{"id":"USN-6263-2","summary":"openjdk-lts, openjdk-17 regression","details":"USN-6263-1 fixed vulnerabilities in OpenJDK. Unfortunately, that update\nintroduced a regression when opening APK, ZIP or JAR files in OpenJDK 11\nand OpenJDK 17. This update fixes the problem.\n\nWe apologize for the inconvenience.\n\nOriginal advisory details:\n\n Motoyasu Saburi discovered that OpenJDK incorrectly handled special\n characters in file name parameters. An attacker could possibly use\n this issue to insert, edit or obtain sensitive information. This issue\n only affected OpenJDK 11 and OpenJDK 17. (CVE-2023-22006)\n\n Eirik Bjørsnøs discovered that OpenJDK incorrectly handled certain ZIP\n archives. An attacker could possibly use this issue to cause a denial\n of service. This issue only affected OpenJDK 11 and OpenJDK 17.\n (CVE-2023-22036)\n\n David Stancu discovered that OpenJDK had a flaw in the AES cipher\n implementation. An attacker could possibly use this issue to obtain\n sensitive information. This issue only affected OpenJDK 11 and OpenJDK 17.\n (CVE-2023-22041)\n\n Zhiqiang Zang discovered that OpenJDK incorrectly handled array accesses\n when using the binary '%' operator. An attacker could possibly use this\n issue to obtain sensitive information. This issue only affected OpenJDK 17.\n (CVE-2023-22044)\n\n Zhiqiang Zang discovered that OpenJDK incorrectly handled array accesses.\n An attacker could possibly use this issue to obtain sensitive information.\n (CVE-2023-22045)\n\n It was discovered that OpenJDK incorrectly sanitized URIs strings. An\n attacker could possibly use this issue to insert, edit or obtain sensitive\n information. (CVE-2023-22049)\n\n It was discovered that OpenJDK incorrectly handled certain glyphs. An\n attacker could possibly use this issue to cause a denial of service.\n This issue only affected OpenJDK 11 and OpenJDK 17.\n (CVE-2023-25193)\n","modified":"2026-02-10T04:43:14Z","published":"2023-08-30T10:45:56Z","references":[{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-6263-2"},{"type":"REPORT","url":"https://launchpad.net/bugs/2032865"}],"affected":[{"package":{"name":"openjdk-lts","ecosystem":"Ubuntu:Pro:18.04:LTS","purl":"pkg:deb/ubuntu/openjdk-lts@11.0.20.1+1-0ubuntu1~18.04?arch=source&distro=esm-infra/bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"11.0.20.1+1-0ubuntu1~18.04"}]}],"versions":["9.0.4+12-2ubuntu4","9.0.4+12-4ubuntu1","10~46-4ubuntu1","10~46-5ubuntu1","10.0.1+10-1ubuntu2","10.0.1+10-3ubuntu1","10.0.2+13-1ubuntu0.18.04.1","10.0.2+13-1ubuntu0.18.04.2","10.0.2+13-1ubuntu0.18.04.3","10.0.2+13-1ubuntu0.18.04.4","11.0.2+9-3ubuntu1~18.04.3","11.0.3+7-1ubuntu2~18.04.1","11.0.4+11-1ubuntu2~18.04.3","11.0.5+10-0ubuntu1.1~18.04","11.0.6+10-1ubuntu1~18.04.1","11.0.7+10-2ubuntu2~18.04","11.0.8+10-0ubuntu1~18.04.1","11.0.9+11-0ubuntu1~18.04.1","11.0.9.1+1-0ubuntu1~18.04","11.0.10+9-0ubuntu1~18.04","11.0.11+9-0ubuntu2~18.04","11.0.13+8-0ubuntu1~18.04","11.0.14+9-0ubuntu2~18.04","11.0.14.1+1-0ubuntu1~18.04","11.0.15+10-0ubuntu0.18.04.1","11.0.16+8-0ubuntu1~18.04","11.0.17+8-1ubuntu2~18.04","11.0.18+10-0ubuntu1~18.04.1","11.0.19+7~us1-0ubuntu1~18.04.1","11.0.20+8-1ubuntu1~18.04"],"ecosystem_specific":{"availability":"Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro","binaries":[{"binary_version":"11.0.20.1+1-0ubuntu1~18.04","binary_name":"openjdk-11-demo"},{"binary_version":"11.0.20.1+1-0ubuntu1~18.04","binary_name":"openjdk-11-jdk"},{"binary_version":"11.0.20.1+1-0ubuntu1~18.04","binary_name":"openjdk-11-jdk-headless"},{"binary_version":"11.0.20.1+1-0ubuntu1~18.04","binary_name":"openjdk-11-jre"},{"binary_version":"11.0.20.1+1-0ubuntu1~18.04","binary_name":"openjdk-11-jre-headless"},{"binary_version":"11.0.20.1+1-0ubuntu1~18.04","binary_name":"openjdk-11-jre-zero"},{"binary_version":"11.0.20.1+1-0ubuntu1~18.04","binary_name":"openjdk-11-source"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-6263-2.json","cves_map":{"ecosystem":"Ubuntu:Pro:18.04:LTS","cves":[]}}},{"package":{"name":"openjdk-17","ecosystem":"Ubuntu:Pro:18.04:LTS","purl":"pkg:deb/ubuntu/openjdk-17@17.0.8.1+1~us1-0ubuntu1~18.04?arch=source&distro=esm-apps/bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"17.0.8.1+1~us1-0ubuntu1~18.04"}]}],"versions":["17+35-1~18.04","17.0.1+12-1~18.04","17.0.2+8-1~18.04","17.0.3+7-0ubuntu0.18.04.1","17.0.4+8-1~18.04","17.0.5+8-2ubuntu1~18.04","17.0.6+10-0ubuntu1~18.04.1","17.0.7+7~us1-0ubuntu1~18.04","17.0.8+7-1~18.04"],"ecosystem_specific":{"availability":"Available with Ubuntu Pro: https://ubuntu.com/pro","binaries":[{"binary_version":"17.0.8.1+1~us1-0ubuntu1~18.04","binary_name":"openjdk-17-demo"},{"binary_version":"17.0.8.1+1~us1-0ubuntu1~18.04","binary_name":"openjdk-17-jdk"},{"binary_version":"17.0.8.1+1~us1-0ubuntu1~18.04","binary_name":"openjdk-17-jdk-headless"},{"binary_version":"17.0.8.1+1~us1-0ubuntu1~18.04","binary_name":"openjdk-17-jre"},{"binary_version":"17.0.8.1+1~us1-0ubuntu1~18.04","binary_name":"openjdk-17-jre-headless"},{"binary_version":"17.0.8.1+1~us1-0ubuntu1~18.04","binary_name":"openjdk-17-jre-zero"},{"binary_version":"17.0.8.1+1~us1-0ubuntu1~18.04","binary_name":"openjdk-17-source"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-6263-2.json","cves_map":{"ecosystem":"Ubuntu:Pro:18.04:LTS","cves":[]}}},{"package":{"name":"openjdk-17","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/openjdk-17@17.0.8.1+1~us1-0ubuntu1~20.04?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"17.0.8.1+1~us1-0ubuntu1~20.04"}]}],"versions":["17+35-1~20.04","17.0.1+12-1~20.04","17.0.2+8-1~20.04","17.0.3+7-0ubuntu0.20.04.1","17.0.4+8-1~20.04","17.0.5+8-2ubuntu1~20.04","17.0.6+10-0ubuntu1~20.04.1","17.0.7+7~us1-0ubuntu1~20.04","17.0.8+7-1~20.04.2"],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_version":"17.0.8.1+1~us1-0ubuntu1~20.04","binary_name":"openjdk-17-demo"},{"binary_version":"17.0.8.1+1~us1-0ubuntu1~20.04","binary_name":"openjdk-17-jdk"},{"binary_version":"17.0.8.1+1~us1-0ubuntu1~20.04","binary_name":"openjdk-17-jdk-headless"},{"binary_version":"17.0.8.1+1~us1-0ubuntu1~20.04","binary_name":"openjdk-17-jre"},{"binary_version":"17.0.8.1+1~us1-0ubuntu1~20.04","binary_name":"openjdk-17-jre-headless"},{"binary_version":"17.0.8.1+1~us1-0ubuntu1~20.04","binary_name":"openjdk-17-jre-zero"},{"binary_version":"17.0.8.1+1~us1-0ubuntu1~20.04","binary_name":"openjdk-17-source"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-6263-2.json","cves_map":{"ecosystem":"Ubuntu:20.04:LTS","cves":[]}}},{"package":{"name":"openjdk-lts","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/openjdk-lts@11.0.20.1+1-0ubuntu1~20.04?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"11.0.20.1+1-0ubuntu1~20.04"}]}],"versions":["11.0.5+10-0ubuntu1","11.0.5+10-2ubuntu1","11.0.6+10-1ubuntu1","11.0.6+10-2ubuntu2","11.0.7+9-1ubuntu1","11.0.7+10-2ubuntu1","11.0.7+10-3ubuntu1","11.0.8+10-0ubuntu1~20.04","11.0.9+11-0ubuntu1~20.04","11.0.9.1+1-0ubuntu1~20.04","11.0.10+9-0ubuntu1~20.04","11.0.11+9-0ubuntu2~20.04","11.0.13+8-0ubuntu1~20.04","11.0.14+9-0ubuntu2~20.04","11.0.14.1+1-0ubuntu1~20.04","11.0.15+10-0ubuntu0.20.04.1","11.0.16+8-0ubuntu1~20.04","11.0.17+8-1ubuntu2~20.04","11.0.18+10-0ubuntu1~20.04.1","11.0.19+7~us1-0ubuntu1~20.04.1","11.0.20+8-1ubuntu1~20.04"],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_version":"11.0.20.1+1-0ubuntu1~20.04","binary_name":"openjdk-11-demo"},{"binary_version":"11.0.20.1+1-0ubuntu1~20.04","binary_name":"openjdk-11-jdk"},{"binary_version":"11.0.20.1+1-0ubuntu1~20.04","binary_name":"openjdk-11-jdk-headless"},{"binary_version":"11.0.20.1+1-0ubuntu1~20.04","binary_name":"openjdk-11-jre"},{"binary_version":"11.0.20.1+1-0ubuntu1~20.04","binary_name":"openjdk-11-jre-headless"},{"binary_version":"11.0.20.1+1-0ubuntu1~20.04","binary_name":"openjdk-11-jre-zero"},{"binary_version":"11.0.20.1+1-0ubuntu1~20.04","binary_name":"openjdk-11-source"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-6263-2.json","cves_map":{"ecosystem":"Ubuntu:20.04:LTS","cves":[]}}},{"package":{"name":"openjdk-17","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/openjdk-17@17.0.8.1+1~us1-0ubuntu1~22.04?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"17.0.8.1+1~us1-0ubuntu1~22.04"}]}],"versions":["17+35-1","17.0.1+12-1","17.0.2+8-1","17.0.3+7-0ubuntu0.22.04.1","17.0.4+8-1~22.04","17.0.5+8-2ubuntu1~22.04","17.0.6+10-0ubuntu1~22.04","17.0.7+7~us1-0ubuntu1~22.04.2","17.0.8+7-1~22.04"],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_version":"17.0.8.1+1~us1-0ubuntu1~22.04","binary_name":"openjdk-17-demo"},{"binary_version":"17.0.8.1+1~us1-0ubuntu1~22.04","binary_name":"openjdk-17-jdk"},{"binary_version":"17.0.8.1+1~us1-0ubuntu1~22.04","binary_name":"openjdk-17-jdk-headless"},{"binary_version":"17.0.8.1+1~us1-0ubuntu1~22.04","binary_name":"openjdk-17-jre"},{"binary_version":"17.0.8.1+1~us1-0ubuntu1~22.04","binary_name":"openjdk-17-jre-headless"},{"binary_version":"17.0.8.1+1~us1-0ubuntu1~22.04","binary_name":"openjdk-17-jre-zero"},{"binary_version":"17.0.8.1+1~us1-0ubuntu1~22.04","binary_name":"openjdk-17-source"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-6263-2.json","cves_map":{"ecosystem":"Ubuntu:22.04:LTS","cves":[]}}},{"package":{"name":"openjdk-lts","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/openjdk-lts@11.0.20.1+1-0ubuntu1~22.04?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"11.0.20.1+1-0ubuntu1~22.04"}]}],"versions":["11.0.12+7-0ubuntu3","11.0.13+8-0ubuntu1","11.0.14+9-0ubuntu2","11.0.14.1+1-0ubuntu1","11.0.15+10-0ubuntu0.22.04.1","11.0.16+8-0ubuntu1~22.04","11.0.17+8-1ubuntu2~22.04","11.0.18+10-0ubuntu1~22.04","11.0.19+7~us1-0ubuntu1~22.04.1","11.0.20+8-1ubuntu1~22.04"],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_version":"11.0.20.1+1-0ubuntu1~22.04","binary_name":"openjdk-11-demo"},{"binary_version":"11.0.20.1+1-0ubuntu1~22.04","binary_name":"openjdk-11-jdk"},{"binary_version":"11.0.20.1+1-0ubuntu1~22.04","binary_name":"openjdk-11-jdk-headless"},{"binary_version":"11.0.20.1+1-0ubuntu1~22.04","binary_name":"openjdk-11-jre"},{"binary_version":"11.0.20.1+1-0ubuntu1~22.04","binary_name":"openjdk-11-jre-headless"},{"binary_version":"11.0.20.1+1-0ubuntu1~22.04","binary_name":"openjdk-11-jre-zero"},{"binary_version":"11.0.20.1+1-0ubuntu1~22.04","binary_name":"openjdk-11-source"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-6263-2.json","cves_map":{"ecosystem":"Ubuntu:22.04:LTS","cves":[]}}}],"schema_version":"1.7.3"}