Oracle Linux Security Advisory ELSA-2022-1445 https://linux.oracle.com/errata/ELSA-2022-1445.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: java-17-openjdk-17.0.3.0.6-2.el8_5.x86_64.rpm java-17-openjdk-demo-17.0.3.0.6-2.el8_5.x86_64.rpm java-17-openjdk-devel-17.0.3.0.6-2.el8_5.x86_64.rpm java-17-openjdk-headless-17.0.3.0.6-2.el8_5.x86_64.rpm java-17-openjdk-javadoc-17.0.3.0.6-2.el8_5.x86_64.rpm java-17-openjdk-javadoc-zip-17.0.3.0.6-2.el8_5.x86_64.rpm java-17-openjdk-jmods-17.0.3.0.6-2.el8_5.x86_64.rpm java-17-openjdk-src-17.0.3.0.6-2.el8_5.x86_64.rpm java-17-openjdk-static-libs-17.0.3.0.6-2.el8_5.x86_64.rpm java-17-openjdk-demo-fastdebug-17.0.3.0.6-2.el8_5.x86_64.rpm java-17-openjdk-demo-slowdebug-17.0.3.0.6-2.el8_5.x86_64.rpm java-17-openjdk-devel-fastdebug-17.0.3.0.6-2.el8_5.x86_64.rpm java-17-openjdk-devel-slowdebug-17.0.3.0.6-2.el8_5.x86_64.rpm java-17-openjdk-fastdebug-17.0.3.0.6-2.el8_5.x86_64.rpm java-17-openjdk-headless-fastdebug-17.0.3.0.6-2.el8_5.x86_64.rpm java-17-openjdk-headless-slowdebug-17.0.3.0.6-2.el8_5.x86_64.rpm java-17-openjdk-jmods-fastdebug-17.0.3.0.6-2.el8_5.x86_64.rpm java-17-openjdk-jmods-slowdebug-17.0.3.0.6-2.el8_5.x86_64.rpm java-17-openjdk-slowdebug-17.0.3.0.6-2.el8_5.x86_64.rpm java-17-openjdk-src-fastdebug-17.0.3.0.6-2.el8_5.x86_64.rpm java-17-openjdk-src-slowdebug-17.0.3.0.6-2.el8_5.x86_64.rpm java-17-openjdk-static-libs-fastdebug-17.0.3.0.6-2.el8_5.x86_64.rpm java-17-openjdk-static-libs-slowdebug-17.0.3.0.6-2.el8_5.x86_64.rpm aarch64: java-17-openjdk-17.0.3.0.6-2.el8_5.aarch64.rpm java-17-openjdk-demo-17.0.3.0.6-2.el8_5.aarch64.rpm java-17-openjdk-devel-17.0.3.0.6-2.el8_5.aarch64.rpm java-17-openjdk-headless-17.0.3.0.6-2.el8_5.aarch64.rpm java-17-openjdk-javadoc-17.0.3.0.6-2.el8_5.aarch64.rpm java-17-openjdk-javadoc-zip-17.0.3.0.6-2.el8_5.aarch64.rpm java-17-openjdk-jmods-17.0.3.0.6-2.el8_5.aarch64.rpm java-17-openjdk-src-17.0.3.0.6-2.el8_5.aarch64.rpm java-17-openjdk-static-libs-17.0.3.0.6-2.el8_5.aarch64.rpm java-17-openjdk-demo-fastdebug-17.0.3.0.6-2.el8_5.aarch64.rpm java-17-openjdk-demo-slowdebug-17.0.3.0.6-2.el8_5.aarch64.rpm java-17-openjdk-devel-fastdebug-17.0.3.0.6-2.el8_5.aarch64.rpm java-17-openjdk-devel-slowdebug-17.0.3.0.6-2.el8_5.aarch64.rpm java-17-openjdk-fastdebug-17.0.3.0.6-2.el8_5.aarch64.rpm java-17-openjdk-headless-fastdebug-17.0.3.0.6-2.el8_5.aarch64.rpm java-17-openjdk-headless-slowdebug-17.0.3.0.6-2.el8_5.aarch64.rpm java-17-openjdk-jmods-fastdebug-17.0.3.0.6-2.el8_5.aarch64.rpm java-17-openjdk-jmods-slowdebug-17.0.3.0.6-2.el8_5.aarch64.rpm java-17-openjdk-slowdebug-17.0.3.0.6-2.el8_5.aarch64.rpm java-17-openjdk-src-fastdebug-17.0.3.0.6-2.el8_5.aarch64.rpm java-17-openjdk-src-slowdebug-17.0.3.0.6-2.el8_5.aarch64.rpm java-17-openjdk-static-libs-fastdebug-17.0.3.0.6-2.el8_5.aarch64.rpm java-17-openjdk-static-libs-slowdebug-17.0.3.0.6-2.el8_5.aarch64.rpm SRPMS: https://oss.oracle.com/ol8/SRPMS-updates/java-17-openjdk-17.0.3.0.6-2.el8_5.src.rpm Related CVEs: CVE-2022-21426 CVE-2022-21434 CVE-2022-21443 CVE-2022-21449 CVE-2022-21476 CVE-2022-21496 Description of changes: [1:17.0.3.0.6-2] - Add JDK-8284920 fix for XPath regression - Related: rhbz#2073575 [1:17.0.3.0.6-2] - JDK-8275082 should be listed as also resolving JDK-8278008 & CVE-2022-21476 - Related: rhbz#2073575 [1:17.0.3.0.6-1] - JDK-8283911 patch no longer needed now we're GA... - Resolves: rhbz#2073575 [1:17.0.3.0.6-1] - April 2022 security update to jdk 17.0.3+6 - Update to jdk-17.0.3.0+6 pre-release tarball (17usec.17.0.3+5-220408) - Add JDK-8284548 regression fix missing from pre-release tarball but in jdk-17.0.3+6/jdk-17.0.3-ga - Update release notes to 17.0.3.0+6 - Add missing README.md and generate_source_tarball.sh - Introduce tests/tests.yml, based on the one in java-11-openjdk - Switch to GA mode for release - ** This tarball is embargoed until 2022-04-19 @ 1pm PT. ** - Resolves: rhbz#2073575 [1:17.0.3.0.5-0.1.ea] - Update to jdk-17.0.3.0+5 - Update release notes to 17.0.3.0+5 - Switch to EA mode for 17.0.3 pre-release builds. - Add JDK-8283911 to fix bad DEFAULT_PROMOTED_VERSION_PRE value - Related: rhbz#2073422 [1:17.0.2.0.8-6] - Enable AlgorithmParameters and AlgorithmParameterGenerator services in FIPS mode - Resolves: rhbz#2055396 [1:17.0.2.0.8-5] - Allow plain key import to be disabled with -Dcom.redhat.fips.plainKeySupport=false - Resolves: rhbz#2018189 [1:17.0.2.0.8-5] - Add patch to allow plain key import. - Resolves: rhbz#2018189 _______________________________________________ El-errata mailing list [email protected] https://oss.oracle.com/mailman/listinfo/el-errata