First published: Mon Jul 10 2023(Updated: )
A flaw was found in the way the Hotspot component of OpenJDK handled array accesses using the binary % operator. This flaw could lead to an access at an invalid array position, leading to an out-of-bounds read vulnerability.
Credit: secalert_us@oracle.com secalert_us@oracle.com secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle GraalVM Enterprise Edition | =21.3.6 | |
Oracle GraalVM Enterprise Edition | =22.3.2 | |
Oracle GraalVM for JDK | =17.0.7 | |
Oracle GraalVM for JDK | =20.0.1 | |
Oracle JDK 6 | =1.8.0-update371 | |
Oracle JDK 6 | =17.0.7 | |
Oracle JDK 6 | =20.0.1 | |
Oracle Java Runtime Environment (JRE) | =1.8.0-update371 | |
Oracle Java Runtime Environment (JRE) | =17.0.7 | |
Oracle Java Runtime Environment (JRE) | =20.0.1 | |
Debian GNU/Linux | =11.0 | |
Debian GNU/Linux | =12.0 | |
debian/openjdk-17 | 17.0.12+7-2~deb11u1 17.0.14+7-1~deb11u1 17.0.13+11-2~deb12u1 17.0.14+7-1~deb12u1 17.0.14+7-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-22044 is a vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition, Oracle GraalVM for JDK product.
The affected versions are Oracle Java SE: 8u371-perf, 17.0.7, 20.0.1; Oracle GraalVM Enterprise Edition: 21.3.6, 22.3.2; Oracle GraalVM for JDK: 17.0.7, 20.0.1.
CVE-2023-22044 has a severity rating of 3.7 (low).
To fix CVE-2023-22044 in Oracle Java SE, update to the latest version available from Oracle's security alerts page.
To fix CVE-2023-22044 in Oracle GraalVM, update to the latest version available from Oracle's security alerts page.
To fix CVE-2023-22044 in Oracle GraalVM for JDK, update to the latest version available from Oracle's security alerts page.
To fix CVE-2023-22044 in Ubuntu openjdk-17, update to version 17.0.8+7-1~18.04 (for Bionic), 17.0.8+7-1~20.04.2 (for Focal), 17.0.8+7-1~22.04 (for Jammy), or 17.0.8+7-1~23.04 (for Lunar).
To fix CVE-2023-22044 in Ubuntu openjdk-20, update to version 20.0.2+9+ (for Lunar).
To fix CVE-2023-22044 in Oracle GraalVM 21.3.6, update to the latest version available from Oracle's security alerts page.
To fix CVE-2023-22044 in Oracle GraalVM 22.3.2, update to the latest version available from Oracle's security alerts page.
To fix CVE-2023-22044 in Oracle GraalVM for JDK 17.0.7, update to the latest version available from Oracle's security alerts page.
To fix CVE-2023-22044 in Oracle GraalVM for JDK 20.0.1, update to the latest version available from Oracle's security alerts page.