Oracle Java SE and Oracle GraalVM Enterprise Edition product of Oracle Java SE (their component: Libraries) are vulnerable to signature verification bypass. The vulnerability is possible due to a flawed implementation of ECDSA verification code rewritten from native C++ code, allowing an attacker to forge signature and bypass signature verification. The vulnerability exists only for Java 15, 16, 17, or 18 version.
www.openwall.com/lists/oss-security/2022/04/28/2
www.openwall.com/lists/oss-security/2022/04/28/3
www.openwall.com/lists/oss-security/2022/04/28/4
www.openwall.com/lists/oss-security/2022/04/28/5
www.openwall.com/lists/oss-security/2022/04/28/6
www.openwall.com/lists/oss-security/2022/04/28/7
www.openwall.com/lists/oss-security/2022/04/29/1
www.openwall.com/lists/oss-security/2022/04/30/1
www.openwall.com/lists/oss-security/2022/04/30/2
www.openwall.com/lists/oss-security/2022/04/30/3
www.openwall.com/lists/oss-security/2022/04/30/4
www.openwall.com/lists/oss-security/2022/05/01/1
www.openwall.com/lists/oss-security/2022/05/01/2
www.openwall.com/lists/oss-security/2022/05/02/1
backstage.forgerock.com/knowledge/kb/article/a90257583
bitbucket.org/connect2id/nimbus-jose-jwt/commits/651580526d8e815420e06abe31c0b4976c4afec9
bugs.openjdk.java.net/browse/JDK-8235710
bugs.openjdk.java.net/browse/JDK-8285389
connect2id.com/blog/cve-2022-21449
docs.oracle.com/en/graalvm/enterprise/20/docs/overview/release-notes
github.com/khalednassar/CVE-2022-21449-TLS-PoC
neilmadden.blog/2022/04/19/psychic-signatures-in-java
neilmadden.blog/2022/04/25/a-few-clarifications-about-cve-2022-21449
openjdk.java.net/groups/vulnerability/advisories/2022-04-19
security.netapp.com/advisory/ntap-20220429-0006/
www.debian.org/security/2022/dsa-5128
www.debian.org/security/2022/dsa-5131
www.oracle.com/security-alerts/cpuapr2022.html