Lucene search

K
ubuntuUbuntuUSN-6527-1
HistoryNov 29, 2023 - 12:00 a.m.

OpenJDK vulnerabilities

2023-11-2900:00:00
ubuntu.com
26
openjdk
ubuntu
memory corruption
pkix certification
denial of service
arbitrary code
cve-2023-22025
cve-2023-22081

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

6.3 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

28.8%

Releases

  • Ubuntu 23.10
  • Ubuntu 23.04
  • Ubuntu 22.04 LTS
  • Ubuntu 20.04 LTS
  • Ubuntu 18.04 ESM

Packages

  • openjdk-17 - Open Source Java implementation
  • openjdk-21 - Open Source Java implementation
  • openjdk-lts - Open Source Java implementation

Details

Carter Kozak discovered that OpenJDK, when compiling with AVX-512
instruction support enabled, could produce code that resulted in memory
corruption in certain situations. An attacker targeting applications built
in this way could possibly use this to cause a denial of service or execute
arbitrary code. In Ubuntu, OpenJDK defaults to not using AVX-512
instructions. (CVE-2023-22025)

It was discovered that OpenJDK did not properly perform PKIX certification
path validation in certain situations. An attacker could use this to cause
a denial of service. (CVE-2023-22081)

OSVersionArchitecturePackageVersionFilename
Ubuntu23.10noarchopenjdk-11-jdk< 11.0.21+9-0ubuntu1~23.10UNKNOWN
Ubuntu23.10noarchopenjdk-11-dbg< 11.0.21+9-0ubuntu1~23.10UNKNOWN
Ubuntu23.10noarchopenjdk-11-demo< 11.0.21+9-0ubuntu1~23.10UNKNOWN
Ubuntu23.10noarchopenjdk-11-doc< 11.0.21+9-0ubuntu1~23.10UNKNOWN
Ubuntu23.10noarchopenjdk-11-jdk-headless< 11.0.21+9-0ubuntu1~23.10UNKNOWN
Ubuntu23.10noarchopenjdk-11-jre< 11.0.21+9-0ubuntu1~23.10UNKNOWN
Ubuntu23.10noarchopenjdk-11-jre-headless< 11.0.21+9-0ubuntu1~23.10UNKNOWN
Ubuntu23.10noarchopenjdk-11-jre-zero< 11.0.21+9-0ubuntu1~23.10UNKNOWN
Ubuntu23.10noarchopenjdk-11-source< 11.0.21+9-0ubuntu1~23.10UNKNOWN
Ubuntu23.10noarchopenjdk-17-jdk< 17.0.9+9-1~23.10UNKNOWN
Rows per page:
1-10 of 1181

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

6.3 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

28.8%