RHSA-2022:4957MediumCVSS 5.3
Red Hat Security Advisory: java-1.7.1-ibm security update
🔗 CVE IDs covered (5)
📋 Description
CVE-2021-35561 — OpenJDK: Excessive memory allocation in HashMap and HashSet (Utility, 8266097) CVE-2022-21299 — OpenJDK: Infinite loop related to incorrect handling of newlines in XMLEntityScanner (JAXP, 8270646) CVE-2022-21434 — OpenJDK: Improper object-to-string conversion in AnnotationInvocationHandler (Libraries, 8277672) CVE-2022-21443 — OpenJDK: Missing check for negative ObjectIdentifier (Libraries, 8275151) CVE-2022-21496 — OpenJDK: URI parsing inconsistencies (JNDI, 8278972)
🎯 Affected products41
- Red Hat Enterprise Linux Client Supplementary (v. 7)
- Red Hat Enterprise Linux ComputeNode Supplementary (v. 7)
- Red Hat Enterprise Linux Server Supplementary (v. 7)
- Red Hat Enterprise Linux Workstation Supplementary (v. 7)
- java-1.7.1-ibm-1:1.7.1.5.10-1jpp.1.el7.ppc64 as a component of Red Hat Enterprise Linux Server Supplementary (v. 7)
- java-1.7.1-ibm-1:1.7.1.5.10-1jpp.1.el7.ppc64le as a component of Red Hat Enterprise Linux Server Supplementary (v. 7)
- java-1.7.1-ibm-1:1.7.1.5.10-1jpp.1.el7.s390x as a component of Red Hat Enterprise Linux Server Supplementary (v. 7)
- java-1.7.1-ibm-1:1.7.1.5.10-1jpp.1.el7.x86_64 as a component of Red Hat Enterprise Linux Client Supplementary (v. 7)
- java-1.7.1-ibm-1:1.7.1.5.10-1jpp.1.el7.x86_64 as a component of Red Hat Enterprise Linux ComputeNode Supplementary (v. 7)
- java-1.7.1-ibm-1:1.7.1.5.10-1jpp.1.el7.x86_64 as a component of Red Hat Enterprise Linux Server Supplementary (v. 7)
- java-1.7.1-ibm-1:1.7.1.5.10-1jpp.1.el7.x86_64 as a component of Red Hat Enterprise Linux Workstation Supplementary (v. 7)
- java-1.7.1-ibm-demo-1:1.7.1.5.10-1jpp.1.el7.ppc64 as a component of Red Hat Enterprise Linux Server Supplementary (v. 7)
- java-1.7.1-ibm-demo-1:1.7.1.5.10-1jpp.1.el7.ppc64le as a component of Red Hat Enterprise Linux Server Supplementary (v. 7)
- java-1.7.1-ibm-demo-1:1.7.1.5.10-1jpp.1.el7.s390x as a component of Red Hat Enterprise Linux Server Supplementary (v. 7)
- java-1.7.1-ibm-demo-1:1.7.1.5.10-1jpp.1.el7.x86_64 as a component of Red Hat Enterprise Linux Client Supplementary (v. 7)
- java-1.7.1-ibm-demo-1:1.7.1.5.10-1jpp.1.el7.x86_64 as a component of Red Hat Enterprise Linux ComputeNode Supplementary (v. 7)
- java-1.7.1-ibm-demo-1:1.7.1.5.10-1jpp.1.el7.x86_64 as a component of Red Hat Enterprise Linux Server Supplementary (v. 7)
- java-1.7.1-ibm-demo-1:1.7.1.5.10-1jpp.1.el7.x86_64 as a component of Red Hat Enterprise Linux Workstation Supplementary (v. 7)
- java-1.7.1-ibm-devel-1:1.7.1.5.10-1jpp.1.el7.ppc64 as a component of Red Hat Enterprise Linux Server Supplementary (v. 7)
- java-1.7.1-ibm-devel-1:1.7.1.5.10-1jpp.1.el7.ppc64le as a component of Red Hat Enterprise Linux Server Supplementary (v. 7)
- java-1.7.1-ibm-devel-1:1.7.1.5.10-1jpp.1.el7.s390x as a component of Red Hat Enterprise Linux Server Supplementary (v. 7)
- java-1.7.1-ibm-devel-1:1.7.1.5.10-1jpp.1.el7.x86_64 as a component of Red Hat Enterprise Linux Client Supplementary (v. 7)
- java-1.7.1-ibm-devel-1:1.7.1.5.10-1jpp.1.el7.x86_64 as a component of Red Hat Enterprise Linux ComputeNode Supplementary (v. 7)
- java-1.7.1-ibm-devel-1:1.7.1.5.10-1jpp.1.el7.x86_64 as a component of Red Hat Enterprise Linux Server Supplementary (v. 7)
- java-1.7.1-ibm-devel-1:1.7.1.5.10-1jpp.1.el7.x86_64 as a component of Red Hat Enterprise Linux Workstation Supplementary (v. 7)
- java-1.7.1-ibm-jdbc-1:1.7.1.5.10-1jpp.1.el7.ppc64 as a component of Red Hat Enterprise Linux Server Supplementary (v. 7)
- java-1.7.1-ibm-jdbc-1:1.7.1.5.10-1jpp.1.el7.ppc64le as a component of Red Hat Enterprise Linux Server Supplementary (v. 7)
- java-1.7.1-ibm-jdbc-1:1.7.1.5.10-1jpp.1.el7.s390x as a component of Red Hat Enterprise Linux Server Supplementary (v. 7)
- java-1.7.1-ibm-jdbc-1:1.7.1.5.10-1jpp.1.el7.x86_64 as a component of Red Hat Enterprise Linux Client Supplementary (v. 7)
- java-1.7.1-ibm-jdbc-1:1.7.1.5.10-1jpp.1.el7.x86_64 as a component of Red Hat Enterprise Linux Server Supplementary (v. 7)
- +11 more not shown
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 All running instances of IBM Java must be restarted for this update to take effect.
🔗 References (8)
- selfhttps://access.redhat.com/errata/RHSA-2022:4957
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2014524
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2041472
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2075793
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2075836
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2075849
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2022/rhsa-2022_4957.json