[BLFS Trac] #23218: jdk-21.0.11

"BLFS Trac" ([email protected] via blfs-book Mailing List) <[email protected]>
Newsgroups gmane.linux.lfs.beyond.book
Message-ID <[email protected]>
#23218: jdk-21.0.11
-----------------------------+-----------------------
 Reporter:  Douglas R. Reno  |      Owner:  blfs-book
     Type:  enhancement      |     Status:  new
 Priority:  high             |  Milestone:  13.1
Component:  BOOK             |    Version:  git
 Severity:  normal           |   Keywords:
-----------------------------+-----------------------
 New quarterly OpenJDK release.

 This includes fixes for the following security vulnerabilities:

 - CVE-2026-22016 in the JAXP component. Rated as 7.5 High, low attack
 complexity and no privileges required. It is remotely exploitable and
 allows for trivial remote access to any information that the Java process
 is able to access.

 - CVE-2026-34282 in the Networking component. Rated as 7.5 High, low
 attack complexity and no privileges required. It is remotely exploitable
 and allows for easy crashes of Java applications.

 - CVE-2026-22021 in the JSSE component. Rated as 5.3 Medium. Remotely
 exploitable with low attack complexity and no privileges required. It
 allows for easy crashes of Java applications.

 - CVE-2026-22013 in the JGSS component. Rated as 5.3 Medium. Remotely
 exploitable with no privileges required, but the vulnerability is complex
 to exploit. Successful exploitation though allows for remote access to any
 information that the Java process is able to access.

 - CVE-2026-23865 in the 2D (Freetype) component. Rated as 5.3 Medium. Only
 exploitable locally and allows for a malicious font in a Java program to
 cause denial of service, and a low chance of information disclosure or
 arbitrary code execution.

 - CVE-2026-22018 in the Libraries component. Rated as 3.7 Low. Remotely
 exploitable vulnerability with High attack complexity and no privileges
 required. It allows for a remote attacker to crash a Java program.

 - CVE-2026-22007 in the Security component. Rated as 2.9 Low. Local
 attackers can possibly access all information on a system that a Java
 process can access without any privileges required or user interaction.

 - CVE-2026-34628 in the Security component. Rated as 2.9 Low. Local
 attackers can possibly access all information on a system that a Java
 process can access without any privileges required or user interaction.

 Note that of the above vulnerabilities, only the FreeType and the JGSS
 issues require any user interaction to successfully exploit.
-- 
Ticket URL: <https://wiki.linuxfromscratch.org/blfs/ticket/23218>
BLFS Trac <https://wiki.linuxfromscratch.org/blfs/>
Beyond Linux From Scratch

-- 
http://lists.linuxfromscratch.org/sympa/info/blfs-book
Unsubscribe: See the above information page
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.