Updated java-17-openjdk packages fix security vulnerabilities
Publication date: 13 Mar 2024Modification date: 13 Mar 2024
Type: security
Affected Mageia releases : 9
CVE: CVE-2023-22081 , CVE-2023-22025 , CVE-2024-20932 , CVE-2024-20918 , CVE-2024-20952 , CVE-2024-20919 , CVE-2024-20921 , CVE-2024-20945
Description
The java-17-openjdk packages provide the OpenJDK 17 Java Runtime Environment and the OpenJDK 17 Java Software Development Kit. Security Fix(es): OpenJDK: memory corruption issue on x86_64 with AVX-512 (8317121) (CVE-2023-22025) OpenJDK: certificate path validation issue during client authentication (8309966) (CVE-2023-22081) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
References
- https://bugs.mageia.org/show_bug.cgi?id=32545
- https://access.redhat.com/errata/RHSA-2023:5752
- https://www.oracle.com/security-alerts/cpuoct2023.html#AppendixJAVA
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22081
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22025
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-20932
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-20918
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-20952
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-20919
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-20921
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-20945
SRPMS
9/core
- java-17-openjdk-17.0.10.0.7-1.mga9