RHSA-2022:4957: Moderate: java-1.7.1-ibm security update
IBM Java SE version 7 Release 1 includes the IBM Java Runtime Environment and the IBM Java Software Development Kit.This update upgrades IBM Java SE 7 to version 7R1 SR5-FP10.Security Fix(es): OpenJDK: Excessive memory allocation in HashMap and HashSet (Utility, 8266097) (CVE-2021-35561) OpenJDK: Infinite loop related to incorrect handling of newlines in XMLEntityScanner (JAXP, 8270646) (CVE-2022-21299) OpenJDK: Improper object-to-string conversion in AnnotationInvocationHandler (Libraries, 8277672) (CVE-2022-21434) OpenJDK: Missing check for negative ObjectIdentifier (Libraries, 8275151) (CVE-2022-21443) OpenJDK: URI parsing inconsistencies (JNDI, 8278972) (CVE-2022-21496) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2022:4957?
The severity of RHSA-2022:4957 is high due to excessive memory allocation issues in Java.
How do I fix RHSA-2022:4957?
To fix RHSA-2022:4957, you should upgrade to IBM Java SE version 7R1 SR5-FP10.
Which versions of IBM Java are affected by RHSA-2022:4957?
RHSA-2022:4957 affects versions of IBM Java SE prior to 7R1 SR5-FP10.
What components are included in the RHSA-2022:4957 update?
The RHSA-2022:4957 update includes the IBM Java Runtime Environment and the IBM Java Software Development Kit.
Is there a specific package I need to update for RHSA-2022:4957?
Yes, you need to update the specific packages such as java, java-demo, java-devel, java-jdbc, and others to their new versions.