CLSA-2022-1654174749

See a problem?
Import Source
https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos6els/CLSA-2022-1654174749.json
JSON Data
https://api.osv.dev/v1/vulns/CLSA-2022-1654174749
Upstream
Published
2022-06-02T12:59:09Z
Modified
2026-06-01T00:32:15.559218169Z
Summary
Fixed CVEs in java-1.8.0-openjdk: CVE-2022-21434, CVE-2022-21443, CVE-2022-21476, CVE-2022-21426, CVE-2022-21496
Details
  • Upgrade to openjdk-shenandoah-jdk8u-shenandoah-jdk8u332-b09. That fixes following CVEs:
  • CVE-2022-21476: Defective secure validation in Apache Santuario
  • CVE-2022-21496: URI parsing inconsistencies
  • CVE-2022-21434: Improper object-to-string conversion in AnnotationInvocationHandler
  • CVE-2022-21426: Unbounded memory allocation when compiling crafted XPath expressions
  • CVE-2022-21443: Missing check for negative ObjectIdentifier
  • Remove patch files from previous change due to their presence in newer versions
References

Affected packages

TuxCare:CentOS:6
java-1.8.0-openjdk

Package

Name
java-1.8.0-openjdk
Purl
pkg:rpm/tuxcare/java-1.8.0-openjdk?distro=centos-6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:1.8.0.332.b09-1.el6.tuxcare.els1

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos6els/CLSA-2022-1654174749.json"
java-1.8.0-openjdk-debug

Package

Name
java-1.8.0-openjdk-debug
Purl
pkg:rpm/tuxcare/java-1.8.0-openjdk-debug?distro=centos-6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:1.8.0.332.b09-1.el6.tuxcare.els1

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos6els/CLSA-2022-1654174749.json"
java-1.8.0-openjdk-demo

Package

Name
java-1.8.0-openjdk-demo
Purl
pkg:rpm/tuxcare/java-1.8.0-openjdk-demo?distro=centos-6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:1.8.0.332.b09-1.el6.tuxcare.els1

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos6els/CLSA-2022-1654174749.json"
java-1.8.0-openjdk-demo-debug

Package

Name
java-1.8.0-openjdk-demo-debug
Purl
pkg:rpm/tuxcare/java-1.8.0-openjdk-demo-debug?distro=centos-6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:1.8.0.332.b09-1.el6.tuxcare.els1

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos6els/CLSA-2022-1654174749.json"
java-1.8.0-openjdk-devel

Package

Name
java-1.8.0-openjdk-devel
Purl
pkg:rpm/tuxcare/java-1.8.0-openjdk-devel?distro=centos-6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:1.8.0.332.b09-1.el6.tuxcare.els1

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos6els/CLSA-2022-1654174749.json"
java-1.8.0-openjdk-devel-debug

Package

Name
java-1.8.0-openjdk-devel-debug
Purl
pkg:rpm/tuxcare/java-1.8.0-openjdk-devel-debug?distro=centos-6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:1.8.0.332.b09-1.el6.tuxcare.els1

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos6els/CLSA-2022-1654174749.json"
java-1.8.0-openjdk-headless

Package

Name
java-1.8.0-openjdk-headless
Purl
pkg:rpm/tuxcare/java-1.8.0-openjdk-headless?distro=centos-6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:1.8.0.332.b09-1.el6.tuxcare.els1

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos6els/CLSA-2022-1654174749.json"
java-1.8.0-openjdk-headless-debug

Package

Name
java-1.8.0-openjdk-headless-debug
Purl
pkg:rpm/tuxcare/java-1.8.0-openjdk-headless-debug?distro=centos-6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:1.8.0.332.b09-1.el6.tuxcare.els1

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos6els/CLSA-2022-1654174749.json"
java-1.8.0-openjdk-javadoc

Package

Name
java-1.8.0-openjdk-javadoc
Purl
pkg:rpm/tuxcare/java-1.8.0-openjdk-javadoc?distro=centos-6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:1.8.0.332.b09-1.el6.tuxcare.els1

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos6els/CLSA-2022-1654174749.json"
java-1.8.0-openjdk-javadoc-debug

Package

Name
java-1.8.0-openjdk-javadoc-debug
Purl
pkg:rpm/tuxcare/java-1.8.0-openjdk-javadoc-debug?distro=centos-6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:1.8.0.332.b09-1.el6.tuxcare.els1

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos6els/CLSA-2022-1654174749.json"
java-1.8.0-openjdk-src

Package

Name
java-1.8.0-openjdk-src
Purl
pkg:rpm/tuxcare/java-1.8.0-openjdk-src?distro=centos-6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:1.8.0.332.b09-1.el6.tuxcare.els1

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos6els/CLSA-2022-1654174749.json"
java-1.8.0-openjdk-src-debug

Package

Name
java-1.8.0-openjdk-src-debug
Purl
pkg:rpm/tuxcare/java-1.8.0-openjdk-src-debug?distro=centos-6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:1.8.0.332.b09-1.el6.tuxcare.els1

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos6els/CLSA-2022-1654174749.json"