Advisories ยป MGASA-2024-0056

Updated java-17-openjdk packages fix security vulnerabilities

Publication date: 13 Mar 2024
Modification date: 13 Mar 2024
Type: security
Affected Mageia releases : 9
CVE: CVE-2023-22081 , CVE-2023-22025 , CVE-2024-20932 , CVE-2024-20918 , CVE-2024-20952 , CVE-2024-20919 , CVE-2024-20921 , CVE-2024-20945

Description

The java-17-openjdk packages provide the OpenJDK 17 Java Runtime
Environment and the OpenJDK 17 Java Software Development Kit.
Security Fix(es):
 OpenJDK: memory corruption issue on x86_64 with AVX-512 (8317121)
(CVE-2023-22025)
 OpenJDK: certificate path validation issue during client authentication
(8309966) (CVE-2023-22081)
For more details about the security issue(s), including the impact, a
CVSS score, acknowledgments, and other related information, refer to the
CVE page(s) listed in the References section.
                

References

SRPMS

9/core