Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Containers
  • Support Cases
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Containers
  • Support Cases
  • Products & Services

    Products

    Support

    • Production Support
    • Development Support
    • Product Life Cycles

    Services

    • Consulting
    • Technical Account Management
    • Training & Certifications

    Documentation

    • Red Hat Enterprise Linux
    • Red Hat JBoss Enterprise Application Platform
    • Red Hat OpenStack Platform
    • Red Hat OpenShift Container Platform
    All Documentation

    Ecosystem Catalog

    • Red Hat Partner Ecosystem
    • Partner Resources
  • Tools

    Tools

    • Troubleshoot a product issue
    • Packages
    • Errata

    Customer Portal Labs

    • Configuration
    • Deployment
    • Security
    • Troubleshoot
    All labs

    Red Hat Insights

    Increase visibility into IT operations to detect and resolve technical issues before they impact your business.

    Learn More
    Go to Insights
  • Security

    Red Hat Product Security Center

    Engage with our Red Hat Product Security team, access security updates, and ensure your environments are not exposed to any known security vulnerabilities.

    Product Security Center

    Security Updates

    • Security Advisories
    • Red Hat CVE Database
    • Security Labs

    Keep your systems secure with Red Hat's specialized responses to security vulnerabilities.

    View Responses

    Resources

    • Security Blog
    • Security Measurement
    • Severity Ratings
    • Backporting Policies
    • Product Signing (GPG) Keys
  • Community

    Customer Portal Community

    • Discussions
    • Private Groups
    Community Activity

    Customer Events

    • Red Hat Convergence
    • Red Hat Summit

    Stories

    • Red Hat Subscription Value
    • You Asked. We Acted.
    • Open Source Communities
Or troubleshoot an issue.

Select Your Language

  • English
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Virtualization
  • Red Hat Identity Management
  • Red Hat Directory Server
  • Red Hat Certificate System
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Update Infrastructure
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat CloudForms
  • Red Hat OpenStack Platform
  • Red Hat OpenShift Container Platform
  • Red Hat OpenShift Data Science
  • Red Hat OpenShift Online
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat Single Sign On
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Thorntail
  • Red Hat build of Eclipse Vert.x
  • Red Hat build of OpenJDK
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Integration
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
  • Red Hat JBoss Data Virtualization
  • Red Hat Process Automation
  • Red Hat Process Automation Manager
  • Red Hat Decision Manager
All Products
Red Hat Product Errata RHSA-2022:7003 - Security Advisory
Issued:
2022-10-19
Updated:
2022-10-19

RHSA-2022:7003 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Moderate: java-1.8.0-openjdk security update

Type/Severity

Security Advisory: Moderate

Red Hat Insights patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for java-1.8.0-openjdk is now available for Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions.

Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

The java-1.8.0-openjdk packages provide the OpenJDK 8 Java Runtime Environment and the OpenJDK 8 Java Software Development Kit.

Security Fix(es):

  • OpenJDK: excessive memory allocation in X.509 certificate parsing (Security, 8286533) (CVE-2022-21626)
  • OpenJDK: HttpServer no connection count limit (Lightweight HTTP Server, 8286918) (CVE-2022-21628)
  • OpenJDK: improper handling of long NTLM client hostnames (Security, 8286526) (CVE-2022-21619)
  • OpenJDK: insufficient randomization of JNDI DNS port numbers (JNDI, 8286910) (CVE-2022-21624)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

All running instances of OpenJDK Java must be restarted for this update to take effect.

Affected Products

  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.1 ppc64le
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.1 x86_64

Fixes

  • BZ - 2133745 - CVE-2022-21619 OpenJDK: improper handling of long NTLM client hostnames (Security, 8286526)
  • BZ - 2133753 - CVE-2022-21626 OpenJDK: excessive memory allocation in X.509 certificate parsing (Security, 8286533)
  • BZ - 2133765 - CVE-2022-21624 OpenJDK: insufficient randomization of JNDI DNS port numbers (JNDI, 8286910)
  • BZ - 2133769 - CVE-2022-21628 OpenJDK: HttpServer no connection count limit (Lightweight HTTP Server, 8286918)

CVEs

  • CVE-2022-21619
  • CVE-2022-21624
  • CVE-2022-21626
  • CVE-2022-21628

References

  • https://access.redhat.com/security/updates/classification/#moderate
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.1

SRPM
java-1.8.0-openjdk-1.8.0.352.b08-2.el8_1.src.rpm SHA-256: 727040d6fb214c1bbf105ff58da0ea4823bce81f4f328150c2f1d9648e602cf5
ppc64le
java-1.8.0-openjdk-1.8.0.352.b08-2.el8_1.ppc64le.rpm SHA-256: af7dc0938a5bf0cb4e6de63bff5ae93194002ddba166fdf44457c4396333c70c
java-1.8.0-openjdk-accessibility-1.8.0.352.b08-2.el8_1.ppc64le.rpm SHA-256: 1e7c85d215e7387181f02f75ba18bce8384c2d2ffe21668df06e82fbe506e2f5
java-1.8.0-openjdk-debuginfo-1.8.0.352.b08-2.el8_1.ppc64le.rpm SHA-256: a54010b75e6f3b8a7fd6cf48e030c3af69f4fbabca9963e749702a918772e523
java-1.8.0-openjdk-debugsource-1.8.0.352.b08-2.el8_1.ppc64le.rpm SHA-256: 9bda01438652d03d32c6e7468ace04650383a52450732cbee97e567a6ef57b9c
java-1.8.0-openjdk-demo-1.8.0.352.b08-2.el8_1.ppc64le.rpm SHA-256: bf92bc328c462d540277d3d668be98c8ecd358c16c6dca89ab8e1092614777a2
java-1.8.0-openjdk-demo-debuginfo-1.8.0.352.b08-2.el8_1.ppc64le.rpm SHA-256: 32987946eb67fe0d3c478a8b5434955c59d9d2f267e6bb41f6827c12e55c09b5
java-1.8.0-openjdk-demo-slowdebug-debuginfo-1.8.0.352.b08-2.el8_1.ppc64le.rpm SHA-256: e99ad0eb272858ac6ae9ca2eb4eab191a0ef4cf72613ea0a7849baff3ca37494
java-1.8.0-openjdk-devel-1.8.0.352.b08-2.el8_1.ppc64le.rpm SHA-256: 24c59673d00465659def5f57f2b9681e4f336ded3b5bd6b4629295c2b30b0ed4
java-1.8.0-openjdk-devel-debuginfo-1.8.0.352.b08-2.el8_1.ppc64le.rpm SHA-256: 2462fed0007560e6021073aeca8cf541057fee8d46f1ef25c8789e1a25029b00
java-1.8.0-openjdk-devel-slowdebug-debuginfo-1.8.0.352.b08-2.el8_1.ppc64le.rpm SHA-256: a163a664a21852537065d361b681783c524520e49980f1f28f3641ddf92eba71
java-1.8.0-openjdk-headless-1.8.0.352.b08-2.el8_1.ppc64le.rpm SHA-256: daf4e3da8db3e9e5e89022558b8f51ac2fd6655c27d1462f2006c8d99f98ff49
java-1.8.0-openjdk-headless-debuginfo-1.8.0.352.b08-2.el8_1.ppc64le.rpm SHA-256: 4a9ed79ffd721a0c103856431a333ebcf12420d10d0eb70387bacf45b06a3535
java-1.8.0-openjdk-headless-slowdebug-debuginfo-1.8.0.352.b08-2.el8_1.ppc64le.rpm SHA-256: 75033b77fe829cfbe638dc3d05e5d5d0a9afa11d32de605d01726ea5b4a538be
java-1.8.0-openjdk-javadoc-1.8.0.352.b08-2.el8_1.noarch.rpm SHA-256: af8f311589a851e893e11d9a9be6dfe8aacb459b69b66a024ea6f776b7e8d266
java-1.8.0-openjdk-javadoc-zip-1.8.0.352.b08-2.el8_1.noarch.rpm SHA-256: 3e86f662c592f571669b9530450b597bf64a3a2c10bc6cd204fed51cb9cea8fe
java-1.8.0-openjdk-slowdebug-debuginfo-1.8.0.352.b08-2.el8_1.ppc64le.rpm SHA-256: 0001d8f159a9ca991dc125a1bb3eeb9c9c335e03a99d7366f57f8f7dc52f254d
java-1.8.0-openjdk-src-1.8.0.352.b08-2.el8_1.ppc64le.rpm SHA-256: 272fb2b02777744e8114ead093270ae321edf2f8987e6d72a92f71e5244afa44

Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.1

SRPM
java-1.8.0-openjdk-1.8.0.352.b08-2.el8_1.src.rpm SHA-256: 727040d6fb214c1bbf105ff58da0ea4823bce81f4f328150c2f1d9648e602cf5
x86_64
java-1.8.0-openjdk-1.8.0.352.b08-2.el8_1.x86_64.rpm SHA-256: 989f0e8eec61b95436db167626e38a2b95a50e5e7f8bb3173e03802b53d3cc6f
java-1.8.0-openjdk-accessibility-1.8.0.352.b08-2.el8_1.x86_64.rpm SHA-256: c683d6476d87fcc5662946db1d6eca96bd8508b838d177438114e8c20502e201
java-1.8.0-openjdk-debuginfo-1.8.0.352.b08-2.el8_1.x86_64.rpm SHA-256: c44a91e1e7dfab747cf35218cab93689c2ca805192e55b2bfd995050e462f7a9
java-1.8.0-openjdk-debugsource-1.8.0.352.b08-2.el8_1.x86_64.rpm SHA-256: 792a1c9ce5b4b07e17c437f25684fa72fd9d2e09cfe2ed91d98015db0885870b
java-1.8.0-openjdk-demo-1.8.0.352.b08-2.el8_1.x86_64.rpm SHA-256: 1dab79d1bc2a3b5b398be99cf45d19a949de87129db99300f047349246498169
java-1.8.0-openjdk-demo-debuginfo-1.8.0.352.b08-2.el8_1.x86_64.rpm SHA-256: 7c71b2c612e19244b7c57dfc4dba8601192f218a4452d48299abf77b982b49a0
java-1.8.0-openjdk-demo-slowdebug-debuginfo-1.8.0.352.b08-2.el8_1.x86_64.rpm SHA-256: c5998e1435a52dcaf36d04eece838303232adb90839d4685be1188e54117a021
java-1.8.0-openjdk-devel-1.8.0.352.b08-2.el8_1.x86_64.rpm SHA-256: 195b699c0338e3fef711cf83dbd11fcb01e0c32d77acac80df15f316749e725a
java-1.8.0-openjdk-devel-debuginfo-1.8.0.352.b08-2.el8_1.x86_64.rpm SHA-256: 46e8e6af76d6ad1509b1e17fb8f5e1c306ddfa4cfe80d1745d8d46e9336dd9e0
java-1.8.0-openjdk-devel-slowdebug-debuginfo-1.8.0.352.b08-2.el8_1.x86_64.rpm SHA-256: 953bfdc67fe83016023102820fa9912e55abc6c7ac3ca3f97e24e6953dd9c86c
java-1.8.0-openjdk-headless-1.8.0.352.b08-2.el8_1.x86_64.rpm SHA-256: 00183abc0bc7e2c3ce8bcd33929045df5f02e63843bcea644b4bd4a4cc2552b7
java-1.8.0-openjdk-headless-debuginfo-1.8.0.352.b08-2.el8_1.x86_64.rpm SHA-256: 50e3cf786b5b2f69bafdc74e4b709f27809baaa0a8d3cd4f12cee9d00043b0b1
java-1.8.0-openjdk-headless-slowdebug-debuginfo-1.8.0.352.b08-2.el8_1.x86_64.rpm SHA-256: db79ab74909e21d99057366fb9f49e37fa40357fe622493d4746a1d4402998e8
java-1.8.0-openjdk-javadoc-1.8.0.352.b08-2.el8_1.noarch.rpm SHA-256: af8f311589a851e893e11d9a9be6dfe8aacb459b69b66a024ea6f776b7e8d266
java-1.8.0-openjdk-javadoc-zip-1.8.0.352.b08-2.el8_1.noarch.rpm SHA-256: 3e86f662c592f571669b9530450b597bf64a3a2c10bc6cd204fed51cb9cea8fe
java-1.8.0-openjdk-slowdebug-debuginfo-1.8.0.352.b08-2.el8_1.x86_64.rpm SHA-256: fda73975ca9c9fd6da82375e997168754c806e91a68077430f2aca5cb0a746d4
java-1.8.0-openjdk-src-1.8.0.352.b08-2.el8_1.x86_64.rpm SHA-256: 86038e4288e292bd0afb8df308e31dcb7f95c035be36ac1103c84b1d7459433f

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

About

  • Red Hat Subscription Value
  • About Red Hat
  • Red Hat Jobs
Copyright © 2023 Red Hat, Inc.
  • Privacy Statement
  • Customer Portal Terms of Use
  • All Policies and Guidelines
Red Hat Summit
Twitter