Bug 2075793 (CVE-2022-21443) - CVE-2022-21443 OpenJDK: Missing check for negative ObjectIdentifier (Libraries, 8275151)
Summary: CVE-2022-21443 OpenJDK: Missing check for negative ObjectIdentifier (Librarie...
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2022-21443
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2073577 2073579 2073593 2073595 2074646 2074650 2073575 2073576 2073578 2073587 2073589 2073590 2073591 2073592 2073594 2073601 2074639 2074641 2074642 2074643 2074644 2074645 2074649 2088330 2092639 2092640 2094031
Blocks: 2073424
TreeView+ depends on / blocked
 
Reported: 2022-04-15 11:18 UTC by Mauro Matteo Cascella
Modified: 2022-08-02 08:03 UTC (History)
12 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2022-04-28 23:16:07 UTC


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHBA-2022:1479 0 None None None 2022-04-20 20:55:11 UTC
Red Hat Product Errata RHBA-2022:1493 0 None None None 2022-04-21 12:14:25 UTC
Red Hat Product Errata RHBA-2022:1528 0 None None None 2022-04-25 16:37:34 UTC
Red Hat Product Errata RHBA-2022:1529 0 None None None 2022-04-25 17:28:57 UTC
Red Hat Product Errata RHBA-2022:1593 0 None None None 2022-04-26 16:50:21 UTC
Red Hat Product Errata RHBA-2022:1594 0 None None None 2022-04-26 16:47:38 UTC
Red Hat Product Errata RHBA-2022:1598 0 None None None 2022-04-26 16:58:33 UTC
Red Hat Product Errata RHBA-2022:1624 0 None None None 2022-04-27 08:24:06 UTC
Red Hat Product Errata RHBA-2022:1630 0 None None None 2022-04-27 11:11:51 UTC
Red Hat Product Errata RHBA-2022:1633 0 None None None 2022-04-28 00:28:33 UTC
Red Hat Product Errata RHBA-2022:1634 0 None None None 2022-04-27 21:10:30 UTC
Red Hat Product Errata RHBA-2022:1635 0 None None None 2022-04-27 21:16:37 UTC
Red Hat Product Errata RHBA-2022:1641 0 None None None 2022-04-28 14:29:13 UTC
Red Hat Product Errata RHBA-2022:1653 0 None None None 2022-05-02 01:15:01 UTC
Red Hat Product Errata RHBA-2022:1668 0 None None None 2022-05-02 11:20:39 UTC
Red Hat Product Errata RHBA-2022:1752 0 None None None 2022-05-09 14:02:55 UTC
Red Hat Product Errata RHBA-2022:4709 0 None None None 2022-05-23 17:49:51 UTC
Red Hat Product Errata RHBA-2022:4761 0 None None None 2022-05-27 10:36:08 UTC
Red Hat Product Errata RHBA-2022:4762 0 None None None 2022-05-26 12:06:23 UTC
Red Hat Product Errata RHSA-2022:1435 0 None None None 2022-04-28 18:59:33 UTC
Red Hat Product Errata RHSA-2022:1436 0 None None None 2022-04-28 19:03:55 UTC
Red Hat Product Errata RHSA-2022:1437 0 None None None 2022-04-28 19:04:23 UTC
Red Hat Product Errata RHSA-2022:1438 0 None None None 2022-04-28 18:58:45 UTC
Red Hat Product Errata RHSA-2022:1439 0 None None None 2022-04-28 18:59:53 UTC
Red Hat Product Errata RHSA-2022:1440 0 None Closed [BZ] openscap report fail with 2022-06-01 16:45:10 UTC
Red Hat Product Errata RHSA-2022:1441 0 None None None 2022-04-20 13:08:37 UTC
Red Hat Product Errata RHSA-2022:1442 0 None None None 2022-04-20 14:14:34 UTC
Red Hat Product Errata RHSA-2022:1443 0 None None None 2022-04-20 12:38:16 UTC
Red Hat Product Errata RHSA-2022:1444 0 None None None 2022-04-20 12:50:22 UTC
Red Hat Product Errata RHSA-2022:1445 0 None None None 2022-04-20 13:28:27 UTC
Red Hat Product Errata RHSA-2022:1487 0 None None None 2022-04-25 13:47:50 UTC
Red Hat Product Errata RHSA-2022:1488 0 None None None 2022-04-25 14:59:26 UTC
Red Hat Product Errata RHSA-2022:1489 0 None None None 2022-04-25 15:00:06 UTC
Red Hat Product Errata RHSA-2022:1490 0 None None None 2022-04-25 15:09:04 UTC
Red Hat Product Errata RHSA-2022:1491 0 None None None 2022-04-25 15:47:54 UTC
Red Hat Product Errata RHSA-2022:1492 0 None None None 2022-04-28 18:58:28 UTC
Red Hat Product Errata RHSA-2022:1728 0 None None None 2022-05-17 23:39:36 UTC
Red Hat Product Errata RHSA-2022:1729 0 None None None 2022-05-17 23:39:16 UTC
Red Hat Product Errata RHSA-2022:2137 0 None None None 2022-05-17 23:39:01 UTC
Red Hat Product Errata RHSA-2022:4957 0 None None None 2022-06-08 12:25:01 UTC
Red Hat Product Errata RHSA-2022:4959 0 None None None 2022-06-08 12:34:57 UTC
Red Hat Product Errata RHSA-2022:5837 0 None None None 2022-08-02 08:03:13 UTC

Description Mauro Matteo Cascella 2022-04-15 11:18:01 UTC
It was discovered that the ObjectIdentifier class in the Libraries component of OpenJDK did not properly validate the encoded length of the object identifier. This could lead to an integer underflow and possibly cause a Java application to throw an out of memory (OOM) exception because of excessive memory allocation.

Comment 7 errata-xmlrpc 2022-04-20 12:38:14 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.2 Extended Update Support

Via RHSA-2022:1443 https://access.redhat.com/errata/RHSA-2022:1443

Comment 8 errata-xmlrpc 2022-04-20 12:50:20 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions

Via RHSA-2022:1444 https://access.redhat.com/errata/RHSA-2022:1444

Comment 9 errata-xmlrpc 2022-04-20 13:08:34 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.4 Extended Update Support

Via RHSA-2022:1441 https://access.redhat.com/errata/RHSA-2022:1441

Comment 11 errata-xmlrpc 2022-04-20 13:28:25 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2022:1445 https://access.redhat.com/errata/RHSA-2022:1445

Comment 12 errata-xmlrpc 2022-04-20 14:14:31 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2022:1442 https://access.redhat.com/errata/RHSA-2022:1442

Comment 13 Mauro Matteo Cascella 2022-04-20 15:18:30 UTC
Oracle CPU April 2022:

https://www.oracle.com/security-alerts/cpuapr2022.html#AppendixJAVA

Fixed in Oracle Java SE 7u341, 8u331, 11.0.15, 17.0.3, 18.0.1.

Comment 14 errata-xmlrpc 2022-04-20 15:23:48 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7

Via RHSA-2022:1440 https://access.redhat.com/errata/RHSA-2022:1440

Comment 15 errata-xmlrpc 2022-04-25 13:47:46 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7

Via RHSA-2022:1487 https://access.redhat.com/errata/RHSA-2022:1487

Comment 16 errata-xmlrpc 2022-04-25 14:59:23 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions

Via RHSA-2022:1488 https://access.redhat.com/errata/RHSA-2022:1488

Comment 17 errata-xmlrpc 2022-04-25 15:00:03 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.2 Extended Update Support

Via RHSA-2022:1489 https://access.redhat.com/errata/RHSA-2022:1489

Comment 18 errata-xmlrpc 2022-04-25 15:09:02 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.4 Extended Update Support

Via RHSA-2022:1490 https://access.redhat.com/errata/RHSA-2022:1490

Comment 19 errata-xmlrpc 2022-04-25 15:47:51 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2022:1491 https://access.redhat.com/errata/RHSA-2022:1491

Comment 20 errata-xmlrpc 2022-04-28 18:58:26 UTC
This issue has been addressed in the following products:

  Red Hat Build of OpenJDK 8u332

Via RHSA-2022:1492 https://access.redhat.com/errata/RHSA-2022:1492

Comment 21 errata-xmlrpc 2022-04-28 18:58:43 UTC
This issue has been addressed in the following products:

  Red Hat Build of OpenJDK 8u332

Via RHSA-2022:1438 https://access.redhat.com/errata/RHSA-2022:1438

Comment 22 errata-xmlrpc 2022-04-28 18:59:31 UTC
This issue has been addressed in the following products:

  Red Hat Build of OpenJDK 11.0.15

Via RHSA-2022:1435 https://access.redhat.com/errata/RHSA-2022:1435

Comment 23 errata-xmlrpc 2022-04-28 18:59:50 UTC
This issue has been addressed in the following products:

  Red Hat Build of OpenJDK 11.0.15

Via RHSA-2022:1439 https://access.redhat.com/errata/RHSA-2022:1439

Comment 24 errata-xmlrpc 2022-04-28 19:03:52 UTC
This issue has been addressed in the following products:

  Red Hat Build of OpenJDK 17.0.3

Via RHSA-2022:1436 https://access.redhat.com/errata/RHSA-2022:1436

Comment 25 errata-xmlrpc 2022-04-28 19:04:21 UTC
This issue has been addressed in the following products:

  Red Hat Build of OpenJDK 17.0.3

Via RHSA-2022:1437 https://access.redhat.com/errata/RHSA-2022:1437

Comment 26 Product Security DevOps Team 2022-04-28 23:16:05 UTC
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):

https://access.redhat.com/security/cve/cve-2022-21443

Comment 27 errata-xmlrpc 2022-05-17 23:38:59 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2022:2137 https://access.redhat.com/errata/RHSA-2022:2137

Comment 28 errata-xmlrpc 2022-05-17 23:39:14 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2022:1729 https://access.redhat.com/errata/RHSA-2022:1729

Comment 29 errata-xmlrpc 2022-05-17 23:39:33 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2022:1728 https://access.redhat.com/errata/RHSA-2022:1728

Comment 30 errata-xmlrpc 2022-06-08 12:24:58 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7 Supplementary

Via RHSA-2022:4957 https://access.redhat.com/errata/RHSA-2022:4957

Comment 31 errata-xmlrpc 2022-06-08 12:34:55 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7 Supplementary

Via RHSA-2022:4959 https://access.redhat.com/errata/RHSA-2022:4959

Comment 32 errata-xmlrpc 2022-08-02 08:03:10 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2022:5837 https://access.redhat.com/errata/RHSA-2022:5837


Note You need to log in before you can comment on or make changes to this bug.