RHSA-2022:1445: Important: java-17-openjdk security and bug fix update
The java-17-openjdk packages provide the OpenJDK 17 Java Runtime Environment and the OpenJDK 17 Java Software Development Kit.Security Fix(es): OpenJDK: Improper ECDSA signature verification (Libraries, 8277233) (CVE-2022-21449) OpenJDK: Defective secure validation in Apache Santuario (Libraries, 8278008) (CVE-2022-21476) OpenJDK: Unbounded memory allocation when compiling crafted XPath expressions (JAXP, 8270504) (CVE-2022-21426) OpenJDK: Improper object-to-string conversion in AnnotationInvocationHandler (Libraries, 8277672) (CVE-2022-21434) OpenJDK: Missing check for negative ObjectIdentifier (Libraries, 8275151) (CVE-2022-21443) OpenJDK: URI parsing inconsistencies (JNDI, 8278972) (CVE-2022-21496) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Bug Fix(es): Enable the import of plain keys into the NSS Software Token while in FIPS mode [rhel-8, openjdk-17] (BZ#2018189) Enable AlgorithmParameters and AlgorithmParameterGenerator services in FIPS mode [rhel-8, openjdk-17] (BZ#2055396)
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-17.0.3.0.6-2.el8_5 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-debuginfo-17.0.3.0.6-2.el8_5 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-debugsource-17.0.3.0.6-2.el8_5 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-demo-17.0.3.0.6-2.el8_5 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-devel-17.0.3.0.6-2.el8_5 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-devel-debuginfo-17.0.3.0.6-2.el8_5 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-headless-17.0.3.0.6-2.el8_5 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-headless-debuginfo-17.0.3.0.6-2.el8_5 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-javadoc-17.0.3.0.6-2.el8_5 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-javadoc-zip-17.0.3.0.6-2.el8_5 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-jmods-17.0.3.0.6-2.el8_5 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-src-17.0.3.0.6-2.el8_5 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-static-libs-17.0.3.0.6-2.el8_5 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-17.0.3.0.6-2.el8_5.aa - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-debuginfo-17.0.3.0.6-2.el8_5.aa - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-debugsource-17.0.3.0.6-2.el8_5.aa - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-demo-17.0.3.0.6-2.el8_5.aa - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-devel-17.0.3.0.6-2.el8_5.aa - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-devel-debuginfo-17.0.3.0.6-2.el8_5.aa - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-headless-17.0.3.0.6-2.el8_5.aa - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-headless-debuginfo-17.0.3.0.6-2.el8_5.aa - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-javadoc-17.0.3.0.6-2.el8_5.aa - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-javadoc-zip-17.0.3.0.6-2.el8_5.aa - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-jmods-17.0.3.0.6-2.el8_5.aa - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-src-17.0.3.0.6-2.el8_5.aa - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-static-libs-17.0.3.0.6-2.el8_5.aa - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-demo-fastdebug-17.0.3.0.6-2.el8_5 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-demo-slowdebug-17.0.3.0.6-2.el8_5 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-devel-fastdebug-17.0.3.0.6-2.el8_5 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-devel-fastdebug-debuginfo-17.0.3.0.6-2.el8_5 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-devel-slowdebug-17.0.3.0.6-2.el8_5 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-devel-slowdebug-debuginfo-17.0.3.0.6-2.el8_5 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-fastdebug-17.0.3.0.6-2.el8_5 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-fastdebug-debuginfo-17.0.3.0.6-2.el8_5 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-headless-fastdebug-17.0.3.0.6-2.el8_5 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-headless-fastdebug-debuginfo-17.0.3.0.6-2.el8_5 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-headless-slowdebug-17.0.3.0.6-2.el8_5 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-headless-slowdebug-debuginfo-17.0.3.0.6-2.el8_5 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-jmods-fastdebug-17.0.3.0.6-2.el8_5 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-jmods-slowdebug-17.0.3.0.6-2.el8_5 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-slowdebug-17.0.3.0.6-2.el8_5 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-slowdebug-debuginfo-17.0.3.0.6-2.el8_5 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-src-fastdebug-17.0.3.0.6-2.el8_5 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-src-slowdebug-17.0.3.0.6-2.el8_5 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-static-libs-fastdebug-17.0.3.0.6-2.el8_5 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-static-libs-slowdebug-17.0.3.0.6-2.el8_5 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-demo-fastdebug-17.0.3.0.6-2.el8_5.aa - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-demo-slowdebug-17.0.3.0.6-2.el8_5.aa - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-devel-fastdebug-17.0.3.0.6-2.el8_5.aa - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-devel-fastdebug-debuginfo-17.0.3.0.6-2.el8_5.aa - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-devel-slowdebug-17.0.3.0.6-2.el8_5.aa - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-devel-slowdebug-debuginfo-17.0.3.0.6-2.el8_5.aa - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-fastdebug-17.0.3.0.6-2.el8_5.aa - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-fastdebug-debuginfo-17.0.3.0.6-2.el8_5.aa - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-headless-fastdebug-17.0.3.0.6-2.el8_5.aa - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-headless-fastdebug-debuginfo-17.0.3.0.6-2.el8_5.aa - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-headless-slowdebug-17.0.3.0.6-2.el8_5.aa - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-headless-slowdebug-debuginfo-17.0.3.0.6-2.el8_5.aa - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-jmods-fastdebug-17.0.3.0.6-2.el8_5.aa - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-jmods-slowdebug-17.0.3.0.6-2.el8_5.aa - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-slowdebug-17.0.3.0.6-2.el8_5.aa - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-slowdebug-debuginfo-17.0.3.0.6-2.el8_5.aa - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-src-fastdebug-17.0.3.0.6-2.el8_5.aa - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-src-slowdebug-17.0.3.0.6-2.el8_5.aa - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-static-libs-fastdebug-17.0.3.0.6-2.el8_5.aa - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-static-libs-slowdebug-17.0.3.0.6-2.el8_5.aa - Upgrade
Upgrade
java-17-openjdkto a version that resolves this vulnerability.Patch BZ#2055396 - Configuration
Enable the AlgorithmParameters and AlgorithmParameterGenerator services in FIPS mode (rhel-8, openjdk-17) to address BZ#2055396.
FIPS mode AlgorithmParameters and AlgorithmParameterGenerator services = Enabled - Operational
Restart all running instances of OpenJDK Java so the update takes effect.
Event History
Frequently Asked Questions
What is the severity of RHSA-2022:1445?
The severity of RHSA-2022:1445 is classified as important due to the risks associated with improper ECDSA signature verification.
How do I fix RHSA-2022:1445?
To fix RHSA-2022:1445, update the affected java-17-openjdk packages to version 17-openjdk-17.0.3.0.6-2.el8_5 or later.
What vulnerabilities are addressed in RHSA-2022:1445?
RHSA-2022:1445 addresses vulnerabilities related to improper ECDSA signature verification (CVE-2022-21449) and defective secure validation.
Which packages are affected by RHSA-2022:1445?
The affected packages include various versions of java-17-openjdk such as 17-openjdk-17.0.3.0.6-2.el8_5 and its associated sub-packages.
Is there a known exploit for RHSA-2022:1445?
Currently, there are no known exploits in the wild for the vulnerabilities addressed by RHSA-2022:1445.