USN-6528-1: OpenJDK 8 vulnerabilities
It was discovered that the HotSpot VM implementation in OpenJDK did not properly validate bytecode blocks in certain situations. An attacker could possibly use this to cause a denial of service. (CVE-2022-40433) Carter Kozak discovered that OpenJDK, when compiling with AVX-512 instruction support enabled, could produce code that resulted in memory corruption in certain situations. An attacker targeting applications built in this way could possibly use this to cause a denial of service or execute arbitrary code. In Ubuntu, OpenJDK defaults to not using AVX-512 instructions. (CVE-2023-22025) It was discovered that the CORBA implementation in OpenJDK did not properly perform deserialization of IOR string objects. An attacker could possibly use this to bypass Java sandbox restrictions. (CVE-2023-22067) It was discovered that OpenJDK did not properly perform PKIX certification path validation in certain situations. An attacker could use this to cause a denial of service. (CVE-2023-22081)
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-6528-1?
USN-6528-1 has been classified as a denial of service vulnerability.
How do I fix USN-6528-1?
You can resolve USN-6528-1 by upgrading to the fixed package version 8u392-ga-1~23.10 or later.
What software is affected by USN-6528-1?
USN-6528-1 affects OpenJDK packages in Ubuntu versions 16.04, 18.04, 20.04, 22.04, and 23.04.
Can USN-6528-1 be exploited remotely?
Yes, an attacker can exploit USN-6528-1 to cause a denial of service remotely.
What are the CVEs associated with USN-6528-1?
USN-6528-1 is associated with CVE-2023-22067, CVE-2022-40433, and CVE-2023-22081.