Announcements

Liberica Native Image Kit 22.3.1 builds are released

Jan 30, 2023
Peter Zhelezniakov
2.3

We are happy to announce the general availability of Liberica Native Image Kit (NIK) version 22.3.1 as part of Critical Patch Update (CPU) release cycle. The builds contain several security fixes and enhancements.

Note that Liberica NIK releases are aligned with GraalVM release schedule, which underwent essential changes in 2023. GraalVM feature releases were previously issued every three months. Starting with JDK 20 release in March 2023, GraalVM CE will conform to the six-month JDK release cadence. CPU builds will see the light four times a year as before.

New release calendar is as follows. For more information, consult the GraalVM website.

Date

Version

Type

Name

January 24, 2023

22.3.1

CPU

 

March 21, 2023

23.0.0

Feature

GraalVM for JDK 20

April 18, 2023

23.0.1, 22.3.2

CPU

 

July 18, 2023

23.0.2, 22.3.3

CPU

 

September 19, 2023

23.1.0

Feature

GraalVM for JDK 21

All Liberica NIK builds contain the latest version of Liberica JDK with fixes and eliminated security issues.

Summary of fixes and enhancements

Important changes

We enabled the cross-compilation of musl-based Linux static images. Static native images are created by statically linking against musl, a lightweight C library implementation. They are smaller in size and start up faster. The native-image can produce both static and dynamic musl-based images.  

List of security issues fixed

CVE ID

cvss score

component

module

Attack vector (network/local)

Complexity (low/high)

Privileges (none/low)

User interaction (none/required)

Scope (changed/unchanged)

Confidentiality (low/none/high)

Integrity (low/none/high)

Availability (low/none/high)

CVE-2023-21835

5.3

security-libs

javax.net.ssl

network

low

none

none

unchanged

none

none

low

CVE-2023-21830

5.3

other-libs

-

network

low

none

none

unchanged

none

low

none

CVE-2023-21843

3.7

client-libs

javax.sound

network

high

none

none

unchanged

none

low

none

Conclusion

BellSoft strives to provide Java developers with a full stack of secure and affordable technologies suitable for creating a wide range of applications. And thanks to the CPU release cycle, your applications will be secure at all times. Download the latest version of Liberica NIK now!

Download Liberica NIK

Subcribe to our newsletter

figure

Read the industry news, receive solutions to your problems, and find the ways to save money.

Further reading