-----BEGIN PGP SIGNATURE-----
wsF5BAABCAAjFiEEAPYWTpwtIbr7xH4OWNrRIKaTkWcFAmejB2kFAwAAAAAACgkQWNrRIKaTkWdC
NBAAunzlRxl7gu0jQ8J/CzVSJM5pXDq/evW2JYiwQxtCqEuwXIa8h5OHDUVxe3k0Eafy/dK0qhv9
mFmO+/npxRvc7kO1Bslj0OFcU0V67Q4gJ6jtub39rLkBSn+U9c44Tcj1+JDerbyZ2jY+iZoxEvim
S1tzlKSm7i9KyZkYpZPZrWT5yWx0zgSFUXo748oS2ogAAv8XSYjZDNywvjU3MdPTTpUfeOwMkU3a
IbGD3bYHkwGJmSfHv+2OqIeQOyvddyNrEGJ8JUD1ekGXeiqF/ug+5lm5WE4rSetLHhxGOdKqyZ22
YN2LMizZInBz3PSKXC5UH1qmJ/7w3wGKdZ2wOC/chK8aezvGoST7lF2kwIKzJtdOw6tZ2IrnysnE
eDWLwlTo46la3wzyWTqiopC+V0dD2aYnjlBcSYM6VxlbB93BDWtC1X6SnGH8bQzdCxcI0eln2o0q
vFfUThABQfgw7c8ID+WtKeq9qnFbSL0RNonncSVUfVDI5Ago4EKdok1gT37akjgq9dDWV4YnLsiy
bSoqdMV6vJvHhFfzxl7fy3UwXw8vBXCuNJOliP+nJoqqXPfE58lYUpUDAr7Rbms/vUykLDAG8Zas
HWfRBmmqV2iokIPNe3KLmIk9j3OyMzGMt2HJ/PT0kGSi/+zLfvgNTe/NOxFgnRpLDv+rIAASuN52
Z6U=
=UTXf
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-7254-1
February 05, 2025
openjdk-21 vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 24.10
- Ubuntu 24.04 LTS
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
Summary:
OpenJDK 21 could be made to expose sensitive information over the
network.
Software Description:
- openjdk-21: Open Source Java implementation
Details:
It was discovered that the Hotspot component of OpenJDK 21 did not properly
handle API access under certain circumstances. An unauthenticated attacker
could possibly use this issue to access unauthorized resources and expose
sensitive information.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 24.10
openjdk-21-jdk 21.0.6+7-1~24.10.1
openjdk-21-jdk-headless 21.0.6+7-1~24.10.1
openjdk-21-jre 21.0.6+7-1~24.10.1
openjdk-21-jre-headless 21.0.6+7-1~24.10.1
openjdk-21-jre-zero 21.0.6+7-1~24.10.1
Ubuntu 24.04 LTS
openjdk-21-jdk 21.0.6+7-1~24.04.1
openjdk-21-jdk-headless 21.0.6+7-1~24.04.1
openjdk-21-jre 21.0.6+7-1~24.04.1
openjdk-21-jre-headless 21.0.6+7-1~24.04.1
openjdk-21-jre-zero 21.0.6+7-1~24.04.1
Ubuntu 22.04 LTS
openjdk-21-jdk 21.0.6+7-1~22.04.1
openjdk-21-jdk-headless 21.0.6+7-1~22.04.1
openjdk-21-jre 21.0.6+7-1~22.04.1
openjdk-21-jre-headless 21.0.6+7-1~22.04.1
openjdk-21-jre-zero 21.0.6+7-1~22.04.1
Ubuntu 20.04 LTS
openjdk-21-jdk 21.0.6+7-1~20.04.1
openjdk-21-jdk-headless 21.0.6+7-1~20.04.1
openjdk-21-jre 21.0.6+7-1~20.04.1
openjdk-21-jre-headless 21.0.6+7-1~20.04.1
openjdk-21-jre-zero 21.0.6+7-1~20.04.1
This update uses a new upstream release, which includes additional bug
fixes. After a standard system update you need to restart Java
applications to make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-7254-1
CVE-2025-21502
Package Information:
https://launchpad.net/ubuntu/+source/openjdk-21/21.0.6+7-1~24.10.1
https://launchpad.net/ubuntu/+source/openjdk-21/21.0.6+7-1~24.04.1
https://launchpad.net/ubuntu/+source/openjdk-21/21.0.6+7-1~22.04.1
https://launchpad.net/ubuntu/+source/openjdk-21/21.0.6+7-1~20.04.1
No comments:
Post a Comment