First published: Tue Jan 18 2022(Updated: )
A flaw was found in the way the Hotspot component of OpenJDK processed classes with _fields that needed to be written to in Rewriter::scan_method(). A specially-crafted Java class file could use this flaw to crash Java virtual machine.
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/java | <11-openjdk-1:11.0.14.0.9-1.el7_9 | 11-openjdk-1:11.0.14.0.9-1.el7_9 |
redhat/java | <17-openjdk-1:17.0.2.0.8-4.el8_5 | 17-openjdk-1:17.0.2.0.8-4.el8_5 |
redhat/java | <11-openjdk-1:11.0.14.0.9-2.el8_5 | 11-openjdk-1:11.0.14.0.9-2.el8_5 |
redhat/java | <11-openjdk-1:11.0.14.0.9-1.el8_1 | 11-openjdk-1:11.0.14.0.9-1.el8_1 |
redhat/java | <11-openjdk-1:11.0.14.0.9-1.el8_2 | 11-openjdk-1:11.0.14.0.9-1.el8_2 |
redhat/java | <11-openjdk-1:11.0.14.0.9-2.el8_4 | 11-openjdk-1:11.0.14.0.9-2.el8_4 |
debian/openjdk-11 | 11.0.16+8-1~deb10u1 11.0.21+9-1~deb10u1 11.0.20+8-1~deb11u1 11.0.21+9-1~deb11u1 11.0.22~6ea-1 | |
debian/openjdk-17 | 17.0.7+7-1~deb11u1 17.0.9+9-1~deb11u1 17.0.9+9-1~deb12u1 17.0.9+9-2 17.0.10~6ea-1 | |
IBM InfoSphere Guardium z/OS | <=10.5 | |
IBM InfoSphere Guardium z/OS | <=10.6 | |
IBM InfoSphere Guardium z/OS | <=11.0 | |
IBM InfoSphere Guardium z/OS | <=11.1 | |
IBM InfoSphere Guardium z/OS | <=11.3 | |
IBM InfoSphere Guardium z/OS | <=11.2 | |
IBM InfoSphere Guardium z/OS | <=11.4 | |
Oracle GraalVM Enterprise Edition | =20.3.4 | |
Oracle GraalVM Enterprise Edition | =21.3.0 | |
Oracle JDK 6 | =1.7.0-update321 | |
Oracle JDK 6 | =1.8.0-update311 | |
Oracle JDK 6 | =11.0.13 | |
Oracle JDK 6 | =17.0.1 | |
Oracle Java Runtime Environment (JRE) | =1.7.0-update321 | |
Oracle Java Runtime Environment (JRE) | =1.8.0-update311 | |
Oracle Java Runtime Environment (JRE) | =11.0.13 | |
Oracle Java Runtime Environment (JRE) | =17.0.1 | |
Debian | =10.0 | |
Debian | =11.0 | |
NetApp 7-Mode Transition Tool | ||
NetApp Active IQ Unified Manager for VMware vSphere | ||
netapp active iq unified manager windows | ||
netapp cloud insights | ||
NetApp E-Series SANtricity OS Controller | >=11.0.0<=11.70.1 | |
netapp e-series santricity storage manager | ||
netapp e-series santricity Web services Web services proxy | ||
netapp hci management node | ||
NetApp OnCommand Insight | ||
NetApp OnCommand Workflow Automation | ||
netapp santricity unified manager | ||
netapp snapmanager Oracle | ||
netapp snapmanager sap | ||
netapp solidfire | ||
OpenJDK 17 | >=11<=11.0.13 | |
OpenJDK 17 | >=13<=13.0.9 | |
OpenJDK 17 | >=15<=15.0.5 | |
OpenJDK 17 | =17 | |
OpenJDK 17 | =17.0.1 | |
netapp cloud insights acquisition unit | ||
netapp cloud secure agent | ||
NetApp SANtricity Storage Plugin for vCenter | ||
Fedora | =34 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
CVE-2022-21291 is an unspecified vulnerability in Java SE related to the VM component that could allow an unauthenticated attacker to exploit it.
Oracle Java SE versions 7u321, 8u311, 11.0.13, and 17.0.1 are affected by CVE-2022-21291.
Oracle GraalVM Enterprise Edition versions 20.3.4 and 21.3.0 are affected by CVE-2022-21291.
CVE-2022-21291 has a severity rating of 5.3 (medium).
You can find more information about CVE-2022-21291 at the following references: [Oracle Security Alerts](https://www.oracle.com/security-alerts/cpujan2022.html#AppendixJAVA) and [Red Hat Security Advisory](https://access.redhat.com/errata/RHSA-2022:0161) and [Red Hat Security Advisory](https://access.redhat.com/errata/RHSA-2022:0233).