The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-8921 http://linux.oracle.com/errata/ELSA-2026-8921.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable LinuxNetwork: x86_64: kernel-5.14.0-611.49.1.el9_7.x86_64.rpm kernel-abi-stablelists-5.14.0-611.49.1.el9_7.noarch.rpm kernel-core-5.14.0-611.49.1.el9_7.x86_64.rpm kernel-cross-headers-5.14.0-611.49.1.el9_7.x86_64.rpm kernel-debug-5.14.0-611.49.1.el9_7.x86_64.rpm kernel-debug-core-5.14.0-611.49.1.el9_7.x86_64.rpm kernel-debug-devel-5.14.0-611.49.1.el9_7.x86_64.rpm kernel-debug-devel-matched-5.14.0-611.49.1.el9_7.x86_64.rpm kernel-debug-modules-5.14.0-611.49.1.el9_7.x86_64.rpm kernel-debug-modules-core-5.14.0-611.49.1.el9_7.x86_64.rpm kernel-debug-modules-extra-5.14.0-611.49.1.el9_7.x86_64.rpm kernel-debug-uki-virt-5.14.0-611.49.1.el9_7.x86_64.rpm kernel-devel-5.14.0-611.49.1.el9_7.x86_64.rpm kernel-devel-matched-5.14.0-611.49.1.el9_7.x86_64.rpm kernel-doc-5.14.0-611.49.1.el9_7.noarch.rpm kernel-headers-5.14.0-611.49.1.el9_7.x86_64.rpm kernel-modules-5.14.0-611.49.1.el9_7.x86_64.rpm kernel-modules-core-5.14.0-611.49.1.el9_7.x86_64.rpm kernel-modules-extra-5.14.0-611.49.1.el9_7.x86_64.rpm kernel-tools-5.14.0-611.49.1.el9_7.x86_64.rpm kernel-tools-libs-5.14.0-611.49.1.el9_7.x86_64.rpm kernel-tools-libs-devel-5.14.0-611.49.1.el9_7.x86_64.rpm kernel-uki-virt-5.14.0-611.49.1.el9_7.x86_64.rpm kernel-uki-virt-addons-5.14.0-611.49.1.el9_7.x86_64.rpm libperf-5.14.0-611.49.1.el9_7.x86_64.rpm perf-5.14.0-611.49.1.el9_7.x86_64.rpm python3-perf-5.14.0-611.49.1.el9_7.x86_64.rpm rtla-5.14.0-611.49.1.el9_7.x86_64.rpm rv-5.14.0-611.49.1.el9_7.x86_64.rpm aarch64: kernel-cross-headers-5.14.0-611.49.1.el9_7.aarch64.rpm kernel-headers-5.14.0-611.49.1.el9_7.aarch64.rpm kernel-tools-5.14.0-611.49.1.el9_7.aarch64.rpm kernel-tools-libs-5.14.0-611.49.1.el9_7.aarch64.rpm kernel-tools-libs-devel-5.14.0-611.49.1.el9_7.aarch64.rpm libperf-5.14.0-611.49.1.el9_7.aarch64.rpm perf-5.14.0-611.49.1.el9_7.aarch64.rpm python3-perf-5.14.0-611.49.1.el9_7.aarch64.rpm rtla-5.14.0-611.49.1.el9_7.aarch64.rpm rv-5.14.0-611.49.1.el9_7.aarch64.rpm SRPMS: http://oss.oracle.com/ol9/SRPMS-updates/kernel-5.14.0-611.49.1.el9_7.src.rpm RelatedCVEs: CVE-2025-39766 CVE-2025-68741 Description of changes: [5.14.0-611.49.1] - Disable UKI signing [Orabug: 36571828] - Update Oracle Linux certificates (Kevin Lyons) - Disable signing for aarch64 (Ilya Okomin) - Oracle Linux RHCK Module Signing Key was added to the kernel trusted keys list (olkmod_signing_key.pem) [Orabug: 29539237] - Update x509.genkey [Orabug: 24817676] - Conflict with shim-ia32 and shim-x64
Change for system JDK from 17 to 21. upstream security release 122.0.6261.94 High CVE-2024-1938: Type Confusion in V8 High CVE-2024-1939: Type Confusion in V8 fixed bug with requires. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-129d8ca6fc 2024-03-07 22:24:39.963937 -------------------------------------------------------------------------------- Name : xmvn-connector-ivy Product : Fedora 40 Version : 4.0.0 Release : 3.fc40 URL : https://fedora-java.github.io/xmvn/ Summary : XMvn Connector for Apache Ivy Description : This package provides XMvn Connector for Apache Ivy, which provides integration of Apache Ivy with XMvn. It provides an adapter which allows XMvn resolver to be used as Ivy resolver. -------------------------------------------------------------------------------- Update Information: Change for system JDK from 17 to 21. upstream security release 122.0.6261.94 High CVE-2024-1938: Type Confusion in V8 High CVE-2024-1939: Type Confusion in V8 fixed bug with requires Automatic update for lucene-9.9.2-1.fc40. bump java source/target to 1.8, fixes 2266639 -------------------------------------------------------------------------------- ChangeLog: * Sat Mar 2 2024 Jiri Vanek - 4.0.0-3 - Rebuilt for java-21-openjdk as system jdk -------------------------------------------------------------------------------- References: [ 1 ] Bug #2123726 - consoleImageViewer crashes at start https://bugzilla.redhat.com/show_bug.cgi?id=2123726 [ 2 ] Bug #2261062 - directory-maven-plugin: FTBFS in Fedora rawhide/f40 https://bugzilla.redhat.com/show_bug.cgi?id=2261062 [ 3 ] Bug #2266639 - directory-maven-plugin fails to build with java-21-openjdk https://bugzilla.redhat.com/show_bug.cgi?id=2266639 [ 4 ] Bug #2266934 - CVE-2024-1938 chromium: type confusion [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2266934 [ 5 ] Bug#2266937 - CVE-2024-1939 chromium: type confusion [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2266937 [ 6 ] Bug #2267486 - Include Java 21 as system Java Change in Fedora 40 Beta https://bugzilla.redhat.com/show_bug.cgi?id=2267486 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-129d8ca6fc' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Change for system JDK from 17 to 21. upstream security release 122.0.6261.94 High CVE-2024-1938: Type Confusion in V8 High CVE-2024-1939: Type Confusion in V8 fixed bug with requires. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-129d8ca6fc 2024-03-07 22:24:39.963937 -------------------------------------------------------------------------------- Name : jakarta-xml-ws Product : Fedora 40 Version : 4.0.0 Release : 6.fc40 URL : https://github.com/jakartaee/jax-ws-api Summary : Jakarta XML Web Services API Description : Jakarta XML Web Services defines a means for implementing XML-Based Web Services based on Jakarta SOAP with Attachments and Jakarta Web Services Metadata. -------------------------------------------------------------------------------- Update Information: Change for system JDK from 17 to 21. upstream security release 122.0.6261.94 High CVE-2024-1938: Type Confusion in V8 High CVE-2024-1939: Type Confusion in V8 fixed bug with requires Automatic update for lucene-9.9.2-1.fc40. bump java source/target to 1.8, fixes 2266639 -------------------------------------------------------------------------------- ChangeLog: * Sat Mar 2 2024 Jiri Vanek - 4.0.0-6 - Rebuilt for java-21-openjdk as system jdk -------------------------------------------------------------------------------- References: [ 1 ] Bug #2123726 - consoleImageViewer crashes at start https://bugzilla.redhat.com/show_bug.cgi?id=2123726 [ 2 ] Bug #2261062 - directory-maven-plugin: FTBFS in Fedora rawhide/f40 https://bugzilla.redhat.com/show_bug.cgi?id=2261062 [ 3 ] Bug #2266639 - directory-maven-plugin fails to build with java-21-openjdk https://bugzilla.redhat.com/show_bug.cgi?id=2266639 [ 4 ] Bug #2266934 - CVE-2024-1938 chromium: type confusion [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2266934 [ 5 ] Bug #2266937 - CVE-2024-1939chromium: type confusion [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2266937 [ 6 ] Bug #2267486 - Include Java 21 as system Java Change in Fedora 40 Beta https://bugzilla.redhat.com/show_bug.cgi?id=2267486 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-129d8ca6fc' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2023-12800 https://linux.oracle.com/errata/ELSA-2023-12800.html The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: x86_64: kernel-uek-doc-4.1.12-124.78.4.1.el7uek.noarch.rpm kernel-uek-firmware-4.1.12-124.78.4.1.el7uek.noarch.rpm kernel-uek-4.1.12-124.78.4.1.el7uek.x86_64.rpm kernel-uek-devel-4.1.12-124.78.4.1.el7uek.x86_64.rpm kernel-uek-debug-4.1.12-124.78.4.1.el7uek.x86_64.rpm kernel-uek-debug-devel-4.1.12-124.78.4.1.el7uek.x86_64.rpm SRPMS: https://oss.oracle.com:443/ol7/SRPMS-updates//kernel-uek-4.1.12-124.78.4.1.el7uek.src.rpm Related CVEs: CVE-2023-22024 Description of changes: [4.1.12-124.78.4.1.el7uek] - rds: Fix lack of reentrancy for connection reset with dst addr zero (HÃ¥kon Bugge) [Orabug: 35741584] {CVE-2023-22024} _______________________________________________ El-errata mailing list
Get the latest Linux and open source security news straight to your inbox.