Mageia 2024-0056: java-17-openjdk security update
Summary
The java-17-openjdk packages provide the OpenJDK 17 Java Runtime
Environment and the OpenJDK 17 Java Software Development Kit.
Security Fix(es):
OpenJDK: memory corruption issue on x86_64 with AVX-512 (8317121)
(CVE-2023-22025)
OpenJDK: certificate path validation issue during client authentication
(8309966) (CVE-2023-22081)
For more details about the security issue(s), including the impact, a
CVSS score, acknowledgments, and other related information, refer to the
CVE page(s) listed in the References section.
References
- https://bugs.mageia.org/show_bug.cgi?id=32545
- https://access.redhat.com/errata/RHSA-2023:5752
- https://www.oracle.com/security-alerts/cpuoct2023.html#AppendixJAVA
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22081
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22025
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-20932
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-20918
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-20952
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-20919
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-20921
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-20945
Resolution
MGASA-2024-0056 - Updated java-17-openjdk packages fix security vulnerabilities
SRPMS
- 9/core/java-17-openjdk-17.0.10.0.7-1.mga9