Alerts This Week
Warning Icon 1 681
Alerts This Week
Warning Icon 1 681

Fedora 30: FEDORA-2019-f36ac0db92 Critical: java-11-openjdk DoS

fedora
Calendar Grey October 21, 2019
Dist Fedora Esm H88
Critical update for Fedora 30 addresses a DoS threat in java-11-openjdk. Upgrade advised for system integrity.
Update to OpenJDK October CPU (security update)

Summary

The OpenJDK runtime environment.

Update to OpenJDK October CPU (security update). See:

https://openjdk.org/groups/vulnerability/advisories/2019-10-15

https://mail.openjdk.org/pipermail/jdk-updates-dev/2019-October/002025.html

* Wed Oct 9 2019 Andrew Hughes - 1:11.0.5.10-0

- Update to shenandoah-jdk-11.0.5+10 (GA)

- Switch to GA mode for final release.

* Mon Oct 7 2019 Andrew Hughes - 1:11.0.5.9-0.0.ea

- Update to shenandoah-jdk-11.0.5+9 (EA)

* Tue Aug 27 2019 Andrew Hughes - 1:11.0.5.2-0.2.ea

- Update generate_source_tarball.sh script to use the PR3751 patch and retain the secp256k1 curve.

- Regenerate source tarball using the updated script and add the -'4curve' suffix.

- PR3751 includes the changes in the PR1834/RH1022017 patch which is removed.

* Sat Aug 24 2019 Andrew John Hughes - 1:11.0.5.2-0.1.ea

- Update to shenandoah-jdk-11.0.5+2 (EA)

* Mon Aug 12 2019 Andrew Hughes - 1:11.0.5.1-0.1.ea

- Update to shenandoah-jdk-11.0.5+1 (EA)

- Switch to EA mode for 11.0.5 pre-release builds.

* Thu Aug 8 2019 Andrew Hughes - 1:11.0.4.11-4

- Switch to in-tree SunEC code, dropping NSS runtime dependencies and patches to link against it.

* Fri Jul 26 2019 Andrew John Hughes - 1:11.0.4.11-3

- Drop unnecessary build requirement on gtk3-devel, as OpenJDK searches for Gtk+ at runtime.

- Add missing build requirement for libXrender-devel, previously masked by Gtk3+ dependency

- Add missing build requirement for libXrandr-devel, previously masked by Gtk3+ dependency

- fontconfig build requirement should be fontconfig-devel, previously masked by Gtk3+ dependency

* Fri Jul 26 2019 Severin Gehwolf - 1:11.0.4.11-2

- Rebuild with itself as boot JDK.

* Fri Jul 26 2019 Severin Gehwolf - 1:11.0.4.11-1

- Remove -fno-tree-ch workaround for i686 as the root cause has been

fixed with 11.0.4+9.

- Resolves RHBZ#1683095

* Tue Jul 9 2019 Andrew Hughes - 1:11.0.4.11-0

- Update to shenandoah-jdk-11.0.4+11 (GA)

- Switch to GA mode for final release.

* Mon Jul 8 2019 Andrew Hughes - 1:11.0.4.10-0.2.ea

- Obsolete javadoc-slowdebug and javadoc-slowdebug-zip packages via javadoc and javadoc-zip respectively.

* Mon Jul 8 2019 Andrew Hughes - 1:11.0.4.10-0.1.ea

- Update to shenandoah-jdk-11.0.4+10 (EA)

* Sun Jun 30 2019 Andrew John Hughes - 1:11.0.4.2-0.1.ea

- Update to shenandoah-jdk-11.0.4+2 (EA)

* Fri Jun 21 2019 Severin Gehwolf - 1:11.0.4.2-0.1.ea

- Package jspawnhelper (see JDK-8220360).

* Fri Jun 21 2019 Severin Gehwolf - 1:11.0.3.7-6

- Include 'ea' designator in Release when appropriate.

* Wed May 22 2019 Andrew Hughes - 1:11.0.3.7-6

- Handle milestone as variables so we can alter it easily and set the docs zip filename appropriately.

* Tue May 14 2019 Severin Gehwolf - 1:11.0.3.7-5

- Bump release for rebuild.

* Fri May 10 2019 Severin Gehwolf - 1:11.0.3.7-4

- Add -fno-tree-ch in order to work around GCC 9 issue on

i686.

- Resolves: RHBZ#1683095

* Thu Apr 25 2019 Severin Gehwolf - 1:11.0.3.7-3

- Don't produce javadoc/javadoc-zip sub packages for the

debug variant build.

- Don't perform a bootcycle build for the debug variant build.

* Wed Apr 24 2019 Severin Gehwolf - 1:11.0.3.7-2

- Don't generate lib-style requires for -slowdebug subpackages.

- Resolves: RHBZ#1702379

* Tue Apr 23 2019 Severin Gehwolf - 1:11.0.3.7-1

- Fix requires/provides for the non-system JDK case. JDK 11

isn't a system JDK at this point.

- Resolves: RHBZ#1702324

* Sun Apr 7 2019 Andrew Hughes - 1:11.0.3.7-0

- Update to shenandoah-jdk-11.0.3+7 (April 2019 GA)

* Sat Apr 6 2019 Andrew Hughes - 1:11.0.3.6-0

- Update to shenandoah-jdk-11.0.3+6 (April 2019 EA)

- Drop JDK-8210416/RH1632174 applied upstream.

- Drop JDK-8210425/RH1632174 applied upstream.

- Drop JDK-8210647/RH1632174 applied upstream.

- Drop JDK-8210761/RH1632174 applied upstream.

- Drop JDK-8210703/RH1632174 applied upstream.

- Add cast to resolve s390 ambiguity in call to log2_intptr

* Thu Mar 21 2019 Severin Gehwolf - 1:11.0.2.7-9

- Add patch for RH1566890

* Wed Mar 20 2019 Peter Robinson 1:11.0.2.7-8

- Drop chkconfig dep, 1.7 shipped in f24

[ 1 ] Bug #1683095 - [F30] java-11-openjdk intermittently FTBFS on i686 in G1 code due to a race condition

https://bugzilla.redhat.com/show_bug.cgi?id=1683095

su -c 'dnf upgrade --advisory FEDORA-2019-f36ac0db92' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 30
Version: 11.0.5.10
Release: 0.fc30
Summary: OpenJDK Runtime Environment 11

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here