{"id":"ALSA-2023:0210","summary":"Moderate: java-1.8.0-openjdk security and bug fix update","details":"The java-1.8.0-openjdk packages provide the OpenJDK 8 Java Runtime Environment and the OpenJDK 8 Java Software Development Kit.\n\nSecurity Fix(es):\n\n* OpenJDK: improper restrictions in CORBA deserialization (Serialization, 8285021) (CVE-2023-21830)\n* OpenJDK: soundbank URL remote loading (Sound, 8293742) (CVE-2023-21843)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n\nBug Fix(es):\n\n* Prepare for the next quarterly OpenJDK upstream release (2023-01, 8u362) [almalinux-9] (BZ#2159912)\n* solr broken due to access denied (\"java.io.FilePermission\" \"/etc/pki/java/cacerts\" \"read\") [almalinux-9, openjdk-8] (BZ#2163594)","modified":"2026-02-04T04:30:24.360371Z","published":"2023-01-26T00:00:00Z","related":["CVE-2023-21830","CVE-2023-21843"],"references":[{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2023:0210"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2023-21830"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2023-21843"},{"type":"REPORT","url":"https://bugzilla.redhat.com/2160475"},{"type":"REPORT","url":"https://bugzilla.redhat.com/2160490"},{"type":"ADVISORY","url":"https://errata.almalinux.org/9/ALSA-2023-0210.html"}],"affected":[{"package":{"name":"java-1.8.0-openjdk","ecosystem":"AlmaLinux:9","purl":"pkg:rpm/almalinux/java-1.8.0-openjdk"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:1.8.0.362.b09-2.el9_1"}]}],"database_specific":{"source":"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux9/ALSA-2023:0210.json"}},{"package":{"name":"java-1.8.0-openjdk-demo","ecosystem":"AlmaLinux:9","purl":"pkg:rpm/almalinux/java-1.8.0-openjdk-demo"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:1.8.0.362.b09-2.el9_1"}]}],"database_specific":{"source":"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux9/ALSA-2023:0210.json"}},{"package":{"name":"java-1.8.0-openjdk-demo-fastdebug","ecosystem":"AlmaLinux:9","purl":"pkg:rpm/almalinux/java-1.8.0-openjdk-demo-fastdebug"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:1.8.0.362.b09-2.el9_1"}]}],"database_specific":{"source":"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux9/ALSA-2023:0210.json"}},{"package":{"name":"java-1.8.0-openjdk-demo-slowdebug","ecosystem":"AlmaLinux:9","purl":"pkg:rpm/almalinux/java-1.8.0-openjdk-demo-slowdebug"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:1.8.0.362.b09-2.el9_1"}]}],"database_specific":{"source":"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux9/ALSA-2023:0210.json"}},{"package":{"name":"java-1.8.0-openjdk-devel","ecosystem":"AlmaLinux:9","purl":"pkg:rpm/almalinux/java-1.8.0-openjdk-devel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:1.8.0.362.b09-2.el9_1"}]}],"database_specific":{"source":"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux9/ALSA-2023:0210.json"}},{"package":{"name":"java-1.8.0-openjdk-devel-fastdebug","ecosystem":"AlmaLinux:9","purl":"pkg:rpm/almalinux/java-1.8.0-openjdk-devel-fastdebug"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:1.8.0.362.b09-2.el9_1"}]}],"database_specific":{"source":"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux9/ALSA-2023:0210.json"}},{"package":{"name":"java-1.8.0-openjdk-devel-slowdebug","ecosystem":"AlmaLinux:9","purl":"pkg:rpm/almalinux/java-1.8.0-openjdk-devel-slowdebug"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:1.8.0.362.b09-2.el9_1"}]}],"database_specific":{"source":"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux9/ALSA-2023:0210.json"}},{"package":{"name":"java-1.8.0-openjdk-fastdebug","ecosystem":"AlmaLinux:9","purl":"pkg:rpm/almalinux/java-1.8.0-openjdk-fastdebug"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:1.8.0.362.b09-2.el9_1"}]}],"database_specific":{"source":"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux9/ALSA-2023:0210.json"}},{"package":{"name":"java-1.8.0-openjdk-headless","ecosystem":"AlmaLinux:9","purl":"pkg:rpm/almalinux/java-1.8.0-openjdk-headless"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:1.8.0.362.b09-2.el9_1"}]}],"database_specific":{"source":"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux9/ALSA-2023:0210.json"}},{"package":{"name":"java-1.8.0-openjdk-headless-fastdebug","ecosystem":"AlmaLinux:9","purl":"pkg:rpm/almalinux/java-1.8.0-openjdk-headless-fastdebug"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:1.8.0.362.b09-2.el9_1"}]}],"database_specific":{"source":"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux9/ALSA-2023:0210.json"}},{"package":{"name":"java-1.8.0-openjdk-headless-slowdebug","ecosystem":"AlmaLinux:9","purl":"pkg:rpm/almalinux/java-1.8.0-openjdk-headless-slowdebug"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:1.8.0.362.b09-2.el9_1"}]}],"database_specific":{"source":"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux9/ALSA-2023:0210.json"}},{"package":{"name":"java-1.8.0-openjdk-javadoc","ecosystem":"AlmaLinux:9","purl":"pkg:rpm/almalinux/java-1.8.0-openjdk-javadoc"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:1.8.0.362.b09-2.el9_1"}]}],"database_specific":{"source":"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux9/ALSA-2023:0210.json"}},{"package":{"name":"java-1.8.0-openjdk-javadoc-zip","ecosystem":"AlmaLinux:9","purl":"pkg:rpm/almalinux/java-1.8.0-openjdk-javadoc-zip"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:1.8.0.362.b09-2.el9_1"}]}],"database_specific":{"source":"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux9/ALSA-2023:0210.json"}},{"package":{"name":"java-1.8.0-openjdk-slowdebug","ecosystem":"AlmaLinux:9","purl":"pkg:rpm/almalinux/java-1.8.0-openjdk-slowdebug"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:1.8.0.362.b09-2.el9_1"}]}],"database_specific":{"source":"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux9/ALSA-2023:0210.json"}},{"package":{"name":"java-1.8.0-openjdk-src","ecosystem":"AlmaLinux:9","purl":"pkg:rpm/almalinux/java-1.8.0-openjdk-src"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:1.8.0.362.b09-2.el9_1"}]}],"database_specific":{"source":"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux9/ALSA-2023:0210.json"}},{"package":{"name":"java-1.8.0-openjdk-src-fastdebug","ecosystem":"AlmaLinux:9","purl":"pkg:rpm/almalinux/java-1.8.0-openjdk-src-fastdebug"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:1.8.0.362.b09-2.el9_1"}]}],"database_specific":{"source":"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux9/ALSA-2023:0210.json"}},{"package":{"name":"java-1.8.0-openjdk-src-slowdebug","ecosystem":"AlmaLinux:9","purl":"pkg:rpm/almalinux/java-1.8.0-openjdk-src-slowdebug"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:1.8.0.362.b09-2.el9_1"}]}],"database_specific":{"source":"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux9/ALSA-2023:0210.json"}}],"schema_version":"1.7.3"}