RHSA-2022:5696-01 -- Redhat java-1.8.0-openjdkID: oval:org.secpod.oval:def:507081 | Date: (C)2022-10-21 (M)2024-02-19 |
Class: PATCH | Family: unix |
The java-1.8.0-openjdk packages provide the OpenJDK 8 Java Runtime Environment and the OpenJDK 8 Java Software Development Kit. The following packages have been upgraded to a later upstream version: java-1.8.0-openjdk . Security Fix: * OpenJDK: integer truncation issue in Xalan-J * OpenJDK: class compilation issue * OpenJDK: improper restriction of MethodHandle.invokeBasic For more details about the security issue, including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page listed in the References section. Bug Fix: * rh1991003 patch breaks sun.security.pkcs11.wrapper.PKCS11.getInstance [rhel-8, openjdk-8] * Revert to disabling system security properties and FIPS mode support together [rhel-8, openjdk-8] * SecretKey generate/import operations don"t add the CKA_SIGN attribute in FIPS mode [rhel-8, openjdk-8]
Platform: |
Red Hat Enterprise Linux 8 |
Product: |
java-1.8.0-openjdk |