Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Fedora 32: FEDORA-2020-a405eea76a High: OpenJDK 8u272 Security Update

fedora
Calendar Grey October 30, 2020
Dist Fedora Esm H88
OpenJDK 8u282 for Fedora 32 resolves critical vulnerabilities and introduces enhanced TLSv1.3 protocol support.
New in release OpenJDK 8u272 (2020-10-20): notes can be found at: * https://mail.openjdk.org/pipermail/jdk8u-dev/2020-October/012817.html * https://builds.shipilev.net/backports-mo...

Summary

The OpenJDK runtime environment 8.

New in release OpenJDK 8u272 (2020-10-20):

=========================================== Full versions of these release

notes can be found at: * https://mail.openjdk.org/pipermail/jdk8u-dev/2020-October/012817.html *

https://builds.shipilev.net/backports-monitor/release-notes-openjdk8u272.txt ##

New features * JDK-8245468: Add TLSv1.3 implementation classes from 11.0.7 ##

Security fixes - JDK-8233624: Enhance JNI linkage - JDK-8236196: Improve

string pooling - JDK-8236862, CVE-2020-14779: Enhance support of Proxy class

- JDK-8237990, CVE-2020-14781: Enhanced LDAP contexts - JDK-8237995,

CVE-2020-14782: Enhance certificate processing - JDK-8240124: Better VM

Interning - JDK-8241114, CVE-2020-14792: Better range handling -JDK-8242680, CVE-2020-14796: Improved URI Support - JDK-8242685,

CVE-2020-14797: Better Path Validation - JDK-8242695, CVE-2020-14798: Enhanced

buffer support - JDK-8243302: Advanced class supports - JDK-8244136,

CVE-2020-14803: Improved Buffer supports - JDK-8244479: Further constrain

certificates - JDK-8244955: Additional Fix for JDK-8240124 - JDK-8245407:

Enhance zoning of times - JDK-8245412: Better class definitions -JDK-8245417: Improve certificate chain handling - JDK-8248574: Improve jpeg

processing - JDK-8249927: Specify limits of jdk.serialProxyInterfaceLimit -JDK-8253019: Enhanced JPEG decoding ## JDK-8254177: US/Pacific-New Zone name

removed as part of tzdata2020b Following JDK's update to tzdata2020b, the long-obsolete files pacificnew and systemv have been removed. As a result, the

"US/Pacific-New" zone name declared in the pacificnew data file is no longer

available for use. Information regarding the update can be viewed at

https://mm.icann.org/pipermail/tz-announce/2020-October/000059.html

* Wed Oct 21 2020 Andrew Hughes - 1:1.8.0.272.b10-0

- Update to aarch64-shenandoah-jdk8u272-b10.

- Test build JDK is usable by running 'java -version'.

- JFR must now be explicitly disabled when unwanted (e.g. x86), following switch of upstream default.

- Remove JDK-8154313 backport now applied upstream.

- Change target from 'zip-docs' to 'docs-zip', which is the naming used upstream.

- Remove "-fcommon" following GCC 10 fixes upstream (JDK-8238380, JDK-8238386, JDK-8238388)

- Update tarball generation script to use PR3795, following inclusion of JDK-8177334

- Add additional s390 size_t case in g1ConcurrentMarkObjArrayProcessor.cpp introduced by JDK-8057003

- Add additional s390 log2_intptr case in shenandoahUtils.cpp introduced by JDK-8245464

- Update tarball generation script to use PR3799, following inclusion of JDK-8245468 (TLSv1.3)

- Update release notes for 8u272 release.

- Add backport of JDK-8254177 to update to tzdata 2020b

- Require tzdata 2020b due to resource changes in JDK-8254177

- Temporarily roll back tzdata build requirement while tzdata update is still in testing

- Adjust JDK-8062808/PR3548 following constantPool.hpp context change in JDK-8243302

- Adjust PR3593 following g1StringDedupTable.cpp context change in JDK-8240124 & JDK-8244955

* Wed Aug 5 2020 Severin Gehwolf - 1:1.8.0.272.b01-0.1.ea

- Fix vendor name to include '.': Red Hat, Inc => Red Hat, Inc.

su -c 'dnf upgrade --advisory FEDORA-2020-a405eea76a' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Change Log

References

Update Instructions

Severity
important
Lowest
Low
Medium
High
Critical

Product: Fedora 32
Version: 1.8.0.272.b10
Release: 0.fc32
Summary: OpenJDK Runtime Environment 8

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here