Bug 2015648 (CVE-2021-35550) - CVE-2021-35550 OpenJDK: Weak ciphers preferred over stronger ones for TLS (JSSE, 8264210)
Summary: CVE-2021-35550 OpenJDK: Weak ciphers preferred over stronger ones for TLS (JS...
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2021-35550
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: Red Hat2012332 Red Hat2012333 Red Hat2012334 Red Hat2012335 Red Hat2012336 Red Hat2012337 Red Hat2012338 Red Hat2012339 Red Hat2014299 Red Hat2014300 Red Hat2014301 Red Hat2014302 Red Hat2057129 Red Hat2057130 Red Hat2057131 Red Hat2061939 Red Hat2070472
Blocks: Embargoed2011827
TreeView+ depends on / blocked
 
Reported: 2021-10-19 18:35 UTC by Tomas Hoger
Modified: 2022-04-06 11:58 UTC (History)
8 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2021-10-20 14:09:05 UTC


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHBA-2021:3952 0 None None None 2021-10-25 01:19:52 UTC
Red Hat Product Errata RHBA-2021:3954 0 None None None 2021-10-25 01:23:04 UTC
Red Hat Product Errata RHBA-2021:3963 0 None None None 2021-10-25 12:33:39 UTC
Red Hat Product Errata RHBA-2021:3964 0 None None None 2021-10-25 12:33:26 UTC
Red Hat Product Errata RHBA-2021:3965 0 None None None 2021-10-25 12:32:27 UTC
Red Hat Product Errata RHBA-2021:3966 0 None None None 2021-10-25 12:32:48 UTC
Red Hat Product Errata RHBA-2021:3969 0 None None None 2021-10-25 12:58:42 UTC
Red Hat Product Errata RHBA-2021:3970 0 None None None 2021-10-25 12:57:20 UTC
Red Hat Product Errata RHBA-2021:3979 0 None None None 2021-10-25 17:53:17 UTC
Red Hat Product Errata RHBA-2021:3983 0 None None None 2021-10-26 01:25:02 UTC
Red Hat Product Errata RHBA-2021:3984 0 None None None 2021-10-26 01:30:02 UTC
Red Hat Product Errata RHBA-2021:3985 0 None None None 2021-10-26 01:30:55 UTC
Red Hat Product Errata RHBA-2021:3986 0 None None None 2021-10-26 01:28:26 UTC
Red Hat Product Errata RHBA-2021:3993 0 None None None 2021-10-26 10:35:40 UTC
Red Hat Product Errata RHBA-2021:3994 0 None None None 2021-10-26 11:29:03 UTC
Red Hat Product Errata RHBA-2021:3995 0 None None None 2021-10-26 11:29:21 UTC
Red Hat Product Errata RHBA-2021:4041 0 None None None 2021-11-01 10:43:14 UTC
Red Hat Product Errata RHBA-2021:4048 0 None None None 2021-11-01 18:52:02 UTC
Red Hat Product Errata RHBA-2021:4125 0 None None None 2021-11-04 11:21:20 UTC
Red Hat Product Errata RHBA-2021:4126 0 None None None 2021-11-04 11:21:48 UTC
Red Hat Product Errata RHBA-2021:4127 0 None None None 2021-11-04 12:56:00 UTC
Red Hat Product Errata RHBA-2021:4583 0 None None None 2021-11-10 13:06:02 UTC
Red Hat Product Errata RHBA-2021:4584 0 None None None 2021-11-10 08:16:51 UTC
Red Hat Product Errata RHBA-2021:4670 0 None None None 2021-11-16 03:50:33 UTC
Red Hat Product Errata RHBA-2021:4732 0 None None None 2021-11-18 12:15:20 UTC
Red Hat Product Errata RHBA-2021:4842 0 None None None 2021-11-29 12:31:44 UTC
Red Hat Product Errata RHBA-2021:5079 0 None None None 2021-12-13 08:05:47 UTC
Red Hat Product Errata RHBA-2021:5083 0 None None None 2021-12-13 09:51:29 UTC
Red Hat Product Errata RHSA-2021:3884 0 None None None 2021-10-20 13:18:41 UTC
Red Hat Product Errata RHSA-2021:3885 0 None Waiting on Customer CVE-2022-0185 patching RHV manager & hypervisor 2022-06-06 14:18:07 UTC
Red Hat Product Errata RHSA-2021:3886 0 None None None 2021-10-20 13:09:07 UTC
Red Hat Product Errata RHSA-2021:3887 0 None None None 2021-10-20 13:45:11 UTC
Red Hat Product Errata RHSA-2021:3889 0 None None None 2021-10-20 14:38:13 UTC
Red Hat Product Errata RHSA-2021:3891 0 None None None 2021-10-20 13:53:35 UTC
Red Hat Product Errata RHSA-2021:3892 0 None None None 2021-10-20 15:23:09 UTC
Red Hat Product Errata RHSA-2021:3893 0 None None None 2021-10-20 13:40:07 UTC
Red Hat Product Errata RHSA-2021:3960 0 None None None 2021-10-25 11:55:49 UTC
Red Hat Product Errata RHSA-2021:3961 0 None None None 2021-10-25 11:56:10 UTC
Red Hat Product Errata RHSA-2021:3967 0 None None None 2021-10-25 12:24:44 UTC
Red Hat Product Errata RHSA-2021:3968 0 None None None 2021-10-25 12:25:18 UTC
Red Hat Product Errata RHSA-2022:0968 0 None None None 2022-03-21 07:34:13 UTC
Red Hat Product Errata RHSA-2022:0969 0 None None None 2022-03-21 07:32:59 UTC
Red Hat Product Errata RHSA-2022:0970 0 None None None 2022-03-21 07:25:48 UTC

Description Tomas Hoger 2021-10-19 18:35:13 UTC
It was discovered that the default TLS cipher suite configuration in the JSSE component of OpenJDK preferred certain weak ciphers over stronger ciphers.  This issue was addressed by:

- Preferring ciphers with forward secrecy.
- Lowering priority of ciphers using RSA encryption key exchange.
- Lowering priority of ciphers using SHA-1 hashing algorithm.

Upstream commit:

https://github.com/openjdk/jdk11u/commit/af4b37301d33723806c38cf8ae5d85b7fa7ef39f

Comment 1 Tomas Hoger 2021-10-19 20:15:34 UTC
Related noted in the Oracle JDK release notes:

"""
security-libs/javax.net.ssl
➜ Updated the Default Enabled Cipher Suites Preference

The default priority order of the cipher suites for TLS 1.0 to TLS 1.3 has been adjusted.

For TLS 1.3, TLS_AES_256_GCM_SHA384 is now preferred over TLS_AES_128_GCM_SHA256.

For TLS 1.0 to TLS 1.2, some of the intermediate suites have been lowered in priority as follows:

Cipher suites that do not preserve forward secrecy have been moved lower in priority than those that do support forward secrecy.
Cipher suites that use SHA-1 have been moved lower in priority.

See JDK-8163326 (https://bugs.openjdk.java.net/browse/JDK-8163326)
"""

https://www.oracle.com/java/technologies/javase/11-0-13-relnotes.html
https://www.oracle.com/java/technologies/javase/8u311-relnotes.html

Comment 2 Tomas Hoger 2021-10-19 20:18:35 UTC
Public now via Oracle CPU October 2021:

https://www.oracle.com/security-alerts/cpuoct2021.html#AppendixJAVA

Fixed in Oracle Java SE 17.0.1, 11.0.13, 8u311, and 7u321.

Comment 7 errata-xmlrpc 2021-10-20 13:09:06 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.1 Extended Update Support

Via RHSA-2021:3886 https://access.redhat.com/errata/RHSA-2021:3886

Comment 8 errata-xmlrpc 2021-10-20 13:18:40 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.1 Extended Update Support

Via RHSA-2021:3884 https://access.redhat.com/errata/RHSA-2021:3884

Comment 9 errata-xmlrpc 2021-10-20 13:32:14 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.2 Extended Update Support

Via RHSA-2021:3885 https://access.redhat.com/errata/RHSA-2021:3885

Comment 10 errata-xmlrpc 2021-10-20 13:40:05 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2021:3893 https://access.redhat.com/errata/RHSA-2021:3893

Comment 11 errata-xmlrpc 2021-10-20 13:45:10 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.2 Extended Update Support

Via RHSA-2021:3887 https://access.redhat.com/errata/RHSA-2021:3887

Comment 12 errata-xmlrpc 2021-10-20 13:53:34 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2021:3891 https://access.redhat.com/errata/RHSA-2021:3891

Comment 13 Product Security DevOps Team 2021-10-20 14:09:05 UTC
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):

https://access.redhat.com/security/cve/cve-2021-35550

Comment 14 errata-xmlrpc 2021-10-20 14:38:12 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7

Via RHSA-2021:3889 https://access.redhat.com/errata/RHSA-2021:3889

Comment 15 errata-xmlrpc 2021-10-20 15:23:07 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7

Via RHSA-2021:3892 https://access.redhat.com/errata/RHSA-2021:3892

Comment 16 errata-xmlrpc 2021-10-25 11:55:48 UTC
This issue has been addressed in the following products:

  Red Hat Build of OpenJDK 8u312

Via RHSA-2021:3960 https://access.redhat.com/errata/RHSA-2021:3960

Comment 17 errata-xmlrpc 2021-10-25 11:56:09 UTC
This issue has been addressed in the following products:

  Red Hat Build of OpenJDK 8u312

Via RHSA-2021:3961 https://access.redhat.com/errata/RHSA-2021:3961

Comment 18 errata-xmlrpc 2021-10-25 12:24:42 UTC
This issue has been addressed in the following products:

  Red Hat Build of OpenJDK 11.0.13

Via RHSA-2021:3967 https://access.redhat.com/errata/RHSA-2021:3967

Comment 19 errata-xmlrpc 2021-10-25 12:25:17 UTC
This issue has been addressed in the following products:

  Red Hat Build of OpenJDK 11.0.13

Via RHSA-2021:3968 https://access.redhat.com/errata/RHSA-2021:3968

Comment 21 errata-xmlrpc 2022-03-21 07:25:46 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2022:0970 https://access.redhat.com/errata/RHSA-2022:0970

Comment 22 errata-xmlrpc 2022-03-21 07:32:57 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7 Supplementary

Via RHSA-2022:0969 https://access.redhat.com/errata/RHSA-2022:0969

Comment 23 errata-xmlrpc 2022-03-21 07:34:12 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7 Supplementary

Via RHSA-2022:0968 https://access.redhat.com/errata/RHSA-2022:0968


Note You need to log in before you can comment on or make changes to this bug.