Lucene search

K
oraclelinuxOracleLinuxELSA-2023-5731
HistoryNov 02, 2023 - 12:00 a.m.

java-1.8.0-openjdk security update

2023-11-0200:00:00
linux.oracle.com
13
security update
openjdk
shenandoah-jdk8u392-b08
segmentation fault
cve-2022-40433
ior deserialization
cve-2023-22067
certificate path validation
cve-2023-22081
maximum signature file size
rhel-13593

5.5 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

28.6%

[1:1.8.0.392.b08-4.0.1]

  • Update to shenandoah-jdk8u392-b08 (GA)
  • OpenJDK: segmentation fault in ciMethodBlocks (CVE-2022-40433)
  • OpenJDK: IOR deserialization issue in CORBA (8303384) (CVE-2023-22067)
  • OpenJDK: certificate path validation issue during client authentication (8309966) (CVE-2023-22081)
  • A maximum signature file size property, jdk.jar.maxSignatureFileSize, was introduced in the 8u382 release of OpenJDK by JDK-8300596, with a default of 8 MB. This default proved to be too small for some JAR files. This release, 8u392, increases it to 16 MB. (RHEL-13593)