Oracle Linux Security Advisory ELSA-2022-7008

https://linux.oracle.com/errata/ELSA-2022-7008.html

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

aarch64:
java-11-openjdk-11.0.17.0.8-2.0.1.el7_9.aarch64.rpm
java-11-openjdk-devel-11.0.17.0.8-2.0.1.el7_9.aarch64.rpm
java-11-openjdk-headless-11.0.17.0.8-2.0.1.el7_9.aarch64.rpm
java-11-openjdk-demo-11.0.17.0.8-2.0.1.el7_9.aarch64.rpm
java-11-openjdk-javadoc-11.0.17.0.8-2.0.1.el7_9.aarch64.rpm
java-11-openjdk-javadoc-zip-11.0.17.0.8-2.0.1.el7_9.aarch64.rpm
java-11-openjdk-jmods-11.0.17.0.8-2.0.1.el7_9.aarch64.rpm
java-11-openjdk-src-11.0.17.0.8-2.0.1.el7_9.aarch64.rpm


SRPMS:
https://oss.oracle.com:443/ol7/SRPMS-updates/java-11-openjdk-11.0.17.0.8-2.0.1.el7_9.src.rpm

Related CVEs:

CVE-2022-21618
CVE-2022-21619
CVE-2022-21624
CVE-2022-21626
CVE-2022-21628
CVE-2022-39399




Description of changes:

[1:11.0.17.0.8-2.0.1]
- link atomic for ix86 build

[1:11.0.17.0.8-2]
- Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173
- Update CLDR data with Europe/Kyiv (JDK-8293834)
- Drop JDK-8292223 patch which we found to be unnecessary
- Update TestTranslations.java to use public API based on TimeZoneNamesTest upstream
- Remove unneeded JDK-8291053 patch as we no longer build in-tree HarfBuzz
- Related: rhbz#2133695

[1:11.0.17.0.8-1]
- Update to jdk-11.0.17+8 (GA)
- Update release notes to 11.0.17+8
- Switch to GA mode for release
- Resolves: rhbz#2133695

[1:11.0.17.0.7-0.1.ea]
- Update to jdk-11.0.17+7
- Update release notes to 11.0.17+7
- Resolves: rhbz#2130373

[1:11.0.17.0.1-0.1.ea]
- Try to build using system HarfBuzz to avoid build failures with 4.4.1 & gcc 4.8.5
- Related: rhbz#2130373

[1:11.0.17.0.1-0.1.ea]
- Include Aleksey's patch for JDK-8291053 to try and get HarfBuzz to build again
- Related: rhbz#2130373

[1:11.0.17.0.1-0.1.ea]
- Update to jdk-11.0.17+1
- Update release notes to 11.0.17+1
- Switch to EA mode for 11.0.17 pre-release builds.
- Related: rhbz#2130373


_______________________________________________
El-errata mailing list
El-errata@oss.oracle.com
https://oss.oracle.com/mailman/listinfo/el-errata

Oracle7: ELSA-2022-7008: java-11-openjdk security and bug fix Moderate Security Update (aa

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

Summary

[1:11.0.17.0.8-2.0.1] - link atomic for ix86 build [1:11.0.17.0.8-2] - Update in-tree tzdata to 2022e with JDK-8294357 & JDK-8295173 - Update CLDR data with Europe/Kyiv (JDK-8293834) - Drop JDK-8292223 patch which we found to be unnecessary - Update TestTranslations.java to use public API based on TimeZoneNamesTest upstream - Remove unneeded JDK-8291053 patch as we no longer build in-tree HarfBuzz - Related: rhbz#2133695 [1:11.0.17.0.8-1] - Update to jdk-11.0.17+8 (GA) - Update release notes to 11.0.17+8 - Switch to GA mode for release - Resolves: rhbz#2133695 [1:11.0.17.0.7-0.1.ea] - Update to jdk-11.0.17+7 - Update release notes to 11.0.17+7 - Resolves: rhbz#2130373 [1:11.0.17.0.1-0.1.ea] - Try to build using system HarfBuzz to avoid build failures with 4.4.1 & gcc 4.8.5 - Related: rhbz#2130373 [1:11.0.17.0.1-0.1.ea] - Include Aleksey's patch for JDK-8291053 to try and get HarfBuzz to build again - Related: rhbz#2130373 [1:11.0.17.0.1-0.1.ea] - Update to jdk-11.0.17+1 - Update release notes to 11.0.17+1 - Switch to EA mode for 11.0.17 pre-release builds. - Related: rhbz#2130373

SRPMs

https://oss.oracle.com:443/ol7/SRPMS-updates/java-11-openjdk-11.0.17.0.8-2.0.1.el7_9.src.rpm

x86_64

aarch64

java-11-openjdk-11.0.17.0.8-2.0.1.el7_9.aarch64.rpm java-11-openjdk-devel-11.0.17.0.8-2.0.1.el7_9.aarch64.rpm java-11-openjdk-headless-11.0.17.0.8-2.0.1.el7_9.aarch64.rpm java-11-openjdk-demo-11.0.17.0.8-2.0.1.el7_9.aarch64.rpm java-11-openjdk-javadoc-11.0.17.0.8-2.0.1.el7_9.aarch64.rpm java-11-openjdk-javadoc-zip-11.0.17.0.8-2.0.1.el7_9.aarch64.rpm java-11-openjdk-jmods-11.0.17.0.8-2.0.1.el7_9.aarch64.rpm java-11-openjdk-src-11.0.17.0.8-2.0.1.el7_9.aarch64.rpm

i386

Severity
Related CVEs: CVE-2022-21618 CVE-2022-21619 CVE-2022-21624 CVE-2022-21626 CVE-2022-21628 CVE-2022-39399

Related News