Hash: SHA256
====================================================================
Red Hat Security Advisory
Synopsis: Moderate: OpenJDK 8u362 Security Update for Portable Linux Builds
Advisory ID: RHSA-2023:0387-01
Product: OpenJDK
Advisory URL: https://access.redhat.com/errata/RHSA-2023:0387
Issue date: 2023-01-23
CVE Names: CVE-2023-21830 CVE-2023-21843
====================================================================
1. Summary:
The Red Hat build of OpenJDK 8 (java-1.8.0-openjdk) is now available for
portable Linux.
Red Hat Product Security has rated this update as having a security impact
of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
gives a detailed severity rating, is available for each vulnerability from
the CVE link(s) in the References section.
2. Description:
The OpenJDK 8 packages provide the OpenJDK 8 Java Runtime Environment and
the OpenJDK 8 Java Software Development Kit.
This release of the Red Hat build of OpenJDK 8 (8u362) for portable Linux
serves as a replacement for Red Hat build of OpenJDK 8 (8u352) and includes
security and bug fixes as well as enhancements. For further information,
refer to the release notes linked to in the References section.
Security Fix(es):
* OpenJDK: soundbank URL remote loading (CVE-2023-21843)
* OpenJDK: improper restrictions in CORBA deserialization (CVE-2023-21830)
For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.
3. Solution:
Before applying this update, make sure all previously released errata
relevant to your system have been applied.
For details on how to apply this update, refer to:
https://access.redhat.com/articles/11258
4. Bugs fixed (https://bugzilla.redhat.com/):
2160475 – CVE-2023-21843 OpenJDK: soundbank URL remote loading (Sound, 8293742)
2160490 – CVE-2023-21830 OpenJDK: improper restrictions in CORBA deserialization (Serialization, 8285021)
5. References:
https://access.redhat.com/security/cve/CVE-2023-21830
https://access.redhat.com/security/cve/CVE-2023-21843
https://access.redhat.com/security/updates/classification/#moderate
6. Contact:
The Red Hat security contact is <secalert@redhat.com>. More contact
details at https://access.redhat.com/security/team/contact/
Copyright 2023 Red Hat, Inc.
—–BEGIN PGP SIGNATURE—–
Version: GnuPG v1
iQIVAwUBY89f3NzjgjWX9erEAQh35hAAkeXwAdEFfIoC7VcMIlyrh3MmHUnC6pjv
n975hBraglQ+KCQpLzdlfLKN86VnLo/Q5oS2m6E59qaAmbCA2teMiK71UEVhXRjx
NxuJpLAEqbjmNiKAHASCxnzTwJskcpKdyoQTCGg+i6muh2ZK++pYGj4WuX/x+OGe
RlDFV8NnvBukW6FqhCayEzpiiROC3dyN8nC5neHxQqcB6VEN4QF3wsEpQ/VaPrT4
GtmAVF5PCzdjaJtBHJGHYLVJ+lwffx2LlaVAb+Nj/lciVPiBMXd66Ll0aHFtNFCA
n/B95VGlW+oibJ74tGls0yjA8QdW99YoNmeLatQmv0h91UtOIIkUJ3dBRA7nOpPx
EZM+/rFCZKCFIj44PbE2wZ4Y6YVilntSkQfT9XDlVARrAPLtJg8nmoQMLzW26bKa
R2CZdDH0xE4GlrczPNRn9nYp7QP2T642/t47lq9pdquR6fwdte4kL9A1Jvsvq0aq
sGCdEi2UsP+26YcLJX3w27r/VqSaEL0QZ94ott7Oo3Edb/mcHPNujQ35ALhcoSn+
dveedRs5Lv8Di/5U8y6fhZtmZ+CxgaYLfH3iNOzDRg4Vfr9k3Pio4f0/i7JHn5Se
3UwILlk9BNNETpPvDy2IJTUzPkjpvMYeh5Yv1RzjxaNzmZA5efSe/Wrn2u2fdviK
PUxM2Ermgz4ðaN
—–END PGP SIGNATURE—–
—
RHSA-announce mailing list
RHSA-announce@redhat.com
https://listman.redhat.com/mailman/listinfo/rhsa-announce