Debian 9906 Published by

An openjdk-8 security update has been released for Debian GNU/Linux 8 Extended LTS to address several vulnerabilities.



ELA-474-1 openjdk-8 security update

Package openjdk-8
Version 8u302-b08-1~deb8u1
Related CVEs CVE-2021-2341 CVE-2021-2369 CVE-2021-2388

Several vulnerabilities have been discovered in the OpenJDK Java runtime, resulting in bypass of sandbox restrictions, incorrect validation of signed Jars or information disclosure.

Thanks to Thorsten Glaser and ⮡ tarent for contributing the updated packages to address these vulnerabilities.

For Debian 8 jessie, these problems have been fixed in version 8u302-b08-1~deb8u1.

We recommend that you upgrade your openjdk-8 packages.

Further information about Extended LTS security advisories can be found at: https://deb.freexian.com/extended-lts/

  ELA-474-1 openjdk-8 security update