-headless          8u362-ga-0ubuntu1~22.10
  openjdk-8-jre-zero              8u362-ga-0ubuntu1~22.10

Ubuntu 22.04 LTS:
  openjdk-8-jdk                   8u362-ga-0ubuntu1~22.04
  openjdk-8-jre                   8u362-ga-0ubuntu1~22.04
  openjdk-8-jre-headless          8u362-ga-0ubuntu1~22.04
  openjdk-8-jre-zero              8u362-ga-0ubuntu1~22.04

Ubuntu 20.04 LTS:
  openjdk-8-jdk                   8u362-ga-0ubuntu1~20.04.1
  openjdk-8-jre                   8u362-ga-0ubuntu1~20.04.1
  openjdk-8-jre-headless          8u362-ga-0ubuntu1~20.04.1
  openjdk-8-jre-zero              8u362-ga-0ubuntu1~20.04.1

Ubuntu 18.04 LTS:
  openjdk-8-jdk                   8u362-ga-0ubuntu1~18.04.1
  openjdk-8-jre                   8u362-ga-0ubuntu1~18.04.1
  openjdk-8-jre-headless          8u362-ga-0ubuntu1~18.04.1
  openjdk-8-jre-zero              8u362-ga-0ubuntu1~18.04.1

Ubuntu 16.04 ESM:
  openjdk-8-jdk                   8u362-ga-0ubuntu1~16.04.1
  openjdk-8-jre                   8u362-ga-0ubuntu1~16.04.1
  openjdk-8-jre-headless          8u362-ga-0ubuntu1~16.04.1
  openjdk-8-jre-zero              8u362-ga-0ubuntu1~16.04.1

This update uses a new upstream release, which includes additional
bug fixes. After a standard system update you need to restart any
Java applications or applets to make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-5898-1

CVE-2023-21830, CVE-2023-21843

Severity
critical
Lowest
Low
Medium
High
Critical

February 28, 2023

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.