CVE-2022-21365: Integer Overflow
An integer overflow flaw was found in the fix applied to the BMPImageReader class implementation in the ImageIO component of OpenJDK to address the CVE-2021-35586 (bug 2015308) issue. This issue could allow a specially-crafted BMP image to bypass previously applied protection and cause a Java application to allocate an excessive amount of memory when opened.
Other sources
An unspecified vulnerability in Java SE related to the ImageIO component could allow an unauthenticated attacker to cause a denial of service resulting in a low availability impact using unknown attack vectors.
— IBM
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: ImageIO). Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13, 17.0.1; Oracle GraalVM Enterprise Edition: 20.3.4 and 21.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM Enterprise Edition. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2022-21365?
CVE-2022-21365 has been classified as a high severity vulnerability due to the potential for exploitation affecting the BMPImageReader class in OpenJDK.
How do I fix CVE-2022-21365?
To fix CVE-2022-21365, upgrade your OpenJDK installation to a version that includes the patch addressing this vulnerability.
What versions of OpenJDK are affected by CVE-2022-21365?
CVE-2022-21365 affects multiple versions of OpenJDK including 11, 8, and 7, particularly those referenced in the vulnerability report.
What type of flaw is described in CVE-2022-21365?
CVE-2022-21365 describes an integer overflow flaw found in the BMPImageReader class implementation.
Who should be concerned about CVE-2022-21365?
Organizations using vulnerable versions of OpenJDK, especially those relying on BMP image processing, should be concerned about the implications of CVE-2022-21365.