RHSA-2023:0192: Moderate: java-17-openjdk security and bug fix update
The java-17-openjdk packages provide the OpenJDK 17 Java Runtime Environment and the OpenJDK 17 Java Software Development Kit.Security Fix(es): OpenJDK: handshake DoS attack against DTLS connections (JSSE, 8287411) (CVE-2023-21835) OpenJDK: soundbank URL remote loading (Sound, 8293742) (CVE-2023-21843) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Bug Fix(es): In FIPS mode, the use of a SQLite database provided by NSS was assumed, which was opened in read-only mode and with no PIN expected. This prevented the use of other databases or setting a PIN on the NSS database. This update allows more control over database use using two new properties - fips.nssdb.path and fips.nssdb.pin - which can be configured permanently in the java.security file or temporarily via command-line arguments to the Java virtual machine (RHBZ#2147473) Prepare for the next quarterly OpenJDK upstream release (2023-01, 17.0.6) [rhel-8] (BZ#2153010)
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-17.0.6.0.10-3.el8_7 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-debuginfo-17.0.6.0.10-3.el8_7 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-debugsource-17.0.6.0.10-3.el8_7 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-demo-17.0.6.0.10-3.el8_7 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-devel-17.0.6.0.10-3.el8_7 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-devel-debuginfo-17.0.6.0.10-3.el8_7 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-headless-17.0.6.0.10-3.el8_7 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-headless-debuginfo-17.0.6.0.10-3.el8_7 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-javadoc-17.0.6.0.10-3.el8_7 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-javadoc-zip-17.0.6.0.10-3.el8_7 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-jmods-17.0.6.0.10-3.el8_7 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-src-17.0.6.0.10-3.el8_7 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-static-libs-17.0.6.0.10-3.el8_7 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-17.0.6.0.10-3.el8_7.aa - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-debuginfo-17.0.6.0.10-3.el8_7.aa - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-debugsource-17.0.6.0.10-3.el8_7.aa - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-demo-17.0.6.0.10-3.el8_7.aa - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-devel-17.0.6.0.10-3.el8_7.aa - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-devel-debuginfo-17.0.6.0.10-3.el8_7.aa - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-headless-17.0.6.0.10-3.el8_7.aa - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-headless-debuginfo-17.0.6.0.10-3.el8_7.aa - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-javadoc-17.0.6.0.10-3.el8_7.aa - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-javadoc-zip-17.0.6.0.10-3.el8_7.aa - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-jmods-17.0.6.0.10-3.el8_7.aa - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-src-17.0.6.0.10-3.el8_7.aa - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-static-libs-17.0.6.0.10-3.el8_7.aa - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-demo-fastdebug-17.0.6.0.10-3.el8_7 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-demo-slowdebug-17.0.6.0.10-3.el8_7 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-devel-fastdebug-17.0.6.0.10-3.el8_7 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-devel-fastdebug-debuginfo-17.0.6.0.10-3.el8_7 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-devel-slowdebug-17.0.6.0.10-3.el8_7 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-devel-slowdebug-debuginfo-17.0.6.0.10-3.el8_7 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-fastdebug-17.0.6.0.10-3.el8_7 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-fastdebug-debuginfo-17.0.6.0.10-3.el8_7 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-headless-fastdebug-17.0.6.0.10-3.el8_7 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-headless-fastdebug-debuginfo-17.0.6.0.10-3.el8_7 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-headless-slowdebug-17.0.6.0.10-3.el8_7 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-headless-slowdebug-debuginfo-17.0.6.0.10-3.el8_7 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-jmods-fastdebug-17.0.6.0.10-3.el8_7 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-jmods-slowdebug-17.0.6.0.10-3.el8_7 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-slowdebug-17.0.6.0.10-3.el8_7 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-slowdebug-debuginfo-17.0.6.0.10-3.el8_7 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-src-fastdebug-17.0.6.0.10-3.el8_7 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-src-slowdebug-17.0.6.0.10-3.el8_7 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-static-libs-fastdebug-17.0.6.0.10-3.el8_7 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-static-libs-slowdebug-17.0.6.0.10-3.el8_7 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-demo-fastdebug-17.0.6.0.10-3.el8_7.aa - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-demo-slowdebug-17.0.6.0.10-3.el8_7.aa - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-devel-fastdebug-17.0.6.0.10-3.el8_7.aa - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-devel-fastdebug-debuginfo-17.0.6.0.10-3.el8_7.aa - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-devel-slowdebug-17.0.6.0.10-3.el8_7.aa - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-devel-slowdebug-debuginfo-17.0.6.0.10-3.el8_7.aa - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-fastdebug-17.0.6.0.10-3.el8_7.aa - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-fastdebug-debuginfo-17.0.6.0.10-3.el8_7.aa - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-headless-fastdebug-17.0.6.0.10-3.el8_7.aa - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-headless-fastdebug-debuginfo-17.0.6.0.10-3.el8_7.aa - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-headless-slowdebug-17.0.6.0.10-3.el8_7.aa - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-headless-slowdebug-debuginfo-17.0.6.0.10-3.el8_7.aa - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-jmods-fastdebug-17.0.6.0.10-3.el8_7.aa - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-jmods-slowdebug-17.0.6.0.10-3.el8_7.aa - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-slowdebug-17.0.6.0.10-3.el8_7.aa - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-slowdebug-debuginfo-17.0.6.0.10-3.el8_7.aa - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-src-fastdebug-17.0.6.0.10-3.el8_7.aa - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-src-slowdebug-17.0.6.0.10-3.el8_7.aa - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-static-libs-fastdebug-17.0.6.0.10-3.el8_7.aa - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 17-openjdk-static-libs-slowdebug-17.0.6.0.10-3.el8_7.aa - Upgrade
Upgrade
OpenJDK (java-17-openjdk)to a version that resolves this vulnerability.Fixed in 17.0.6Patch BZ#2153010 - Configuration
Configure fips.nssdb.path in the java.security file (or via JVM command-line arguments) to control which NSS database is used in FIPS mode, as enabled by the java-17-openjdk security update (RHBZ#2147473).
OpenJDK Java (java.security) fips.nssdb.path = (set to the desired NSS database path instead of using the NSS-provided SQLite DB in read-only mode) - Configuration
Configure fips.nssdb.pin in the java.security file (or via JVM command-line arguments) so the PIN can be supplied in FIPS mode, as enabled by the java-17-openjdk security update (RHBZ#2147473).
OpenJDK Java (java.security) fips.nssdb.pin = (set an NSS database PIN when required) - Compensating control
For the CVE-2023-21843 (Sound, 8293742) soundbank URL remote loading issue, ensure OpenJDK is updated per the advisory (java-17-openjdk to 17.0.6 / BZ#2153010) and restart all running instances of OpenJDK Java for the update to take effect.
- Operational
Restart all running instances of OpenJDK Java after applying the java-17-openjdk update so the changes take effect.
Event History
Frequently Asked Questions
What is the severity of RHSA-2023:0192?
The severity of RHSA-2023:0192 is classified as important.
How do I fix RHSA-2023:0192?
To fix RHSA-2023:0192, update the affected java-17-openjdk packages to version 17.0.6.0.10-3.el8_7.
What vulnerabilities are addressed in RHSA-2023:0192?
RHSA-2023:0192 addresses a DoS attack against DTLS connections and other security flaws related to OpenJDK.
Which OpenJDK components are affected by RHSA-2023:0192?
The affected components include java-17-openjdk packages and its derivatives like java-17-openjdk-headless, java-17-openjdk-devel, and others.
Is RHSA-2023:0192 applicable to all Linux distributions?
No, RHSA-2023:0192 specifically applies to Red Hat and its derivatives.