Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Fedora 35 FEDORA-2021-107c8c5063 Critical: OpenJDK Security Issues

fedora
Calendar Grey October 29, 2021
Dist Fedora Esm H88
Recent improvements and patches addressing potential vulnerabilities in OpenJDK 8u312 on Fedora 35. Crucial for every Java programmer.
# New in release OpenJDK 8u312 (2021-10-19): Live versions of these release notes can be found at: * https://mail.openjdk.org/pipermail/jdk8u-dev/2021-October/014373.html * https:/...

Summary

The OpenJDK 8 runtime environment.

# New in release OpenJDK 8u312 (2021-10-19): Live versions of these release

notes can be found at: * https://mail.openjdk.org/pipermail/jdk8u-dev/2021-October/014373.html *

https://builds.shipilev.net/backports-monitor/release-notes-openjdk8u312.txt ##

Security fixes * JDK-8130183, CVE-2021-35588: InnerClasses: VM permits wrong

Throw ClassFormatError if InnerClasses attribute's inner_class_info_index is 0 *

JDK-8161016: Strange behavior of URLConnection with proxy * JDK-8163326,

CVE-2021-35550: Update the default enabled cipher suites preference *

JDK-8254967, CVE-2021-35565: com.sun.net.HttpsServer spins on TLS session close

* JDK-8263314: Enhance XML Dsig modes * JDK-8265167, CVE-2021-35556: Richer Text

Editors * JDK-8265574: Improve handling of sheets * JDK-8265580,

CVE-2021-35559: Enhanced style for RTF kit * JDK-8265776: Improve Stream

handling for SSL * JDK-8266097, CVE-2021-35561: Better hashing support *

JDK-8266103: Better specified spec values * JDK-8266109: More Resilient

Classloading - JDK-8266115: More Manifest Jar Loading - JDK-8266137,

CVE-2021-35564: Improve Keystore integrity - JDK-8266689, CVE-2021-35567: More

Constrained Delegation - JDK-8267086: ArrayIndexOutOfBoundsException in

java.security.KeyFactory.generatePublic - JDK-8267712: Better LDAP reference

processing - JDK-8267729, CVE-2021-35578: Improve TLS client handshaking -JDK-8267735, CVE-2021-35586: Better BMP support - JDK-8268193: Improve

requests of certificates - JDK-8268199: Correct certificate requests -JDK-8268506: More Manifest Digests - JDK-8269618, CVE-2021-35603: Better

session identification - JDK-8269624: Enhance method selection support -JDK-8270398: Enhance canonicalization - JDK-8270404: Better canonicalization

## Major Changes -[JDK-8164200](https://bugs.openjdk.org/browse/JDK-8164200): Modified

HttpURLConnection behavior when no suitable proxy is found -[JDK-8219551](https://bugs.openjdk.org/browse/JDK-8219551): Updated the

Default Enabled Cipher Suites Preference ## FIPS Mode Changes - FIPS mode

detection now takes place via a call to the NSS library - The `SunPKCS11`

provider in FIPS mode will now eagerly login to the NSS software token on

initialisation - `keytool` in FIPS mode now supports importing plain private

keys by the provider adding them to the NSS database. This can be disabled using

`-Dcom.redhat.fips.plainKeySupport=false`.

* Fri Oct 15 2021 Andrew Hughes - 1:1.8.0.312.b07-1

- Update to aarch64-shenandoah-jdk8u312-b07 (GA)

- Update release notes for 8u312-b07.

- Remove "-clean" suffix as no 8u312 builds are unclean.

- Port FIPS system detection support to OpenJDK 8u

- Minor code cleanups on FIPS detection patch and check for SECMOD_GetSystemFIPSEnabled in configure.

- Remove unneeded Requires on NSS as it will now be dynamically linked and detected by RPM.

- Allow plain key import to be disabled with -Dcom.redhat.fips.plainKeySupport=false

- Reduce disk footprint by removing build artifacts by default.

* Thu Oct 7 2021 Martin Balao - 1:1.8.0.312.b07-1

- Detect FIPS using SECMOD_GetSystemFIPSEnabled in the new libsystemconf JDK library.

- Add patch to login to the NSS software token when in FIPS mode.

- Add patch to allow plain key import.

su -c 'dnf upgrade --advisory FEDORA-2021-107c8c5063' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 35
Version: 1.8.0.312.b07
Release: 1.fc35
Summary: OpenJDK 8 Runtime Environment

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here