Bug 2015061 (CVE-2021-35564) - CVE-2021-35564 OpenJDK: Certificates with end dates too far in the future can corrupt keystore (Keytool, 8266137)
Summary: CVE-2021-35564 OpenJDK: Certificates with end dates too far in the future can...
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2021-35564
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2012332 2012333 2012334 2012335 2012336 2012337 2012338 2012339 2013841 2013842 2014299 2014300 2014301 2014302 2026908 2026909 2026910 2026911 2061507 2070466
Blocks: 2011827
TreeView+ depends on / blocked
 
Reported: 2021-10-18 10:24 UTC by Tomas Hoger
Modified: 2022-04-06 11:58 UTC (History)
8 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2021-10-20 14:08:53 UTC
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHBA-2021:3952 0 None None None 2021-10-25 01:19:50 UTC
Red Hat Product Errata RHBA-2021:3954 0 None None None 2021-10-25 01:23:02 UTC
Red Hat Product Errata RHBA-2021:3963 0 None None None 2021-10-25 12:33:36 UTC
Red Hat Product Errata RHBA-2021:3964 0 None None None 2021-10-25 12:33:23 UTC
Red Hat Product Errata RHBA-2021:3965 0 None None None 2021-10-25 12:32:22 UTC
Red Hat Product Errata RHBA-2021:3966 0 None None None 2021-10-25 12:32:44 UTC
Red Hat Product Errata RHBA-2021:3969 0 None None None 2021-10-25 12:58:40 UTC
Red Hat Product Errata RHBA-2021:3970 0 None None None 2021-10-25 12:57:17 UTC
Red Hat Product Errata RHBA-2021:3979 0 None None None 2021-10-25 17:53:14 UTC
Red Hat Product Errata RHBA-2021:3983 0 None None None 2021-10-26 01:25:00 UTC
Red Hat Product Errata RHBA-2021:3984 0 None None None 2021-10-26 01:29:59 UTC
Red Hat Product Errata RHBA-2021:3985 0 None None None 2021-10-26 01:30:52 UTC
Red Hat Product Errata RHBA-2021:3986 0 None None None 2021-10-26 01:28:24 UTC
Red Hat Product Errata RHBA-2021:3993 0 None None None 2021-10-26 10:35:36 UTC
Red Hat Product Errata RHBA-2021:3994 0 None None None 2021-10-26 11:28:58 UTC
Red Hat Product Errata RHBA-2021:3995 0 None None None 2021-10-26 11:29:17 UTC
Red Hat Product Errata RHBA-2021:4041 0 None None None 2021-11-01 10:43:12 UTC
Red Hat Product Errata RHBA-2021:4048 0 None None None 2021-11-01 18:52:00 UTC
Red Hat Product Errata RHBA-2021:4125 0 None None None 2021-11-04 11:21:17 UTC
Red Hat Product Errata RHBA-2021:4126 0 None None None 2021-11-04 11:21:46 UTC
Red Hat Product Errata RHBA-2021:4127 0 None None None 2021-11-04 12:55:58 UTC
Red Hat Product Errata RHBA-2021:4583 0 None None None 2021-11-10 13:05:58 UTC
Red Hat Product Errata RHBA-2021:4584 0 None None None 2021-11-10 08:16:48 UTC
Red Hat Product Errata RHBA-2021:4670 0 None None None 2021-11-16 03:50:31 UTC
Red Hat Product Errata RHBA-2021:4732 0 None None None 2021-11-18 12:15:17 UTC
Red Hat Product Errata RHBA-2021:4842 0 None None None 2021-11-29 12:31:41 UTC
Red Hat Product Errata RHBA-2021:5079 0 None None None 2021-12-13 08:05:45 UTC
Red Hat Product Errata RHBA-2021:5083 0 None None None 2021-12-13 09:51:27 UTC
Red Hat Product Errata RHSA-2021:3884 0 None None None 2021-10-20 13:18:27 UTC
Red Hat Product Errata RHSA-2021:3885 0 None None None 2021-10-20 13:32:09 UTC
Red Hat Product Errata RHSA-2021:3886 0 None None None 2021-10-20 13:09:03 UTC
Red Hat Product Errata RHSA-2021:3887 0 None None None 2021-10-20 13:45:04 UTC
Red Hat Product Errata RHSA-2021:3889 0 None None None 2021-10-20 14:38:04 UTC
Red Hat Product Errata RHSA-2021:3891 0 None None None 2021-10-20 13:53:31 UTC
Red Hat Product Errata RHSA-2021:3892 0 None None None 2021-10-20 15:23:04 UTC
Red Hat Product Errata RHSA-2021:3893 0 None None None 2021-10-20 13:40:00 UTC
Red Hat Product Errata RHSA-2021:3960 0 None None None 2021-10-25 11:55:44 UTC
Red Hat Product Errata RHSA-2021:3961 0 None None None 2021-10-25 11:56:05 UTC
Red Hat Product Errata RHSA-2021:3967 0 None None None 2021-10-25 12:24:36 UTC
Red Hat Product Errata RHSA-2021:3968 0 None None None 2021-10-25 12:25:12 UTC
Red Hat Product Errata RHSA-2021:4135 0 None None None 2021-11-09 20:08:50 UTC
Red Hat Product Errata RHSA-2021:4531 0 None None None 2021-11-11 18:31:37 UTC
Red Hat Product Errata RHSA-2021:4532 0 None None None 2021-11-11 18:30:57 UTC
Red Hat Product Errata RHSA-2021:5030 0 None None None 2021-12-08 16:19:53 UTC
Red Hat Product Errata RHSA-2022:0310 0 None None None 2022-01-27 14:09:45 UTC
Red Hat Product Errata RHSA-2022:0345 0 None None None 2022-02-01 15:12:22 UTC

Description Tomas Hoger 2021-10-18 10:24:48 UTC
A flaw was found in the way the Keytool component of OpenJDK handled X.509 certificates with validity period ending too far in the future, after year 9999. When such certificates were imported into a keystore, they could cause corruption of the keystore.

Comment 1 Tomas Hoger 2021-10-19 20:37:05 UTC
Public now via Oracle CPU October 2021:

https://www.oracle.com/security-alerts/cpuoct2021.html#AppendixJAVA

Fixed in Oracle Java SE 17.0.1, 11.0.13, 8u311, and 7u321.

Comment 6 errata-xmlrpc 2021-10-20 13:09:01 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.1 Extended Update Support

Via RHSA-2021:3886 https://access.redhat.com/errata/RHSA-2021:3886

Comment 7 errata-xmlrpc 2021-10-20 13:18:26 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.1 Extended Update Support

Via RHSA-2021:3884 https://access.redhat.com/errata/RHSA-2021:3884

Comment 8 errata-xmlrpc 2021-10-20 13:32:06 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.2 Extended Update Support

Via RHSA-2021:3885 https://access.redhat.com/errata/RHSA-2021:3885

Comment 9 errata-xmlrpc 2021-10-20 13:39:58 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2021:3893 https://access.redhat.com/errata/RHSA-2021:3893

Comment 10 errata-xmlrpc 2021-10-20 13:45:02 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.2 Extended Update Support

Via RHSA-2021:3887 https://access.redhat.com/errata/RHSA-2021:3887

Comment 11 errata-xmlrpc 2021-10-20 13:53:29 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2021:3891 https://access.redhat.com/errata/RHSA-2021:3891

Comment 12 Product Security DevOps Team 2021-10-20 14:08:53 UTC
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):

https://access.redhat.com/security/cve/cve-2021-35564

Comment 13 errata-xmlrpc 2021-10-20 14:38:03 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7

Via RHSA-2021:3889 https://access.redhat.com/errata/RHSA-2021:3889

Comment 14 errata-xmlrpc 2021-10-20 15:23:03 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7

Via RHSA-2021:3892 https://access.redhat.com/errata/RHSA-2021:3892

Comment 15 errata-xmlrpc 2021-10-25 11:55:43 UTC
This issue has been addressed in the following products:

  Red Hat Build of OpenJDK 8u312

Via RHSA-2021:3960 https://access.redhat.com/errata/RHSA-2021:3960

Comment 16 errata-xmlrpc 2021-10-25 11:56:04 UTC
This issue has been addressed in the following products:

  Red Hat Build of OpenJDK 8u312

Via RHSA-2021:3961 https://access.redhat.com/errata/RHSA-2021:3961

Comment 17 errata-xmlrpc 2021-10-25 12:24:35 UTC
This issue has been addressed in the following products:

  Red Hat Build of OpenJDK 11.0.13

Via RHSA-2021:3967 https://access.redhat.com/errata/RHSA-2021:3967

Comment 18 errata-xmlrpc 2021-10-25 12:25:11 UTC
This issue has been addressed in the following products:

  Red Hat Build of OpenJDK 11.0.13

Via RHSA-2021:3968 https://access.redhat.com/errata/RHSA-2021:3968

Comment 20 errata-xmlrpc 2021-11-09 20:08:48 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2021:4135 https://access.redhat.com/errata/RHSA-2021:4135

Comment 23 errata-xmlrpc 2021-11-11 18:30:55 UTC
This issue has been addressed in the following products:

  Red Hat Build of OpenJDK 17.0.1

Via RHSA-2021:4532 https://access.redhat.com/errata/RHSA-2021:4532

Comment 24 errata-xmlrpc 2021-11-11 18:31:35 UTC
This issue has been addressed in the following products:

  Red Hat Build of OpenJDK 17.0.1

Via RHSA-2021:4531 https://access.redhat.com/errata/RHSA-2021:4531

Comment 25 errata-xmlrpc 2021-12-08 16:19:52 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7 Supplementary

Via RHSA-2021:5030 https://access.redhat.com/errata/RHSA-2021:5030

Comment 26 errata-xmlrpc 2022-01-27 14:09:43 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7 Supplementary

Via RHSA-2022:0310 https://access.redhat.com/errata/RHSA-2022:0310

Comment 27 errata-xmlrpc 2022-02-01 15:12:20 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2022:0345 https://access.redhat.com/errata/RHSA-2022:0345


Note You need to log in before you can comment on or make changes to this bug.