[Bug 1204703] VUL-0: CVE-2022-3676: In Eclipse Openj9 before version 0.35.0, interface calls can be inlined without a runtime type check. Malicious bytecode could make use of this inlining to access or modify memory via an incompatible type.
https://bugzilla.suse.com/show_bug.cgi?id=1204703 https://bugzilla.suse.com/show_bug.cgi?id=1204703#c3 --- Comment #3 from Swamp Workflow Management <swamp@suse.de> --- SUSE-SU-2022:4250-1: An update that fixes 5 vulnerabilities is now available. Category: security (important) Bug References: 1204471,1204472,1204473,1204475,1204703 CVE References: CVE-2022-21619,CVE-2022-21624,CVE-2022-21626,CVE-2022-21628,CVE-2022-3676 JIRA References: Sources used: openSUSE Leap 15.4 (src): java-1_8_0-openj9-1.8.0.352-150200.3.27.1 openSUSE Leap 15.3 (src): java-1_8_0-openj9-1.8.0.352-150200.3.27.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination. -- You are receiving this mail because: You are on the CC list for the bug.
participants (1)
-
bugzilla_noreply@suse.com