{
  "document": {
    "aggregate_severity": {
      "text": "Medium"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_os/tuxcare9.6esu/vex/2023/cve-2023-22067-els_os-tuxcare9_6esu.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-04-17T11:04:07Z",
      "generator": {
        "date": "2026-04-17T11:04:07Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CVE-2023-22067-ELS_OS-TUXCARE9.6ESU",
      "initial_release_date": "2023-10-17T20:00:00Z",
      "revision_history": [
        {
          "date": "2023-10-17T20:00:00Z",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-04-13T09:03:18Z",
          "number": "2",
          "summary": "Official Publication"
        },
        {
          "date": "2026-04-17T11:04:07Z",
          "number": "3",
          "summary": "Update document"
        }
      ],
      "status": "final",
      "version": "3"
    },
    "title": "Security update on CVE-2023-22067"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "AlmaLinux 9.6",
                "product": {
                  "name": "AlmaLinux 9.6",
                  "product_id": "AlmaLinux-9.6",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:almalinux:almalinux:9.6:*:*:*:*:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "AlmaLinux"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "java-1.8.0-openjdk-src-fastdebug-1:1.8.0.482.b08-1.el9.alma.1.x86_64",
                "product": {
                  "name": "java-1.8.0-openjdk-src-fastdebug-1:1.8.0.482.b08-1.el9.alma.1.x86_64",
                  "product_id": "java-1.8.0-openjdk-src-fastdebug-1:1.8.0.482.b08-1.el9.alma.1.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/almalinux/java-1.8.0-openjdk-src-fastdebug@1.8.0.482.b08-1.el9.alma.1?arch=x86_64&epoch=1"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          }
        ],
        "category": "vendor",
        "name": "AlmaLinux OS Foundation"
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Rocky Linux 9.6",
                "product": {
                  "name": "Rocky Linux 9.6",
                  "product_id": "Rocky Linux-9.6",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:resf:rocky_linux:9.6:*:*:*:*:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Rocky Linux"
          }
        ],
        "category": "vendor",
        "name": "Rocky Linux"
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "java-1.8.0-openjdk-src-fastdebug-1:1.8.0.482.b08-1.el9.alma.1.tuxcare.els1.x86_64",
                "product": {
                  "name": "java-1.8.0-openjdk-src-fastdebug-1:1.8.0.482.b08-1.el9.alma.1.tuxcare.els1.x86_64",
                  "product_id": "java-1.8.0-openjdk-src-fastdebug-1:1.8.0.482.b08-1.el9.alma.1.tuxcare.els1.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/java-1.8.0-openjdk-src-fastdebug@1.8.0.482.b08-1.el9.alma.1.tuxcare.els1?arch=x86_64&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "java-17-openjdk-headless-slowdebug-1:17.0.18.0.8-1.el9.tuxcare.els1.x86_64",
                "product": {
                  "name": "java-17-openjdk-headless-slowdebug-1:17.0.18.0.8-1.el9.tuxcare.els1.x86_64",
                  "product_id": "java-17-openjdk-headless-slowdebug-1:17.0.18.0.8-1.el9.tuxcare.els1.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/java-17-openjdk-headless-slowdebug@17.0.18.0.8-1.el9.tuxcare.els1?arch=x86_64&epoch=1"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          }
        ],
        "category": "vendor",
        "name": "TuxCare"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "java-1.8.0-openjdk-src-fastdebug-1:1.8.0.482.b08-1.el9.alma.1.tuxcare.els1.x86_64 as a component of AlmaLinux 9.6",
          "product_id": "AlmaLinux-9.6:java-1.8.0-openjdk-src-fastdebug-1:1.8.0.482.b08-1.el9.alma.1.tuxcare.els1.x86_64"
        },
        "product_reference": "java-1.8.0-openjdk-src-fastdebug-1:1.8.0.482.b08-1.el9.alma.1.tuxcare.els1.x86_64",
        "relates_to_product_reference": "AlmaLinux-9.6"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "java-1.8.0-openjdk-src-fastdebug-1:1.8.0.482.b08-1.el9.alma.1.tuxcare.els1.x86_64 as a component of Rocky Linux 9.6",
          "product_id": "Rocky Linux-9.6:java-1.8.0-openjdk-src-fastdebug-1:1.8.0.482.b08-1.el9.alma.1.tuxcare.els1.x86_64"
        },
        "product_reference": "java-1.8.0-openjdk-src-fastdebug-1:1.8.0.482.b08-1.el9.alma.1.tuxcare.els1.x86_64",
        "relates_to_product_reference": "Rocky Linux-9.6"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "java-17-openjdk-headless-slowdebug-1:17.0.18.0.8-1.el9.tuxcare.els1.x86_64 as a component of AlmaLinux 9.6",
          "product_id": "AlmaLinux-9.6:java-17-openjdk-headless-slowdebug-1:17.0.18.0.8-1.el9.tuxcare.els1.x86_64"
        },
        "product_reference": "java-17-openjdk-headless-slowdebug-1:17.0.18.0.8-1.el9.tuxcare.els1.x86_64",
        "relates_to_product_reference": "AlmaLinux-9.6"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "java-17-openjdk-headless-slowdebug-1:17.0.18.0.8-1.el9.tuxcare.els1.x86_64 as a component of Rocky Linux 9.6",
          "product_id": "Rocky Linux-9.6:java-17-openjdk-headless-slowdebug-1:17.0.18.0.8-1.el9.tuxcare.els1.x86_64"
        },
        "product_reference": "java-17-openjdk-headless-slowdebug-1:17.0.18.0.8-1.el9.tuxcare.els1.x86_64",
        "relates_to_product_reference": "Rocky Linux-9.6"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "java-1.8.0-openjdk-src-fastdebug-1:1.8.0.482.b08-1.el9.alma.1.x86_64 as a component of AlmaLinux 9.6",
          "product_id": "AlmaLinux-9.6:java-1.8.0-openjdk-src-fastdebug-1:1.8.0.482.b08-1.el9.alma.1.x86_64"
        },
        "product_reference": "java-1.8.0-openjdk-src-fastdebug-1:1.8.0.482.b08-1.el9.alma.1.x86_64",
        "relates_to_product_reference": "AlmaLinux-9.6"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "java-1.8.0-openjdk-src-fastdebug-1:1.8.0.482.b08-1.el9.alma.1.x86_64 as a component of Rocky Linux 9.6",
          "product_id": "Rocky Linux-9.6:java-1.8.0-openjdk-src-fastdebug-1:1.8.0.482.b08-1.el9.alma.1.x86_64"
        },
        "product_reference": "java-1.8.0-openjdk-src-fastdebug-1:1.8.0.482.b08-1.el9.alma.1.x86_64",
        "relates_to_product_reference": "Rocky Linux-9.6"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2023-22067",
      "cwe": {
        "id": "CWE-502",
        "name": "Deserialization of Untrusted Data"
      },
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: CORBA).  Supported versions that are affected are Oracle Java SE: 8u381, 8u381-perf; Oracle GraalVM Enterprise Edition: 20.3.11 and  21.3.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via CORBA to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.1 Base Score 5.3 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N).",
          "title": "Vulnerability description"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "AlmaLinux-9.6:java-1.8.0-openjdk-src-fastdebug-1:1.8.0.482.b08-1.el9.alma.1.tuxcare.els1.x86_64",
          "Rocky Linux-9.6:java-1.8.0-openjdk-src-fastdebug-1:1.8.0.482.b08-1.el9.alma.1.tuxcare.els1.x86_64"
        ],
        "known_affected": [
          "AlmaLinux-9.6:java-1.8.0-openjdk-src-fastdebug-1:1.8.0.482.b08-1.el9.alma.1.x86_64",
          "Rocky Linux-9.6:java-1.8.0-openjdk-src-fastdebug-1:1.8.0.482.b08-1.el9.alma.1.x86_64"
        ],
        "under_investigation": [
          "AlmaLinux-9.6:java-17-openjdk-headless-slowdebug-1:17.0.18.0.8-1.el9.tuxcare.els1.x86_64",
          "Rocky Linux-9.6:java-17-openjdk-headless-slowdebug-1:17.0.18.0.8-1.el9.tuxcare.els1.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2023-22067"
        }
      ],
      "release_date": "2023-10-17T20:00:00Z",
      "remediations": [
        {
          "category": "none_available",
          "details": "Affected",
          "product_ids": [
            "AlmaLinux-9.6:java-1.8.0-openjdk-src-fastdebug-1:1.8.0.482.b08-1.el9.alma.1.x86_64",
            "AlmaLinux-9.6:java-17-openjdk-headless-slowdebug-1:17.0.18.0.8-1.el9.tuxcare.els1.x86_64",
            "Rocky Linux-9.6:java-1.8.0-openjdk-src-fastdebug-1:1.8.0.482.b08-1.el9.alma.1.x86_64",
            "Rocky Linux-9.6:java-17-openjdk-headless-slowdebug-1:17.0.18.0.8-1.el9.tuxcare.els1.x86_64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "LOW",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "AlmaLinux-9.6:java-1.8.0-openjdk-src-fastdebug-1:1.8.0.482.b08-1.el9.alma.1.tuxcare.els1.x86_64",
            "AlmaLinux-9.6:java-1.8.0-openjdk-src-fastdebug-1:1.8.0.482.b08-1.el9.alma.1.x86_64",
            "AlmaLinux-9.6:java-17-openjdk-headless-slowdebug-1:17.0.18.0.8-1.el9.tuxcare.els1.x86_64",
            "Rocky Linux-9.6:java-1.8.0-openjdk-src-fastdebug-1:1.8.0.482.b08-1.el9.alma.1.tuxcare.els1.x86_64",
            "Rocky Linux-9.6:java-1.8.0-openjdk-src-fastdebug-1:1.8.0.482.b08-1.el9.alma.1.x86_64",
            "Rocky Linux-9.6:java-17-openjdk-headless-slowdebug-1:17.0.18.0.8-1.el9.tuxcare.els1.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    }
  ]
}