Bug 2221645 (CVE-2023-22045)

Summary: CVE-2023-22045 OpenJDK: array indexing integer overflow issue (8304468)
Product: [Other] Security Response Reporter: Mauro Matteo Cascella <mcascell>
Component: vulnerabilityAssignee: Nobody <nobody>
Status: CLOSED ERRATA QA Contact:
Severity: low Docs Contact:
Priority: low    
Version: unspecifiedCC: ahughes, caswilli, chazlett, dbhole, dffrench, dfitzmau, fjansen, gmccullo, gzaronik, jdowland, jmartine, jvanek, kaycoth, neugens, ngough, pjindal, rgodfrey, security-response-team, sraghupu
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2023-08-07 14:10:55 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2221108, 2221109, 2221110, 2221111, 2221112, 2221113, 2221114, 2221115, 2221116, 2221118, 2221119, 2221120, 2221121, 2221122, 2221123, 2221124, 2221125, 2221126, 2221127, 2221128, 2221129, 2221130, 2221131, 2221132, 2221133, 2222049, 2222050, 2224350    
Bug Blocks: 2221090    

Description Mauro Matteo Cascella 2023-07-10 13:32:08 UTC
A flaw was found in the way the Hotspot component of OpenJDK handled array accesses in case of overflow in the index computation. This flaw could lead to an access at an invalid array position, leading to an out-of-bounds read vulnerability.

Comment 4 errata-xmlrpc 2023-07-19 17:14:39 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.6 Extended Update Support

Via RHSA-2023:4170 https://access.redhat.com/errata/RHSA-2023:4170

Comment 5 errata-xmlrpc 2023-07-19 17:17:51 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.4 Telecommunications Update Service

Via RHSA-2023:4171 https://access.redhat.com/errata/RHSA-2023:4171

Comment 6 errata-xmlrpc 2023-07-19 17:20:52 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions

Via RHSA-2023:4167 https://access.redhat.com/errata/RHSA-2023:4167

Comment 7 errata-xmlrpc 2023-07-19 17:21:01 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.2 Advanced Update Support
  Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.2 Telecommunications Update Service

Via RHSA-2023:4168 https://access.redhat.com/errata/RHSA-2023:4168

Comment 8 errata-xmlrpc 2023-07-19 17:21:38 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions

Via RHSA-2023:4165 https://access.redhat.com/errata/RHSA-2023:4165

Comment 9 errata-xmlrpc 2023-07-19 17:21:54 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.2 Advanced Update Support
  Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.2 Telecommunications Update Service

Via RHSA-2023:4162 https://access.redhat.com/errata/RHSA-2023:4162

Comment 10 errata-xmlrpc 2023-07-19 17:23:26 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.6 Extended Update Support

Via RHSA-2023:4164 https://access.redhat.com/errata/RHSA-2023:4164

Comment 11 errata-xmlrpc 2023-07-19 17:23:31 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.6 Extended Update Support

Via RHSA-2023:4173 https://access.redhat.com/errata/RHSA-2023:4173

Comment 12 errata-xmlrpc 2023-07-19 17:23:51 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.0 Extended Update Support

Via RHSA-2023:4157 https://access.redhat.com/errata/RHSA-2023:4157

Comment 13 errata-xmlrpc 2023-07-19 17:24:00 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.0 Extended Update Support

Via RHSA-2023:4169 https://access.redhat.com/errata/RHSA-2023:4169

Comment 14 errata-xmlrpc 2023-07-19 17:24:02 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.4 Telecommunications Update Service

Via RHSA-2023:4172 https://access.redhat.com/errata/RHSA-2023:4172

Comment 15 errata-xmlrpc 2023-07-19 17:24:21 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.4 Telecommunications Update Service

Via RHSA-2023:4163 https://access.redhat.com/errata/RHSA-2023:4163

Comment 16 errata-xmlrpc 2023-07-19 17:33:56 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.0 Extended Update Support

Via RHSA-2023:4174 https://access.redhat.com/errata/RHSA-2023:4174

Comment 17 errata-xmlrpc 2023-07-20 12:11:34 UTC
This issue has been addressed in the following products:

  Red Hat Build of OpenJDK 8u382

Via RHSA-2023:4209 https://access.redhat.com/errata/RHSA-2023:4209

Comment 18 errata-xmlrpc 2023-07-20 12:11:39 UTC
This issue has been addressed in the following products:

  Red Hat Build of OpenJDK 8u382

Via RHSA-2023:4212 https://access.redhat.com/errata/RHSA-2023:4212

Comment 19 errata-xmlrpc 2023-07-20 12:11:46 UTC
This issue has been addressed in the following products:

  Red Hat Build of OpenJDK 11.0.20

Via RHSA-2023:4161 https://access.redhat.com/errata/RHSA-2023:4161

Comment 20 errata-xmlrpc 2023-07-20 12:11:51 UTC
This issue has been addressed in the following products:

  Red Hat Build of OpenJDK 11.0.20

Via RHSA-2023:4208 https://access.redhat.com/errata/RHSA-2023:4208

Comment 21 errata-xmlrpc 2023-07-20 12:12:08 UTC
This issue has been addressed in the following products:

  Red Hat Build of OpenJDK 17.0.8

Via RHSA-2023:4210 https://access.redhat.com/errata/RHSA-2023:4210

Comment 22 errata-xmlrpc 2023-07-20 12:12:14 UTC
This issue has been addressed in the following products:

  Red Hat Build of OpenJDK 17.0.8

Via RHSA-2023:4211 https://access.redhat.com/errata/RHSA-2023:4211

Comment 23 errata-xmlrpc 2023-07-20 12:13:54 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2023:4177 https://access.redhat.com/errata/RHSA-2023:4177

Comment 24 errata-xmlrpc 2023-07-20 12:13:59 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2023:4158 https://access.redhat.com/errata/RHSA-2023:4158

Comment 25 errata-xmlrpc 2023-07-20 12:17:26 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2023:4176 https://access.redhat.com/errata/RHSA-2023:4176

Comment 26 errata-xmlrpc 2023-07-20 12:17:43 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2023:4159 https://access.redhat.com/errata/RHSA-2023:4159

Comment 27 errata-xmlrpc 2023-07-20 12:17:51 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2023:4175 https://access.redhat.com/errata/RHSA-2023:4175

Comment 28 errata-xmlrpc 2023-07-20 13:04:30 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2023:4178 https://access.redhat.com/errata/RHSA-2023:4178

Comment 29 errata-xmlrpc 2023-07-21 13:57:53 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7

Via RHSA-2023:4166 https://access.redhat.com/errata/RHSA-2023:4166

Comment 30 errata-xmlrpc 2023-07-21 14:01:13 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7

Via RHSA-2023:4233 https://access.redhat.com/errata/RHSA-2023:4233

Comment 31 Product Security DevOps Team 2023-08-07 14:10:52 UTC
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):

https://access.redhat.com/security/cve/cve-2023-22045