CVE-2023-22025
Published Oct 13, 2023
·Updated
A memory corruption issue was found in JDK-21 on x86_64 with AVX-512. The issue seems to be caused by the calling of the super class's "Ideal()" method in "LoadVectorMaskedNode::Ideal()". Reference: https://mail.openjdk.org/pipermail/hotspot-compiler-dev/2023-September/068447.html
Affected Software
31 affected componentsFixes available
ubuntu/openjdk-17<17.0.9+9-1~18.04
17.0.9+9-1~18.04
ubuntu/openjdk-17<17.0.9+9-1~20.04
17.0.9+9-1~20.04
ubuntu/openjdk-17<17.0.9+9-1~22.04
17.0.9+9-1~22.04
ubuntu/openjdk-17<17.0.9+9-1~23.04
17.0.9+9-1~23.04
ubuntu/openjdk-17<17.0.9+9-1~23.10
17.0.9+9-1~23.10
ubuntu/openjdk-21<21.0.1+12-2~22.04
21.0.1+12-2~22.04
ubuntu/openjdk-21<21.0.1+12-2~23.04
21.0.1+12-2~23.04
ubuntu/openjdk-21<21.0.1+12-2~23.10
21.0.1+12-2~23.10
ubuntu/openjdk-8<8
8
ubuntu/openjdk-8<8
8
ubuntu/openjdk-8<8
8
ubuntu/openjdk-8<8
8
ubuntu/openjdk-8<8
8
ubuntu/openjdk-8<8
8
ubuntu/openjdk-lts<11.0.21+9-0ubuntu1~18.04
11.0.21+9-0ubuntu1~18.04
ubuntu/openjdk-lts<11.0.21+9-0ubuntu1~20.04
11.0.21+9-0ubuntu1~20.04
ubuntu/openjdk-lts<11.0.21+9-0ubuntu1~22.04
11.0.21+9-0ubuntu1~22.04
ubuntu/openjdk-lts<11.0.21+9-0ubuntu1~23.04
11.0.21+9-0ubuntu1~23.04
ubuntu/openjdk-lts<11.0.21+9-0ubuntu1~23.10
11.0.21+9-0ubuntu1~23.10
debian/openjdk-17
17.0.11+9-1~deb11u117.0.11+9-1~deb12u117.0.12~6ea-1
debian/openjdk-21
21.0.4~6ea-1
ORACLE GraalVM for JDK=17.0.8
ORACLE GraalVM for JDK=21
Oracle JDK=1.8.0-update381
Oracle JDK=17.0.8
Oracle JDK=21.0.0
ORACLE JRE=1.8.0-update381
ORACLE JRE=17.0.8
ORACLE JRE=21.0.0
NetApp Cloud Insights Acquisition Unit
NetApp Cloud Insights Storage Workload Security Agent
Remediation
Patch Available
Event History
Oct 13, 2023
Data Sourced
via Red Hat·08:12 AM
DescriptionSeverityAffected Software
Oct 17, 2023
CVE Published
via Ubuntu·12:00 AM
CVE Published
via MITRE·09:02 PM
Data Sourced
via MITRE·09:02 PM
DescriptionSeverity
Data Sourced
10:15 PM
DescriptionSeverity
Jan 13, 2024
Data Sourced
via Launchpad·12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this Oracle Java SE and Oracle GraalVM vulnerability?
The vulnerability ID is CVE-2023-22025.
2
Which versions of Oracle Java SE are affected by this vulnerability?
The affected versions of Oracle Java SE are 8u381-perf, 17.0.8, and 21.
3
Which versions of Oracle GraalVM for JDK are affected by this vulnerability?
The affected versions of Oracle GraalVM for JDK are 17.0.8 and 21.
4
How severe is the vulnerability CVE-2023-22025?
The severity level of the vulnerability CVE-2023-22025 is medium with a severity value of 3.7.
5
How can I fix the vulnerability CVE-2023-22025?
To fix the vulnerability CVE-2023-22025, update to the latest versions of Oracle Java SE and Oracle GraalVM for JDK.