Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Fedora 36 OpenJDK 19.0.2 Critical Fix: Enhanced Security Updates

fedora
Calendar Grey February 5, 2023
Dist Fedora Esm H88
The updates in OpenJDK 19.0.2 for Fedora 36 feature essential revisions and optimizations aimed at countering recognized vulnerabilities.
# New in release OpenJDK 19.0.2 (2023-01-17) ## CVEs Fixed * CVE-2023-21835 * CVE-2023-21843 ## Security Fixes - JDK-8286070: Improve UTF8 representation - JDK-8286496: Improve Th...

Summary

The OpenJDK 19 runtime environment.

# New in release OpenJDK 19.0.2 (2023-01-17) ## CVEs Fixed * CVE-2023-21835 *

CVE-2023-21843 ## Security Fixes - JDK-8286070: Improve UTF8 representation

- JDK-8286496: Improve Thread labels - JDK-8287411: Enhance DTLS performance

- JDK-8288516: Enhance font creation - JDK-8293554: Enhanced DH Key Exchanges

- JDK-8293598: Enhance InetAddress address handling - JDK-8293717: Objective

view of ObjectView - JDK-8293734: Improve BMP image handling - JDK-8293742:

Better Banking of Sounds - JDK-8295687: Better BMP bounds ## Major Changes

### JDK-8295687: Better BMP bounds Loading a linked ICC profile within a BMP

image is now disabled by default. To re-enable it, set the new system property

`sun.imageio.bmp.enabledLinkedProfiles` to `true`. This new property replaces

the old property, `sun.imageio.plugins.bmp.disableLinkedProfiles`. ###

JDK-8293742: Better Banking of Sounds Previously, the SoundbankReader

implementation, `com.sun.media.sound.JARSoundbankReader`, would download a JAR

soundbank from a URL. This behaviour is now disabled by default. To re-enable

it, set the new system property `jdk.sound.jarsoundbank` to `true`. ###

JDK-8287411: Enhance DTLS performance The JDK now exchanges DTLS cookies for

all handshakes, new and resumed. The previous behaviour can be re-enabled by

setting the new system property `jdk.tls.enableDtlsResumeCookie` to `false`.

* Thu Jan 26 2023 Andrew Hughes - 1:19.0.2.0.7-1.rolling

- Revert "Flip the use of in-tree libraries back on by default"

- The transition to bundled libraries is an F37 feature that should not be backported.

* Thu Jan 26 2023 Andrew Hughes - 1:19.0.2.0.7-1.rolling

- Update to jdk-19.0.2 release

- Update release notes to 19.0.2

- Drop JDK-8293834 (CLDR update for Kyiv) which is now upstream

- Drop JDK-8294357 (tzdata2022d), JDK-8295173 (tzdata2022e) & JDK-8296108 (tzdata2022f) local patches which are now upstream

- Drop JDK-8296715 (CLDR update for 2022f) which is now upstream

- Add local patch JDK-8295447 (javac NPE) which was accepted into 19u upstream but not in the GA tag

- Add local patches for JDK-8296239 & JDK-8299439 (Croatia Euro update) which are present in 8u, 11u & 17u releases

* Thu Jan 19 2023 Fedora Release Engineering - 1:19.0.1.0.10-3.rolling.1

- Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild

* Fri Dec 16 2022 Andrew Hughes - 1:19.0.1.0.10-3.rolling

- Update in-tree tzdata & CLDR to 2022g with JDK-8296108, JDK-8296715 & JDK-8297804

- Update TestTranslations.java to test the new America/Ciudad_Juarez zone

su -c 'dnf upgrade --advisory FEDORA-2023-43bce108c7' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Do not reply to spam, report it:

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 36
Version: 19.0.2.0.7
Release: 1.rolling.fc36
Summary: OpenJDK 19 Runtime Environment

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here