We are happy to announce the general availability of Liberica Native Image Kit (NIK) version 22.3.1 as part of Critical Patch Update (CPU) release cycle. The builds contain several security fixes and enhancements.
Note that Liberica NIK releases are aligned with GraalVM release schedule, which underwent essential changes in 2023. GraalVM feature releases were previously issued every three months. Starting with JDK 20 release in March 2023, GraalVM CE will conform to the six-month JDK release cadence. CPU builds will see the light four times a year as before.
New release calendar is as follows. For more information, consult the GraalVM website.
Date |
Version |
Type |
Name |
January 24, 2023 |
22.3.1 |
CPU | |
March 21, 2023 |
23.0.0 |
Feature |
GraalVM for JDK 20 |
April 18, 2023 |
23.0.1, 22.3.2 |
CPU | |
July 18, 2023 |
23.0.2, 22.3.3 |
CPU | |
September 19, 2023 |
23.1.0 |
Feature |
GraalVM for JDK 21 |
All Liberica NIK builds contain the latest version of Liberica JDK with fixes and eliminated security issues.
Summary of fixes and enhancements
Important changes
We enabled the cross-compilation of musl-based Linux static images. Static native images are created by statically linking against musl, a lightweight C library implementation. They are smaller in size and start up faster. The native-image
can produce both static and dynamic musl-based images.
List of security issues fixed
CVE ID |
cvss score |
component |
module |
Attack vector (network/local) |
Complexity (low/high) |
Privileges (none/low) |
User interaction (none/required) |
Scope (changed/unchanged) |
Confidentiality (low/none/high) |
Integrity (low/none/high) |
Availability (low/none/high) |
CVE-2023-21835 |
5.3 |
security-libs |
javax.net.ssl |
network |
low |
none |
none |
unchanged |
none |
none |
low |
CVE-2023-21830 |
5.3 |
other-libs |
- |
network |
low |
none |
none |
unchanged |
none |
low |
none |
CVE-2023-21843 |
3.7 |
client-libs |
javax.sound |
network |
high |
none |
none |
unchanged |
none |
low |
none |
Conclusion
BellSoft strives to provide Java developers with a full stack of secure and affordable technologies suitable for creating a wide range of applications. And thanks to the CPU release cycle, your applications will be secure at all times. Download the latest version of Liberica NIK now!