Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2025-3855 http://linux.oracle.com/errata/ELSA-2025-3855.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable LinuxNetwork: x86_64: java-21-openjdk-21.0.7.0.6-1.0.1.el9.x86_64.rpm java-21-openjdk-demo-21.0.7.0.6-1.0.1.el9.x86_64.rpm java-21-openjdk-devel-21.0.7.0.6-1.0.1.el9.x86_64.rpm java-21-openjdk-headless-21.0.7.0.6-1.0.1.el9.x86_64.rpm java-21-openjdk-javadoc-21.0.7.0.6-1.0.1.el9.x86_64.rpm java-21-openjdk-javadoc-zip-21.0.7.0.6-1.0.1.el9.x86_64.rpm java-21-openjdk-jmods-21.0.7.0.6-1.0.1.el9.x86_64.rpm java-21-openjdk-src-21.0.7.0.6-1.0.1.el9.x86_64.rpm java-21-openjdk-static-libs-21.0.7.0.6-1.0.1.el9.x86_64.rpm java-21-openjdk-demo-fastdebug-21.0.7.0.6-1.0.1.el9.x86_64.rpm java-21-openjdk-demo-slowdebug-21.0.7.0.6-1.0.1.el9.x86_64.rpm java-21-openjdk-devel-fastdebug-21.0.7.0.6-1.0.1.el9.x86_64.rpm java-21-openjdk-devel-slowdebug-21.0.7.0.6-1.0.1.el9.x86_64.rpm java-21-openjdk-fastdebug-21.0.7.0.6-1.0.1.el9.x86_64.rpm java-21-openjdk-headless-fastdebug-21.0.7.0.6-1.0.1.el9.x86_64.rpm java-21-openjdk-headless-slowdebug-21.0.7.0.6-1.0.1.el9.x86_64.rpm java-21-openjdk-jmods-fastdebug-21.0.7.0.6-1.0.1.el9.x86_64.rpm java-21-openjdk-jmods-slowdebug-21.0.7.0.6-1.0.1.el9.x86_64.rpm java-21-openjdk-slowdebug-21.0.7.0.6-1.0.1.el9.x86_64.rpm java-21-openjdk-src-fastdebug-21.0.7.0.6-1.0.1.el9.x86_64.rpm java-21-openjdk-src-slowdebug-21.0.7.0.6-1.0.1.el9.x86_64.rpm java-21-openjdk-static-libs-fastdebug-21.0.7.0.6-1.0.1.el9.x86_64.rpm java-21-openjdk-static-libs-slowdebug-21.0.7.0.6-1.0.1.el9.x86_64.rpm aarch64: java-21-openjdk-21.0.7.0.6-1.0.1.el9.aarch64.rpm java-21-openjdk-demo-21.0.7.0.6-1.0.1.el9.aarch64.rpm java-21-openjdk-devel-21.0.7.0.6-1.0.1.el9.aarch64.rpm java-21-openjdk-headless-21.0.7.0.6-1.0.1.el9.aarch64.rpm java-21-openjdk-javadoc-21.0.7.0.6-1.0.1.el9.aarch64.rpm java-21-openjdk-javadoc-zip-21.0.7.0.6-1.0.1.el9.aarch64.rpm java-21-openjdk-jmods-21.0.7.0.6-1.0.1.el9.aarch64.rpm java-21-openjdk-src-21.0.7.0.6-1.0.1.el9.aarch64.rpm java-21-openjdk-static-libs-21.0.7.0.6-1.0.1.el9.aarch64.rpm java-21-openjdk-demo-fastdebug-21.0.7.0.6-1.0.1.el9.aarch64.rpm java-21-openjdk-demo-slowdebug-21.0.7.0.6-1.0.1.el9.aarch64.rpm java-21-openjdk-devel-fastdebug-21.0.7.0.6-1.0.1.el9.aarch64.rpm java-21-openjdk-devel-slowdebug-21.0.7.0.6-1.0.1.el9.aarch64.rpm java-21-openjdk-fastdebug-21.0.7.0.6-1.0.1.el9.aarch64.rpm java-21-openjdk-headless-fastdebug-21.0.7.0.6-1.0.1.el9.aarch64.rpm java-21-openjdk-headless-slowdebug-21.0.7.0.6-1.0.1.el9.aarch64.rpm java-21-openjdk-jmods-fastdebug-21.0.7.0.6-1.0.1.el9.aarch64.rpm java-21-openjdk-jmods-slowdebug-21.0.7.0.6-1.0.1.el9.aarch64.rpm java-21-openjdk-slowdebug-21.0.7.0.6-1.0.1.el9.aarch64.rpm java-21-openjdk-src-fastdebug-21.0.7.0.6-1.0.1.el9.aarch64.rpm java-21-openjdk-src-slowdebug-21.0.7.0.6-1.0.1.el9.aarch64.rpm java-21-openjdk-static-libs-fastdebug-21.0.7.0.6-1.0.1.el9.aarch64.rpm java-21-openjdk-static-libs-slowdebug-21.0.7.0.6-1.0.1.el9.aarch64.rpm SRPMS: http://oss.oracle.com/ol9/SRPMS-updates//java-21-openjdk-21.0.7.0.6-1.0.1.el9.src.rpm Related CVEs: CVE-2025-21587 CVE-2025-30691 CVE-2025-30698 Description of changes: [1:21.0.7.0.6-1.0.1] - Add Oracle vendor bug URL [Orabug: 34340155] [1:21.0.7.0.6-1] - Update to jdk-21.0.7+6 (GA) - Update release notes to 21.0.7+6 - Rebase FIPS support against 21.0.7+5 - Require tzdata 2025a due to upstream inclusion of JDK-8347965 - Sync the copy of the portable specfile with the latest update - ** This tarball is embargoed until 2025-04-15 @ 1pm PT. ** - Resolves: RHEL-86984 - Resolves: RHEL-86621 [1:21.0.6.0.7-2] - Bump tzdata requirement to 2024b for JDK-8339637 - Resolves: RHEL-74001 _______________________________________________ El-errata mailing list
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2025-0422 http://linux.oracle.com/errata/ELSA-2025-0422.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable LinuxNetwork: x86_64: java-17-openjdk-17.0.14.0.7-2.0.1.el9.x86_64.rpm java-17-openjdk-demo-17.0.14.0.7-2.0.1.el9.x86_64.rpm java-17-openjdk-devel-17.0.14.0.7-2.0.1.el9.x86_64.rpm java-17-openjdk-headless-17.0.14.0.7-2.0.1.el9.x86_64.rpm java-17-openjdk-javadoc-17.0.14.0.7-2.0.1.el9.x86_64.rpm java-17-openjdk-javadoc-zip-17.0.14.0.7-2.0.1.el9.x86_64.rpm java-17-openjdk-jmods-17.0.14.0.7-2.0.1.el9.x86_64.rpm java-17-openjdk-src-17.0.14.0.7-2.0.1.el9.x86_64.rpm java-17-openjdk-static-libs-17.0.14.0.7-2.0.1.el9.x86_64.rpm java-17-openjdk-demo-fastdebug-17.0.14.0.7-2.0.1.el9.x86_64.rpm java-17-openjdk-demo-slowdebug-17.0.14.0.7-2.0.1.el9.x86_64.rpm java-17-openjdk-devel-fastdebug-17.0.14.0.7-2.0.1.el9.x86_64.rpm java-17-openjdk-devel-slowdebug-17.0.14.0.7-2.0.1.el9.x86_64.rpm java-17-openjdk-fastdebug-17.0.14.0.7-2.0.1.el9.x86_64.rpm java-17-openjdk-headless-fastdebug-17.0.14.0.7-2.0.1.el9.x86_64.rpm java-17-openjdk-headless-slowdebug-17.0.14.0.7-2.0.1.el9.x86_64.rpm java-17-openjdk-jmods-fastdebug-17.0.14.0.7-2.0.1.el9.x86_64.rpm java-17-openjdk-jmods-slowdebug-17.0.14.0.7-2.0.1.el9.x86_64.rpm java-17-openjdk-slowdebug-17.0.14.0.7-2.0.1.el9.x86_64.rpm java-17-openjdk-src-fastdebug-17.0.14.0.7-2.0.1.el9.x86_64.rpm java-17-openjdk-src-slowdebug-17.0.14.0.7-2.0.1.el9.x86_64.rpm java-17-openjdk-static-libs-fastdebug-17.0.14.0.7-2.0.1.el9.x86_64.rpm java-17-openjdk-static-libs-slowdebug-17.0.14.0.7-2.0.1.el9.x86_64.rpm aarch64: java-17-openjdk-17.0.14.0.7-2.0.1.el9.aarch64.rpm java-17-openjdk-demo-17.0.14.0.7-2.0.1.el9.aarch64.rpm java-17-openjdk-devel-17.0.14.0.7-2.0.1.el9.aarch64.rpm java-17-openjdk-headless-17.0.14.0.7-2.0.1.el9.aarch64.rpm java-17-openjdk-javadoc-17.0.14.0.7-2.0.1.el9.aarch64.rpm java-17-openjdk-javadoc-zip-17.0.14.0.7-2.0.1.el9.aarch64.rpm java-17-openjdk-jmods-17.0.14.0.7-2.0.1.el9.aarch64.rpm java-17-openjdk-src-17.0.14.0.7-2.0.1.el9.aarch64.rpm java-17-openjdk-static-libs-17.0.14.0.7-2.0.1.el9.aarch64.rpm java-17-openjdk-demo-fastdebug-17.0.14.0.7-2.0.1.el9.aarch64.rpm java-17-openjdk-demo-slowdebug-17.0.14.0.7-2.0.1.el9.aarch64.rpm java-17-openjdk-devel-fastdebug-17.0.14.0.7-2.0.1.el9.aarch64.rpm java-17-openjdk-devel-slowdebug-17.0.14.0.7-2.0.1.el9.aarch64.rpm java-17-openjdk-fastdebug-17.0.14.0.7-2.0.1.el9.aarch64.rpm java-17-openjdk-headless-fastdebug-17.0.14.0.7-2.0.1.el9.aarch64.rpm java-17-openjdk-headless-slowdebug-17.0.14.0.7-2.0.1.el9.aarch64.rpm java-17-openjdk-jmods-fastdebug-17.0.14.0.7-2.0.1.el9.aarch64.rpm java-17-openjdk-jmods-slowdebug-17.0.14.0.7-2.0.1.el9.aarch64.rpm java-17-openjdk-slowdebug-17.0.14.0.7-2.0.1.el9.aarch64.rpm java-17-openjdk-src-fastdebug-17.0.14.0.7-2.0.1.el9.aarch64.rpm java-17-openjdk-src-slowdebug-17.0.14.0.7-2.0.1.el9.aarch64.rpm java-17-openjdk-static-libs-fastdebug-17.0.14.0.7-2.0.1.el9.aarch64.rpm java-17-openjdk-static-libs-slowdebug-17.0.14.0.7-2.0.1.el9.aarch64.rpm SRPMS: http://oss.oracle.com/ol9/SRPMS-updates//java-17-openjdk-17.0.14.0.7-2.0.1.el9.src.rpm Related CVEs: CVE-2025-21502 Description of changes: [1:17.0.14.0.7-2.0.1] - Add Oracle vendor bug URL [Orabug: 34340155] [1:17.0.14.0.7-2] - Do not pass nil to _jvmdir macro in cjc logic [1:17.0.14.0.7-2] - Update to jdk-17.0.14+7 (GA) - Add to .gitignore openjdk-17.0.14+7.tar.xz - Set buildver to 7 - Set is_ga to 1 - Update sources to openjdk-17.0.14+7.tar.xz - Sync java-17-openjdk-portable.specfile from openjdk-portable-rhel-8 - Resolves: RHEL-73981 - Resolves: RHEL-73559 - ** This tarball is embargoed until 2025-01-21 @ 1pm PT. ** [1:17.0.14.0.1-0.2.ea] - Limit Java only tests to one architecture using jdk_test_arch - OPENJDK-3185 [1:17.0.14.0.1-0.2.ea] - Update to jdk-17.0.14+1 (EA) - Add to .gitignore openjdk-17.0.14+1-ea.tar.xz - Set updatever to 14 - Set buildver to 1 - Set rpmrelease to 2 - Set is_ga to 0 - Update sources to openjdk-17.0.14+1-ea.tar.xz - Double percent signs consistently throughout comments - Set bundled giflib provide version to 5.2.2 - Set bundled libpng provide version to 1.6.43 - Warn about bundled provide version bumps and backouts in openjdk_news.sh - Remove0001-8332174-Remove-2-unpaired-RLO-Unicode-characters-in-.patch file - Revert: Use component in EPEL and Fedora bug URLs _______________________________________________ El-errata mailing list
* bsc#1231702 * bsc#1231711 * bsc#1231716 * bsc#1231719 . # Security update for java-21-openjdk Announcement ID: SUSE-SU-2024:3954-1 Release Date: 2024-11-08T13:10:09Z Rating: moderate References: * bsc#1231702 * bsc#1231711 * bsc#1231716 * bsc#1231719 Cross-References: * CVE-2024-21208 * CVE-2024-21210 * CVE-2024-21217 * CVE-2024-21235 CVSS scores: * CVE-2024-21208 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2024-21208 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2024-21208 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2024-21210 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2024-21210 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2024-21210 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2024-21217 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2024-21217 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2024-21217 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2024-21235 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2024-21235 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2024-21235 ( NVD ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N Affected Products: * Basesystem Module 15-SP6 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves four vulnerabilities can now be installed. ## Description: This update for java-21-openjdk fixes the following issues: * Update to upstream tag jdk-21.0.5+13 (October 2024 CPU) * Security fixes * JDK-8307383: Enhance DTLS connections * JDK-8311208: Improve CDS Support * JDK-8328286, CVE-2024-21208, bsc#1231702:Enhance HTTP client * JDK-8328544, CVE-2024-21210, bsc#1231711: Improve handling of vectorization * JDK-8328726: Better Kerberos support * JDK-8331446, CVE-2024-21217, bsc#1231716: Improve deserialization support * JDK-8332644, CVE-2024-21235, bsc#1231719: Improve graph optimizations * JDK-8335713: Enhance vectorization analysis * Other changes * JDK-6355567: AdobeMarkerSegment causes failure to read valid JPEG * JDK-6967482: TAB-key does not work in JTables after selecting details-view in JFileChooser * JDK-7022325: TEST_BUG: test/java/util/zip/ZipFile/ /ReadLongZipFileName.java leaks files if it fails * JDK-8051959: Add thread and timestamp options to java.security.debug system property * JDK-8073061: (fs) Files.copy(foo, bar, REPLACE_EXISTING) deletes bar even if foo is not readable * JDK-8166352: FilePane.createDetailsView() removes JTable TAB, SHIFT-TAB functionality * JDK-8170817: G1: Returning MinTLABSize from unsafe_max_tlab_alloc causes TLAB flapping * JDK-8211847: [aix] java/lang/ProcessHandle/InfoTest.java fails: "reported cputime less than expected" * JDK-8211854: [aix] java/net/ServerSocket/ /AcceptInheritHandle.java fails: read times out * JDK-8222884: ConcurrentClassDescLookup.java times out intermittently * JDK-8238169: BasicDirectoryModel getDirectories and DoChangeContents.run can deadlock * JDK-8241550: [macOS] SSLSocketImpl/ReuseAddr.java failed due to "BindException: Address already in use" * JDK-8242564: javadoc crashes:: class cast exception com.sun.tools.javac.code.Symtab$6 * JDK-8260633: [macos] java/awt/dnd/MouseEventAfterStartDragTest/ /MouseEventAfterStartDragTest.html test failed * JDK-8261433: Better pkcs11 performance for libpkcs11:C_EncryptInit/libpkcs11:C_DecryptInit * JDK-8269428: java/util/concurrent/ConcurrentHashMap/ /ToArray.java timed out * JDK-8269657: Test java/nio/channels/DatagramChannel/ /Loopback.java failed: Unexpected message * JDK-8280120: [IR Framework] Add attribute to@IR to enable/disable IR matching based on the architecture * JDK-8280392: java/awt/Focus/NonFocusableWindowTest/ /NonfocusableOwnerTest.java failed with "RuntimeException: Test failed." * JDK-8280988: [XWayland] Click on title to request focus test failures * JDK-8280990: [XWayland] XTest emulated mouse click does not bring window to front * JDK-8283223: gc/stringdedup/TestStringDeduplicationFullGC.java #Parallel failed with "RuntimeException: String verification failed" * JDK-8287325: AArch64: fix virtual threads with -XX:UseBranchProtection=pac-ret * JDK-8291809: Convert compiler/c2/cr7200264/TestSSE2IntVect.java to IR verification test * JDK-8294148: Support JSplitPane for instructions and test UI * JDK-8299058: AssertionError in sun.net.httpserver.ServerImpl when connection is idle * JDK-8299487: Test java/net/httpclient/whitebox/ /SSLTubeTestDriver.java timed out * JDK-8299790: os::print_hex_dump is racy * JDK-8299813: java/nio/channels/DatagramChannel/Disconnect.java fails with jtreg test timeout due to lost datagram * JDK-8301686: TLS 1.3 handshake fails if server_name doesn't match resuming session * JDK-8303920: Avoid calling out to python in DataDescriptorSignatureMissing test * JDK-8305072: Win32ShellFolder2.compareTo is inconsistent * JDK-8305825: getBounds API returns wrong value resulting in multiple Regression Test Failures on Ubuntu 23.04 * JDK-8307193: Several Swing jtreg tests use class.forName on L&F classes * JDK-8307352: AARCH64: Improve itable_stub * JDK-8307778: com/sun/jdi/cds tests fail with jtreg's Virtual test thread factory * JDK-8307788: vmTestbase/gc/gctests/LargeObjects/large003/ /TestDescription.java timed out * JDK-8308286: Fix clang warnings in linux code * JDK-8308660: C2 compilation hits 'node must be dead' assert * JDK-8309067: gtest/AsyncLogGtest.java fails again in stderrOutput_vm * JDK-8309621: [XWayland][Screencast] screen capture failure with sun.java2d.uiScale other than 1 *JDK-8309685: Fix -Wconversion warnings in assembler and register code * JDK-8309894: compiler/vectorapi/ /VectorLogicalOpIdentityTest.java fails on SVE system with UseSVE=0 * JDK-8310072: JComboBox/DisabledComboBoxFontTestAuto: Enabled and disabled ComboBox does not match in these LAFs: GTK+ * JDK-8310108: Skip ReplaceCriticalClassesForSubgraphs when EnableJVMCI is specified * JDK-8310201: Reduce verbose locale output in -XshowSettings launcher option * JDK-8310334: [XWayland][Screencast] screen capture error message in debug * JDK-8310628: GcInfoBuilder.c missing JNI Exception checks * JDK-8310683: Refactor StandardCharset/standard.java to use JUnit * JDK-8310906: Fix -Wconversion warnings in runtime, oops and some code header files. * JDK-8311306: Test com/sun/management/ThreadMXBean/ /ThreadCpuTimeArray.java failed: out of expected range * JDK-8311666: Disabled tests in test/jdk/sun/java2d/marlin * JDK-8311989: Test java/lang/Thread/virtual/Reflection.java timed out * JDK-8312049: runtime/logging/ClassLoadUnloadTest can be improved * JDK-8312111: open/test/jdk/java/awt/Robot/ModifierRobotKey/ /ModifierRobotKeyTest.java fails on ubuntu 23.04 * JDK-8312140: jdk/jshell tests failed with JDI socket timeouts * JDK-8312200: Fix Parse::catch_call_exceptions memory leak * JDK-8312229: Crash involving yield, switch and anonymous classes * JDK-8313674: (fc) java/nio/channels/FileChannel/ /BlockDeviceSize.java should test for more block devices * JDK-8313697: [XWayland][Screencast] consequent getPixelColor calls are slow * JDK-8313983: jmod create --target-platform should replace existing ModuleTarget attribute * JDK-8314163: os::print_hex_dump prints incorrectly for big endian platforms and unit sizes larger than 1 * JDK-8314225: SIGSEGV in JavaThread::is_lock_owned * JDK-8314515: java/util/concurrent/SynchronousQueue/ /Fairness.java failed with "Error: fair=false i=8 j=0" * JDK-8314614: jdk/jshell/ImportTest.java failed with"InternalError: Failed remote listen" * JDK-8315024: Vector API FP reduction tests should not test for exact equality * JDK-8315031: YoungPLABSize and OldPLABSize not aligned by ObjectAlignmentInBytes * JDK-8315422: getSoTimeout() would be in try block in SSLSocketImpl * JDK-8315505: CompileTask timestamp printed can overflow * JDK-8315576: compiler/codecache/CodeCacheFullCountTest.java fails after JDK-8314837 * JDK-8315804: Open source several Swing JTabbedPane JTextArea JTextField tests * JDK-8315923: pretouch_memory by atomic-add-0 fragments huge pages unexpectedly * JDK-8315965: Open source various AWT applet tests * JDK-8315969: compiler/rangechecks/ /TestRangeCheckHoistingScaledIV.java: make flagless * JDK-8316104: Open source several Swing SplitPane and RadioButton related tests * JDK-8316131: runtime/cds/appcds/TestParallelGCWithCDS.java fails with JNI error * JDK-8316193: jdk/jfr/event/oldobject/TestListenerLeak.java java.lang.Exception: Could not find leak * JDK-8316211: Open source several manual applet tests * JDK-8316240: Open source several add/remove MenuBar manual tests * JDK-8316285: Opensource JButton manual tests * JDK-8316306: Open source and convert manual Swing test * JDK-8316328: Test jdk/jfr/event/oldobject/ /TestSanityDefault.java times out for some heap sizes * JDK-8316361: C2: assert(!failure) failed: Missed optimization opportunity in PhaseIterGVN with -XX:VerifyIterativeGVN=10 * JDK-8316389: Open source few AWT applet tests * JDK-8316756: C2 EA fails with "missing memory path" when encountering unsafe_arraycopy stub call * JDK-8317112: Add screenshot for Frame/DefaultSizeTest.java * JDK-8317128: java/nio/file/Files/CopyAndMove.java failed with AccessDeniedException * JDK-8317240: Promptly free OopMapEntry after fail to insert the entry to OopMapCache * JDK-8317288: [macos] java/awt/Window/Grab/GrabTest.java: Press on the outside area didn't cause ungrab * JDK-8317299: safepointscalarization doesn't keep track of the depth of the JVM state * JDK-8317360: Missing null checks in JfrCheckpointManager and JfrStringPool initialization routines * JDK-8317372: Refactor some NumberFormat tests to use JUnit * JDK-8317446: ProblemList gc/arguments/TestNewSizeFlags.java on macosx-aarch64 in Xcomp * JDK-8317449: ProblemList serviceability/jvmti/stress/ /StackTrace/NotSuspended/ /GetStackTraceNotSuspendedStressTest.java on several platforms * JDK-8317635: Improve GetClassFields test to verify correctness of field order * JDK-8317696: Fix compilation with clang-16 * JDK-8317738: CodeCacheFullCountTest failed with "VirtualMachineError: Out of space in CodeCache for method handle intrinsic" * JDK-8317831: compiler/codecache/CheckLargePages.java fails on OL 8.8 with unexpected memory string * JDK-8318071: IgnoreUnrecognizedVMOptions flag still causes failure in ArchiveHeapTestClass * JDK-8318479: [jmh] the test security.CacheBench failed for multiple threads run * JDK-8318605: Enable parallelism in vmTestbase/nsk/stress/stack tests * JDK-8319197: Exclude hb-subset and hb-style from compilation * JDK-8319406: x86: Shorter movptr(reg, imm) for 32-bit immediates * JDK-8319773: Avoid inflating monitors when installing hash codes for LM_LIGHTWEIGHT * JDK-8319793: C2 compilation fails with "Bad graph detected in build_loop_late" after JDK-8279888 * JDK-8319817: Charset constructor should make defensive copy of aliases * JDK-8319818: Address GCC 13.2.0 warnings (stringop-overflow and dangling-pointer) * JDK-8320079: The ArabicBox.java test has no control buttons * JDK-8320212: Disable GCC stringop-overflow warning for affected files * JDK-8320379: C2: Sort spilling/unspilling sequence for better ld/st merging into ldp/stp on AArch64 * JDK-8320602: Lock contention in SchemaDVFactory.getInstance() * JDK-8320608: Many jtreg printing tests are missing the @printer keyword * JDK-8320655: awt screencast robot spin and syncissues with native libpipewire api * JDK-8320675: PrinterJob/SecurityDialogTest.java hangs * JDK-8320945: problemlist tests failing on latest Windows 11 update * JDK-8321025: Enable Neoverse N1 optimizations for Neoverse V2 * JDK-8321176: [Screencast] make a second attempt on screencast failure * JDK-8321206: Make Locale related system properties `StaticProperty` * JDK-8321220: JFR: RecordedClass reports incorrect modifiers * JDK-8321278: C2: Partial peeling fails with assert "last_peel
Change for system JDK from 17 to 21. upstream security release 122.0.6261.94 High CVE-2024-1938: Type Confusion in V8 High CVE-2024-1939: Type Confusion in V8 fixed bug with requires. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-129d8ca6fc 2024-03-07 22:24:39.963937 -------------------------------------------------------------------------------- Name : CardManager Product : Fedora 40 Version : 3 Release : 29.fc40 URL : Summary : Java application to allows you to play any, especially collectible, card game Description : This is free, open source multiplatform (java) application which allows you to play ANY card game. The game is designed especially to play collectible card games like Magic the Gathering or Doomtrooper over network. To play those games you need to own (scanned) images of card, which are not part of this package. Some can be easily downloadable from internet, but be aware of copyrights. The default deck and background is free of copyright Also please feel free to add your own backgrounds to ~/CardManager/data/backgrounds and of course enhance collection under ~/CardManager/collection -------------------------------------------------------------------------------- Update Information: Change for system JDK from 17 to 21. upstream security release 122.0.6261.94 High CVE-2024-1938: Type Confusion in V8 High CVE-2024-1939: Type Confusion in V8 fixed bug with requires Automatic update for lucene-9.9.2-1.fc40. bump java source/target to 1.8, fixes 2266639 -------------------------------------------------------------------------------- ChangeLog: * Sat Mar 2 2024 Jiri Vanek - 3-29 - Rebuilt for java-21-openjdk as system jdk -------------------------------------------------------------------------------- References: [ 1 ] Bug #2123726 - consoleImageViewer crashes at start https://bugzilla.redhat.com/show_bug.cgi?id=2123726 [ 2 ] Bug#2261062 - directory-maven-plugin: FTBFS in Fedora rawhide/f40 https://bugzilla.redhat.com/show_bug.cgi?id=2261062 [ 3 ] Bug #2266639 - directory-maven-plugin fails to build with java-21-openjdk https://bugzilla.redhat.com/show_bug.cgi?id=2266639 [ 4 ] Bug #2266934 - CVE-2024-1938 chromium: type confusion [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2266934 [ 5 ] Bug #2266937 - CVE-2024-1939 chromium: type confusion [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2266937 [ 6 ] Bug #2267486 - Include Java 21 as system Java Change in Fedora 40 Beta https://bugzilla.redhat.com/show_bug.cgi?id=2267486 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-129d8ca6fc' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
An update that solves 6 vulnerabilities and has two fixes is now available. . SUSE Security Update: Security update for java-11-openjdk ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:4080-1 Rating: moderate References: #1203476 #1204468 #1204471 #1204472 #1204473 #1204475 #1204480 #1204523 Cross-References: CVE-2022-21618 CVE-2022-21619 CVE-2022-21624 CVE-2022-21626 CVE-2022-21628 CVE-2022-39399 CVSS scores: CVE-2022-21618 (NVD) : 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N CVE-2022-21618 (SUSE): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N CVE-2022-21619 (NVD) : 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N CVE-2022-21619 (SUSE): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N CVE-2022-21624 (NVD) : 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N CVE-2022-21624 (SUSE): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N CVE-2022-21626 (NVD) : 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L CVE-2022-21626 (SUSE): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L CVE-2022-21628 (NVD) : 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L CVE-2022-21628 (SUSE): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L CVE-2022-39399 (NVD) : 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N CVE-2022-39399 (SUSE): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N Affected Products: SUSE Linux Enterprise Server 12-SP5 ______________________________________________________________________________ An update that solves 6 vulnerabilities and has two fixes is now available. Description: This update for java-11-openjdk fixes the following issues: - Update to jdk-11.0.17+8 (October 2022 CPU) -CVE-2022-39399: Improve HTTP/2 client usage(bsc#1204480) - CVE-2022-21628: Better HttpServer service (bsc#1204472) - CVE-2022-21624: Enhance icon presentations (bsc#1204475) - CVE-2022-21619: Improve NTLM support (bsc#1204473) - CVE-2022-21626: Key X509 usages (bsc#1204471) - CVE-2022-21618: Wider MultiByte (bsc#1204468) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server 12-SP5: zypper in -t patch SUSE-SLE-SERVER-12-SP5-2022-4080=1 Package List: - SUSE Linux Enterprise Server 12-SP5 (aarch64 ppc64le s390x x86_64): java-11-openjdk-11.0.17.0-3.49.2 java-11-openjdk-debugsource-11.0.17.0-3.49.2 java-11-openjdk-demo-11.0.17.0-3.49.2 java-11-openjdk-devel-11.0.17.0-3.49.2 java-11-openjdk-headless-11.0.17.0-3.49.2 References: https://www.suse.com/security/cve/CVE-2022-21618.html https://www.suse.com/security/cve/CVE-2022-21619.html https://www.suse.com/security/cve/CVE-2022-21624.html https://www.suse.com/security/cve/CVE-2022-21626.html https://www.suse.com/security/cve/CVE-2022-21628.html https://www.suse.com/security/cve/CVE-2022-39399.html https://bugzilla.suse.com/1203476 https://bugzilla.suse.com/1204468 https://bugzilla.suse.com/1204471 https://bugzilla.suse.com/1204472 https://bugzilla.suse.com/1204473 https://bugzilla.suse.com/1204475 https://bugzilla.suse.com/1204480 https://bugzilla.suse.com/1204523 . New patch released for java-11-openjdk tackling five concerns of moderate severity on SUSE Linux Enterprise Server.. SUSE Update, java-11-openjdk, Security Patch, Moderate Severity, HTTP/2 Client. . LinuxSecurity.com Team
A security update is now available for Red Hat JBoss Enterprise Application Platform 7.4 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: Red Hat JBoss Enterprise Application Platform 7.4.3 security update Advisory ID: RHSA-2022:0400-01 Product: Red Hat JBoss Enterprise Application Platform Advisory URL: https://access.redhat.com/errata/RHSA-2022:0400 Issue date: 2022-02-02 CVE Names: CVE-2021-3859 CVE-2021-20318 ==================================================================== 1. Summary: A security update is now available for Red Hat JBoss Enterprise Application Platform 7.4 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat JBoss EAP 7.4 for RHEL 7 Server - noarch 3. Description: Red Hat JBoss Enterprise Application Platform 7 is a platform for Java applications based on the WildFly application runtime. This release of Red Hat JBoss Enterprise Application Platform 7.4.3 serves as a replacement for Red Hat JBoss Enterprise Application Platform 7.4.2, and includes bug fixes and enhancements. See the Red Hat JBoss Enterprise Application Platform 7.4.3 Release Notes for information about the most significant bug fixes and enhancements included in this release. Security Fix(es): * undertow: client side invocation timeout raised when calling over HTTP2 (CVE-2021-3859) * EAP 7: Incomplete fix of CVE-2016-4978 in HornetQ library (CVE-2021-20318) For moredetails about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: Before applying this update, back up your existing Red Hat JBoss Enterprise Application Platform installation and deployed applications. For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2010378 - CVE-2021-3859 undertow: client side invocation timeout raised when calling over HTTP2 2010559 - CVE-2021-20318 EAP 7: Incomplete fix of CVE-2016-4978 in HornetQ library 6. JIRA issues fixed (https://redhat.atlassian.net/jira/projects): JBEAP-22100 - (7.4.z) Upgrade galleon-plugins to a 5.1.x version with WFGP-195 fixed JBEAP-22104 - (7.4.z) Upgrade JBoss Classfilewriter from 1.2.4.Final-redhat-00001 to 1.2.5.Final-redhat-00001 JBEAP-22106 - (7.4.z) Upgrade to JBoss Marshalling from 2.0.11.Final-redhat-00001 to 2.0.12.Final-redhat-00001 JBEAP-22108 - (7.4.z) Upgrade to Byteman from 4.0.14 to 4.0.16 JBEAP-22373 - (7.4.z) Upgrade galleon-plugins in wildfly-core-eap from 5.1.0.Final to 5.1.4.Final JBEAP-22505 - [GSS](7.4.z) WFLY-14923 - Update JPA handling to support `initialize-in-order` JBEAP-22575 - (7.4.z) Upgrade mod_cluster from 1.4.3.Final-redhat-00002 to 1.4.4.Final JBEAP-22582 - (7.4.z) Upgrade WildFly Core from 15.0.5.Final-redhat-00001 to 15.0.6.Final-redhat-00001 JBEAP-22586 - (7.4.z) Upgrade RESTEasy from 3.15.2.Final-redhat-00001 to 3.15.3.Final-redhat-00001 JBEAP-22587 - (7.4.z) Upgrade Hibernate ORM from 5.3.23.Final-redhat-00001 to 5.3.24.Final-redhat-00001 JBEAP-22590 - (7.4.z) Upgrade Mockito from 2.18.0 to 3.10.0 JBEAP-22609 - (7.4.z) Upgrade XNIO from 3.8.4.Final-redhat-00001 to 3.8.5.SP1-redhat-00001 JBEAP-22641 - Tracker bug for the EAP 7.4.3 release for RHEL-7 JBEAP-22668 - (7.4.z) Upgrade Elytron from 1.15.6.Final-redhat-00001 to 1.15.9.Final JBEAP-22679 -[GSS](7.4.z) UNDERTOW-1984 - GOAWAY sent by HTTP2 server when a RST is sent after upgrade JBEAP-22692 - (7.4.z) Upgrade Ironjacamar from 1.5.2.Final-redhat-00001 to 1.5.3.Final-redhat-00001 JBEAP-22693 - (7.4.z) Upgrade jboss-ejb-client from 4.0.43.Final-redhat-00001 to 4.0.44.Final-redhat-00001 JBEAP-22740 - (7.4.z) Upgrade jgroups_azure from 1.3.0.Final-redhat-00001 to 1.3.1.Final JBEAP-22754 - (7.4.z) Upgrade azure-storage 8.6.6 JBEAP-22793 - (7.4.z) Update elytron-tool scripts to make use of jboss-modules JBEAP-22822 - (7.4.z) Update ElytronHttpExchange#getRequestURI to no longer use the 7 argument URI constructor JBEAP-22823 - (7.4.z) Upgrade undertow from 2.2.13.SP1 to 2.2.13.SP2 JBEAP-22833 - (7.4.z) Upgrade elytron-web from 1.9.1.Final-redhat-00001 to 1.9.2.Final-redhat-00001 JBEAP-22851 - (7.4.z) Upgrade WildFly Http Client from 1.1.8.Final-redhat-00001 to 1.1.10.Final-redhat-00001 7. Package List: Red Hat JBoss EAP 7.4 for RHEL 7Server: Source: eap7-azure-storage-8.6.6-1.redhat_00001.1.el7eap.src.rpm eap7-elytron-web-1.9.2-2.Final_redhat_00001.1.el7eap.src.rpm eap7-hibernate-5.3.24-1.Final_redhat_00001.1.el7eap.src.rpm eap7-hornetq-2.4.8-1.Final_redhat_00001.1.el7eap.src.rpm eap7-ironjacamar-1.5.3-1.Final_redhat_00001.1.el7eap.src.rpm eap7-jboss-classfilewriter-1.2.5-1.Final_redhat_00001.1.el7eap.src.rpm eap7-jboss-ejb-client-4.0.44-1.Final_redhat_00001.1.el7eap.src.rpm eap7-jboss-marshalling-2.0.12-1.Final_redhat_00001.1.el7eap.src.rpm eap7-jboss-server-migration-1.10.0-13.Final_redhat_00012.1.el7eap.src.rpm eap7-jboss-xnio-base-3.8.5-1.SP1_redhat_00001.1.el7eap.src.rpm eap7-jgroups-4.2.15-1.Final_redhat_00001.1.el7eap.src.rpm eap7-jgroups-azure-1.3.1-1.Final_redhat_00001.1.el7eap.src.rpm eap7-mod_cluster-1.4.4-1.Final_redhat_00001.1.el7eap.src.rpm eap7-resteasy-3.15.3-1.Final_redhat_00001.1.el7eap.src.rpm eap7-undertow-2.2.13-1.SP2_redhat_00001.1.el7eap.src.rpm eap7-wildfly-7.4.3-5.GA_redhat_00002.1.el7eap.src.rpm eap7-wildfly-elytron-1.15.9-2.Final_redhat_00001.1.el7eap.src.rpm eap7-wildfly-http-client-1.1.10-1.Final_redhat_00001.1.el7eap.src.rpm noarch: eap7-azure-storage-8.6.6-1.redhat_00001.1.el7eap.noarch.rpm eap7-hibernate-5.3.24-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-hibernate-core-5.3.24-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-hibernate-entitymanager-5.3.24-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-hibernate-envers-5.3.24-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-hibernate-java8-5.3.24-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-hornetq-2.4.8-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-hornetq-commons-2.4.8-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-hornetq-core-client-2.4.8-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-hornetq-jms-client-2.4.8-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-ironjacamar-1.5.3-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-ironjacamar-common-api-1.5.3-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-ironjacamar-common-impl-1.5.3-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-ironjacamar-common-spi-1.5.3-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-ironjacamar-core-api-1.5.3-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-ironjacamar-core-impl-1.5.3-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-ironjacamar-deployers-common-1.5.3-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-ironjacamar-jdbc-1.5.3-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-ironjacamar-validator-1.5.3-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-jboss-classfilewriter-1.2.5-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-jboss-ejb-client-4.0.44-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-jboss-marshalling-2.0.12-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-jboss-marshalling-river-2.0.12-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-jboss-server-migration-1.10.0-13.Final_redhat_00012.1.el7eap.noarch.rpm eap7-jboss-server-migration-cli-1.10.0-13.Final_redhat_00012.1.el7eap.noarch.rpm eap7-jboss-server-migration-core-1.10.0-13.Final_redhat_00012.1.el7eap.noarch.rpm eap7-jboss-xnio-base-3.8.5-1.SP1_redhat_00001.1.el7eap.noarch.rpm eap7-jgroups-4.2.15-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-jgroups-azure-1.3.1-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-mod_cluster-1.4.4-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-resteasy-3.15.3-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-resteasy-atom-provider-3.15.3-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-resteasy-cdi-3.15.3-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-resteasy-client-3.15.3-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-resteasy-crypto-3.15.3-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-resteasy-jackson-provider-3.15.3-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-resteasy-jackson2-provider-3.15.3-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-resteasy-jaxb-provider-3.15.3-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-resteasy-jaxrs-3.15.3-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-resteasy-jettison-provider-3.15.3-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-resteasy-jose-jwt-3.15.3-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-resteasy-jsapi-3.15.3-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-resteasy-json-binding-provider-3.15.3-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-resteasy-json-p-provider-3.15.3-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-resteasy-multipart-provider-3.15.3-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-resteasy-rxjava2-3.15.3-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-resteasy-spring-3.15.3-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-resteasy-validator-provider-11-3.15.3-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-resteasy-yaml-provider-3.15.3-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-undertow-2.2.13-1.SP2_redhat_00001.1.el7eap.noarch.rpm eap7-undertow-server-1.9.2-2.Final_redhat_00001.1.el7eap.noarch.rpm eap7-wildfly-7.4.3-5.GA_redhat_00002.1.el7eap.noarch.rpm eap7-wildfly-elytron-1.15.9-2.Final_redhat_00001.1.el7eap.noarch.rpm eap7-wildfly-elytron-tool-1.15.9-2.Final_redhat_00001.1.el7eap.noarch.rpm eap7-wildfly-http-client-common-1.1.10-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-wildfly-http-ejb-client-1.1.10-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-wildfly-http-naming-client-1.1.10-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-wildfly-http-transaction-client-1.1.10-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-wildfly-java-jdk11-7.4.3-5.GA_redhat_00002.1.el7eap.noarch.rpm eap7-wildfly-java-jdk8-7.4.3-5.GA_redhat_00002.1.el7eap.noarch.rpm eap7-wildfly-javadocs-7.4.3-5.GA_redhat_00002.1.el7eap.noarch.rpm eap7-wildfly-modules-7.4.3-5.GA_redhat_00002.1.el7eap.noarch.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 8.References: https://access.redhat.com/security/cve/CVE-2021-3859 https://access.redhat.com/security/cve/CVE-2021-20318 https://access.redhat.com/security/updates/classification#important https://docs.redhat.com/en/documentation/red_hat_jboss_enterprise_application_platform/7.4 https://docs.redhat.com/en/documentation/red_hat_jboss_enterprise_application_platform/7.4/html-single/installation_guide/index 9. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2022 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBYfsRV9zjgjWX9erEAQgd2g/+PH98JXIAKYXEm9mbGRHZSE7b41L3szWD JKX4o/m3Cry1bWyXcZDRZpb1WqMLvSoOcjk6qqgtXl6pk5QfdjAxBE7RX2gBA8u7 HypuvLFubaUmNwMYHQWqiT6o0s5tR6dxzKWdWY5AMVYzmDpoliOJljIK+y+wBOQI 1sK0XjL/wVJtnevNmTd3jAD1aP2x7l7Da8/ti/NUhYr1zi+dBzLs/TwVh84aHW6z ojdgurRhzyyFqhecI1tFayiSYPmwwYhEUgju5dIWbb3KU8ow26N8heturH8yOZJ8 HZX2px3S8sbulbV3CvbE8oxp/f8cw2p+NoydtfALO6xsdY32TThU4l1ORNGQWOgj G5+oiZZDduiT3ERp39P5OMUcAQV7HooEE1UpR5dp9CpjqcpH8hbO9tUwIBJJmAKK cVL9pqtH/kPT5IGOE14mvU6Z89SPZ0Gz3ty3pEYzMlt9kj68Lyj8eicBM7nwfMSR dyHs9ZrLXFeA1y6Gt0WVsOlt9Er263X4XvDaHWxsTWSXTCnEdpwd1pFBSTDVck3N eLyN5LgLI0QCFCfqyKHTsuFFnkpnXlSOe0/XH0DnjA07/xWoiG94Xx34WGGsqNb5 DPSOP3rDeeiyVcBmhyuZYeXOfllFQxuEcZompS0O3TTh4bo9ilZkNVc4z2YSrYgh S35s4niI7G4=g6fX -----END PGP SIGNATURE----- -- RHSA-announce mailing list
An update is now available for Red Hat JBoss Enterprise Application Platform 7.3 for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: Red Hat JBoss Enterprise Application Platform 7.3.4 security update Advisory ID: RHSA-2020:5342-01 Product: Red Hat JBoss Enterprise Application Platform Advisory URL: https://access.redhat.com/errata/RHSA-2020:5342 Issue date: 2020-12-03 CVE Names: CVE-2020-25638 CVE-2020-25644 CVE-2020-25649 ==================================================================== 1. Summary: An update is now available for Red Hat JBoss Enterprise Application Platform 7.3 for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat JBoss EAP 7.3 for BaseOS-8 - noarch 3. Description: Red Hat JBoss Enterprise Application Platform 7 is a platform for Java applications based on the WildFly application runtime. This release of Red Hat JBoss Enterprise Application Platform 7.3.4 serves as a replacement for Red Hat JBoss Enterprise Application Platform 7.3.3, and includes bug fixes and enhancements. See the Red Hat JBoss Enterprise Application Platform 7.3.4 Release Notes for information about the most significant bug fixes and enhancements included in this release. Security Fix(es): * jackson-databind: FasterXML DOMDeserializer insecure entity expansion is vulnerable to XML external entity (CVE-2020-25649) * hibernate-core: SQL injection vulnerability whenboth hibernate.use_sql_comments and JPQL String literals are used (CVE-2020-25638) * wildfly-openssl: memory leak per HTTP session creation in WildFly OpenSSL (CVE-2020-25644) For more details about the security issue(s), including the impact, a CVSS score, and other related information, see the CVE page(s) listed in the References section. 4. Solution: Before applying this update, ensure all previously released errata relevant to your system have been applied. For details about how to apply this update, see: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1881353 - CVE-2020-25638 hibernate-core: SQL injection vulnerability when both hibernate.use_sql_comments and JPQL String literals are used 1885485 - CVE-2020-25644 wildfly-openssl: memory leak per HTTP session creation in WildFly OpenSSL 1887664 - CVE-2020-25649 jackson-databind: FasterXML DOMDeserializer insecure entity expansion is vulnerable to XML external entity (XXE) 6. JIRA issues fixed (https://issues.redhat.com/plugins/servlet/samlsso JBEAP-20029 - [GSS](7.3.z) Upgrade Artemis from 2.9.0.redhat-00011 to 2.9.0.redhat-00016 JBEAP-20089 - [GSS] (7.3.z) Upgrade undertow from 2.0.31.SP1-redhat-00001 to 2.0.32.SP1-redhat JBEAP-20119 - [GSS](7.3.z) Upgrade JBoss Remoting from 5.0.18.Final-redhat-00001 to 5.0.19.Final-redhat-00001 JBEAP-20161 - [GSS](7.3.z) Upgrade XNIO from 3.7.9.Final to 3.7.11.Final JBEAP-20223 - Tracker bug for the EAP 7.3.4 release for RHEL-8 JBEAP-20239 - [GSS](7.3.z) Upgrade Hibernate Validator from 6.0.20.Final to 6.0.21.Final JBEAP-20246 - [GSS](7.3.z) Upgrade JBoss Marshalling from 2.0.9.Final to 2.0.10.Final JBEAP-20285 - [GSS](7.3.z) Upgrade HAL from 3.2.10.Final-redhat-00001 to 3.2.11.Final JBEAP-20300 - (7.3.z) Upgrade jasypt from 1.9.3-redhat-00001 to 1.9.3-redhat-00002 JBEAP-20325 - (7.3.z) Upgrade WildFly Arquillian to 3.0.1.Final for the ts.bootable profile JBEAP-20364 - (7.3.z) Upgrade com.github.fge.msg-simple to 1.1.0.redhat-00007 and com.github.fge.btf to1.2.0.redhat-00007 JBEAP-20368 - (7.3.z) Upgrade Bootable JAR Maven plugin to 2.0.1.Final 7. Package List: Red Hat JBoss EAP 7.3 forBaseOS-8: Source: eap7-activemq-artemis-2.9.0-6.redhat_00016.1.el8eap.src.rpm eap7-fge-btf-1.2.0-1.redhat_00007.1.el8eap.src.rpm eap7-fge-msg-simple-1.1.0-1.redhat_00007.1.el8eap.src.rpm eap7-hal-console-3.2.11-1.Final_redhat_00001.1.el8eap.src.rpm eap7-hibernate-validator-6.0.21-1.Final_redhat_00001.1.el8eap.src.rpm eap7-jackson-annotations-2.10.4-1.redhat_00002.1.el8eap.src.rpm eap7-jackson-core-2.10.4-1.redhat_00002.1.el8eap.src.rpm eap7-jackson-coreutils-1.6.0-1.redhat_00006.1.el8eap.src.rpm eap7-jackson-jaxrs-providers-2.10.4-1.redhat_00002.1.el8eap.src.rpm eap7-jackson-modules-base-2.10.4-3.redhat_00002.1.el8eap.src.rpm eap7-jackson-modules-java8-2.10.4-1.redhat_00002.1.el8eap.src.rpm eap7-jasypt-1.9.3-1.redhat_00002.1.el8eap.src.rpm eap7-jboss-marshalling-2.0.10-1.Final_redhat_00001.1.el8eap.src.rpm eap7-jboss-remoting-5.0.19-1.Final_redhat_00001.1.el8eap.src.rpm eap7-jboss-server-migration-1.7.2-3.Final_redhat_00004.1.el8eap.src.rpm eap7-jboss-xnio-base-3.7.11-1.Final_redhat_00001.1.el8eap.src.rpm eap7-undertow-2.0.32-1.SP1_redhat_00001.1.el8eap.src.rpm eap7-wildfly-7.3.4-3.GA_redhat_00003.1.el8eap.src.rpm eap7-wildfly-elytron-1.10.9-1.Final_redhat_00001.1.el8eap.src.rpm eap7-wildfly-openssl-1.0.12-1.Final_redhat_00001.1.el8eap.src.rpm noarch: eap7-activemq-artemis-2.9.0-6.redhat_00016.1.el8eap.noarch.rpm eap7-activemq-artemis-cli-2.9.0-6.redhat_00016.1.el8eap.noarch.rpm eap7-activemq-artemis-commons-2.9.0-6.redhat_00016.1.el8eap.noarch.rpm eap7-activemq-artemis-core-client-2.9.0-6.redhat_00016.1.el8eap.noarch.rpm eap7-activemq-artemis-dto-2.9.0-6.redhat_00016.1.el8eap.noarch.rpm eap7-activemq-artemis-hornetq-protocol-2.9.0-6.redhat_00016.1.el8eap.noarch.rpm eap7-activemq-artemis-hqclient-protocol-2.9.0-6.redhat_00016.1.el8eap.noarch.rpm eap7-activemq-artemis-jdbc-store-2.9.0-6.redhat_00016.1.el8eap.noarch.rpm eap7-activemq-artemis-jms-client-2.9.0-6.redhat_00016.1.el8eap.noarch.rpm eap7-activemq-artemis-jms-server-2.9.0-6.redhat_00016.1.el8eap.noarch.rpm eap7-activemq-artemis-journal-2.9.0-6.redhat_00016.1.el8eap.noarch.rpm eap7-activemq-artemis-ra-2.9.0-6.redhat_00016.1.el8eap.noarch.rpm eap7-activemq-artemis-selector-2.9.0-6.redhat_00016.1.el8eap.noarch.rpm eap7-activemq-artemis-server-2.9.0-6.redhat_00016.1.el8eap.noarch.rpm eap7-activemq-artemis-service-extensions-2.9.0-6.redhat_00016.1.el8eap.noarch.rpm eap7-activemq-artemis-tools-2.9.0-6.redhat_00016.1.el8eap.noarch.rpm eap7-fge-btf-1.2.0-1.redhat_00007.1.el8eap.noarch.rpm eap7-fge-msg-simple-1.1.0-1.redhat_00007.1.el8eap.noarch.rpm eap7-hal-console-3.2.11-1.Final_redhat_00001.1.el8eap.noarch.rpm eap7-hibernate-validator-6.0.21-1.Final_redhat_00001.1.el8eap.noarch.rpm eap7-hibernate-validator-cdi-6.0.21-1.Final_redhat_00001.1.el8eap.noarch.rpm eap7-jackson-annotations-2.10.4-1.redhat_00002.1.el8eap.noarch.rpm eap7-jackson-core-2.10.4-1.redhat_00002.1.el8eap.noarch.rpm eap7-jackson-coreutils-1.6.0-1.redhat_00006.1.el8eap.noarch.rpm eap7-jackson-datatype-jdk8-2.10.4-1.redhat_00002.1.el8eap.noarch.rpm eap7-jackson-datatype-jsr310-2.10.4-1.redhat_00002.1.el8eap.noarch.rpm eap7-jackson-jaxrs-base-2.10.4-1.redhat_00002.1.el8eap.noarch.rpm eap7-jackson-jaxrs-json-provider-2.10.4-1.redhat_00002.1.el8eap.noarch.rpm eap7-jackson-module-jaxb-annotations-2.10.4-3.redhat_00002.1.el8eap.noarch.rpm eap7-jackson-modules-base-2.10.4-3.redhat_00002.1.el8eap.noarch.rpm eap7-jackson-modules-java8-2.10.4-1.redhat_00002.1.el8eap.noarch.rpm eap7-jasypt-1.9.3-1.redhat_00002.1.el8eap.noarch.rpm eap7-jboss-marshalling-2.0.10-1.Final_redhat_00001.1.el8eap.noarch.rpm eap7-jboss-marshalling-river-2.0.10-1.Final_redhat_00001.1.el8eap.noarch.rpm eap7-jboss-remoting-5.0.19-1.Final_redhat_00001.1.el8eap.noarch.rpm eap7-jboss-server-migration-1.7.2-3.Final_redhat_00004.1.el8eap.noarch.rpm eap7-jboss-server-migration-cli-1.7.2-3.Final_redhat_00004.1.el8eap.noarch.rpm eap7-jboss-server-migration-core-1.7.2-3.Final_redhat_00004.1.el8eap.noarch.rpm eap7-jboss-server-migration-eap6.4-1.7.2-3.Final_redhat_00004.1.el8eap.noarch.rpm eap7-jboss-server-migration-eap6.4-to-eap7.3-1.7.2-3.Final_redhat_00004.1.el8eap.noarch.rpm eap7-jboss-server-migration-eap7.0-1.7.2-3.Final_redhat_00004.1.el8eap.noarch.rpm eap7-jboss-server-migration-eap7.1-1.7.2-3.Final_redhat_00004.1.el8eap.noarch.rpm eap7-jboss-server-migration-eap7.2-1.7.2-3.Final_redhat_00004.1.el8eap.noarch.rpm eap7-jboss-server-migration-eap7.2-to-eap7.3-1.7.2-3.Final_redhat_00004.1.el8eap.noarch.rpm eap7-jboss-server-migration-eap7.3-server-1.7.2-3.Final_redhat_00004.1.el8eap.noarch.rpm eap7-jboss-server-migration-wildfly10.0-1.7.2-3.Final_redhat_00004.1.el8eap.noarch.rpm eap7-jboss-server-migration-wildfly10.1-1.7.2-3.Final_redhat_00004.1.el8eap.noarch.rpm eap7-jboss-server-migration-wildfly11.0-1.7.2-3.Final_redhat_00004.1.el8eap.noarch.rpm eap7-jboss-server-migration-wildfly12.0-1.7.2-3.Final_redhat_00004.1.el8eap.noarch.rpm eap7-jboss-server-migration-wildfly13.0-server-1.7.2-3.Final_redhat_00004.1.el8eap.noarch.rpm eap7-jboss-server-migration-wildfly14.0-server-1.7.2-3.Final_redhat_00004.1.el8eap.noarch.rpm eap7-jboss-server-migration-wildfly15.0-server-1.7.2-3.Final_redhat_00004.1.el8eap.noarch.rpm eap7-jboss-server-migration-wildfly16.0-server-1.7.2-3.Final_redhat_00004.1.el8eap.noarch.rpm eap7-jboss-server-migration-wildfly17.0-server-1.7.2-3.Final_redhat_00004.1.el8eap.noarch.rpm eap7-jboss-server-migration-wildfly18.0-server-1.7.2-3.Final_redhat_00004.1.el8eap.noarch.rpm eap7-jboss-server-migration-wildfly8.2-1.7.2-3.Final_redhat_00004.1.el8eap.noarch.rpm eap7-jboss-server-migration-wildfly9.0-1.7.2-3.Final_redhat_00004.1.el8eap.noarch.rpm eap7-jboss-xnio-base-3.7.11-1.Final_redhat_00001.1.el8eap.noarch.rpm eap7-undertow-2.0.32-1.SP1_redhat_00001.1.el8eap.noarch.rpm eap7-wildfly-7.3.4-3.GA_redhat_00003.1.el8eap.noarch.rpm eap7-wildfly-elytron-1.10.9-1.Final_redhat_00001.1.el8eap.noarch.rpm eap7-wildfly-elytron-tool-1.10.9-1.Final_redhat_00001.1.el8eap.noarch.rpm eap7-wildfly-javadocs-7.3.4-3.GA_redhat_00003.1.el8eap.noarch.rpm eap7-wildfly-modules-7.3.4-3.GA_redhat_00003.1.el8eap.noarch.rpm eap7-wildfly-openssl-1.0.12-1.Final_redhat_00001.1.el8eap.noarch.rpm eap7-wildfly-openssl-java-1.0.12-1.Final_redhat_00001.1.el8eap.noarch.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 8. References: https://access.redhat.com/security/cve/CVE-2020-25638 https://access.redhat.com/security/cve/CVE-2020-25644 https://access.redhat.com/security/cve/CVE-2020-25649 https://access.redhat.com/security/updates/classification/#important https://access.redhat.com/documentation/en-us/red_hat_jboss_enterprise_application_platform/7.3/ https://access.redhat.com/documentation/en-us/red_hat_jboss_enterprise_application_platform/7.3/html-single/installation_guide/ 9. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2020 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBX8k7Y9zjgjWX9erEAQgaMA/8D6uRPrTX/XmXtkeZw9Y9yMoLHIYpl083 iv71vIyCkmQXHFmsYidw0jI6euRhHmihMY5DMyci3zAHqa7KbX1pqQsXWPIvWVnv ykpkGtPGUoqlJU7FDZq00Vk+/bykOEIcAmBJJCoNuLAS09gub2l2UPD3QGC1cZfa 7ziYlGTufSOYN6RInoSGiOgqUpYQzF35oZT2Vwc5b92ZGx6rj08vrCGNmF9SXRYc +yy1IIVGMdYe/1IEcpq936F8AKxJYiqyhsLP4orkt1GxC5P8RGnGvUoIwZmrDq06 xBPP44WmbAmFu8t3hcBUBs+ewzAc9swmy7ZKu8yuJfmxcDlyz/pVpPg8tLfCZRbg XRekSfvEzRw6lidGv5vMqUUoRxJd5LicaWSW93jus01UahLVMTGyPMAVHcdeP1P7 n29R5ZNWk5e9cWCmTL10T3+6Rf4brnbUf09mCsgSwSsuejCoxdD0JLaC0z953cqC ga5z8xSYtXmQdhOKZIhQ17el2Prdw82Vw11dNFvN3AsQMu3exSOp+MAhh9bs5/Ba HcvSdryXIkEy/3atBUZxoDZu6ZJRHB0yWuk3CsvoW3lJuBGhVS1Wah+9g8Lq0H5y QkpRwaCU+SxNXG+VAq59ZP8jKyl87mMzRQ4w0touglb/YqSZfp2dpAqC5t8zPfeO B8NkNn8eYYs=+qXq -----END PGP SIGNATURE----- -- RHSA-announce mailing list
Updates to the latest upstream release of Eclipse. See the upstream release notes for details: https://eclipseide.org/release/noteworthy/ Also contains security fixes for CVE-2019-17566 and CVE-2019-17638.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-cf8ef2f333 2020-08-31 15:48:37.485399 --------------------------------------------------------------------------------Name : univocity-parsers Product : Fedora 32 Version : 2.8.4 Release : 5.fc32 URL : https://github.com/uniVocity/univocity-parsers Summary : Collection of parsers for Java Description : uniVocity-parsers is a suite of extremely fast and reliable parsers for Java. It provides a consistent interface for handling different file formats, and a solid framework for the development of new parsers. --------------------------------------------------------------------------------Update Information: Updates to the latest upstream release of Eclipse. See the upstream release notes for details: https://eclipseide.org/release/noteworthy/ Also contains security fixes for CVE-2019-17566 and CVE-2019-17638. --------------------------------------------------------------------------------ChangeLog: * Thu Aug 13 2020 Mat Booth - 2.8.4-5 - Make OSGi requirement on com.googlecode.openbeans optional * Wed Jul 29 2020 Fedora Release Engineering - 2.8.4-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild * Tue Jul 14 2020 Mat Booth - 2.8.4-3 - Allow building without tests * Sat Jul 11 2020 Jiri Vanek - 2.8.4-2 - Rebuilt for JDK-11, see https://fedoraproject.org/wiki/Changes/Java11 * Thu Feb 13 2020 Fabio Valentini - 2.8.4-1 - Update to version 2.8.4. --------------------------------------------------------------------------------References: [ 1 ] Bug #1848617 - CVE-2019-17566 batik: SSRF via "xlink:href" https://bugzilla.redhat.com/show_bug.cgi?id=1848617 [ 2 ] Bug #1864680 -CVE-2019-17638 jetty: double release of resource can lead to information disclosure https://bugzilla.redhat.com/show_bug.cgi?id=1864680 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-cf8ef2f333' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.