ELSA-2022-5695

ELSA-2022-5695 - java-11-openjdk security, bug fix, and enhancement update

Type:SECURITY
Impact:IMPORTANT
Release Date:2022-07-26

Description


[1:11.0.16.0.8-1.0.1]
- Replace upstream references [Orabug: 34340155]

[1:11.0.16.0.8-1]
- Update to jdk-11.0.16+8
- Update release notes to 11.0.16+8
- Use same tarball naming style as java-17-openjdk and java-latest-openjdk
- Drop JDK-8257794 patch now upstreamed
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use 'git apply' with patches in the tarball script to allow binary diffs
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Make use of the vendor version string to store our version & release rather than an upstream release date
- Explicitly require crypto-policies during build and runtime for system security properties
- Rebase FIPS patches from fips branch and simplify by using a single patch from that repository
- * RH2036462: sun.security.pkcs11.wrapper.PKCS11.getInstance breakage
- * RH2090378: Revert to disabling system security properties and FIPS mode support together
- Rebase RH1648249 nss.cfg patch so it applies after the FIPS patch
- Enable system security properties in the RPM (now disabled by default in the FIPS repo)
- Improve security properties test to check both enabled and disabled behaviour
- Run security properties test with property debugging on
- Resolves: rhbz#2106516
- Resolves: rhbz#2099915
- Resolves: rhbz#2107868

[1:11.0.16.0.8-1]
- Add additional patch during tarball generation to align tests with ECC changes
- Related: rhbz#2106516

[1:11.0.16.0.8-1]
- RH2007331: SecretKey generate/import operations don't add the CKA_SIGN attribute in FIPS mode
- Resolves: rhbz#2107866


Related CVEs


CVE-2022-34169
CVE-2022-21541
CVE-2022-21540

Updated Packages


Release/ArchitectureFilenamesha256Superseded By AdvisoryChannel Label
Oracle Linux 9 (aarch64) java-11-openjdk-11.0.16.0.8-1.0.1.el9_0.src.rpm4d1d701c144a64a826bfc036db816e8e7106c117ad7c31eb697be70edcd611b3-ol9_aarch64_appstream
java-11-openjdk-11.0.16.0.8-1.0.1.el9_0.src.rpm4d1d701c144a64a826bfc036db816e8e7106c117ad7c31eb697be70edcd611b3-ol9_aarch64_codeready_builder
java-11-openjdk-11.0.16.0.8-1.0.1.el9_0.aarch64.rpme5433dfd023103bb741b3eaa6fc840c371f59d04ea3b86c7de955c72d8a426c7-ol9_aarch64_appstream
java-11-openjdk-demo-11.0.16.0.8-1.0.1.el9_0.aarch64.rpmba36c5c94235adea5987fabdfe8efb9738c4dad854e53a8ef1ea9ae832c1bda2-ol9_aarch64_appstream
java-11-openjdk-demo-fastdebug-11.0.16.0.8-1.0.1.el9_0.aarch64.rpm70fbf14c4e584925f4c6f5799f35bef023416e4815dae5d4efdd843c4f48dd5f-ol9_aarch64_codeready_builder
java-11-openjdk-demo-slowdebug-11.0.16.0.8-1.0.1.el9_0.aarch64.rpmf758fc52272677eb2fd0c87a0adf0ac64ea684d4f14f7406041267f31cfb0378-ol9_aarch64_codeready_builder
java-11-openjdk-devel-11.0.16.0.8-1.0.1.el9_0.aarch64.rpm85688f0b566f2465335d7ff06a0e8662e5b1a7e57a4ab11340bad6d096b15574-ol9_aarch64_appstream
java-11-openjdk-devel-fastdebug-11.0.16.0.8-1.0.1.el9_0.aarch64.rpm2a44f6d58cd8b77f202c8231a95b7d37ff47505a15f087825a526bb646d8033b-ol9_aarch64_codeready_builder
java-11-openjdk-devel-slowdebug-11.0.16.0.8-1.0.1.el9_0.aarch64.rpm245ca7b87fad74d2d8dbec48fa11deff4b67f7a0822e12a80061e18d9c1619f4-ol9_aarch64_codeready_builder
java-11-openjdk-fastdebug-11.0.16.0.8-1.0.1.el9_0.aarch64.rpm016a5c3494963dd47ed902d0a49597e513d64528575da6254bd17ada02caf9b2-ol9_aarch64_codeready_builder
java-11-openjdk-headless-11.0.16.0.8-1.0.1.el9_0.aarch64.rpm154e82ea5f706498bd7c0b529aa2e61545f6d3b9674c9e135ce2089e9d036e08-ol9_aarch64_appstream
java-11-openjdk-headless-fastdebug-11.0.16.0.8-1.0.1.el9_0.aarch64.rpm6fdf4d2e4384a2778ffd3af09adf74e3c59fd2ac5668abb07ce187da2be42ab3-ol9_aarch64_codeready_builder
java-11-openjdk-headless-slowdebug-11.0.16.0.8-1.0.1.el9_0.aarch64.rpm12ada240746e043dc7274e2c22c6f6753802f544e2875f006a21b68da87d2633-ol9_aarch64_codeready_builder
java-11-openjdk-javadoc-11.0.16.0.8-1.0.1.el9_0.aarch64.rpm01c6aab0f0d44235ac30a926b0fed8f2c131ccc4cbedad049937268a4ca7dfb0-ol9_aarch64_appstream
java-11-openjdk-javadoc-zip-11.0.16.0.8-1.0.1.el9_0.aarch64.rpm77c3af720320af920561b214f16e2bf45abb101ef32c25296659edb40c84bf04-ol9_aarch64_appstream
java-11-openjdk-jmods-11.0.16.0.8-1.0.1.el9_0.aarch64.rpmff7a2020c09e7fdcdf7caa0e34083830da1b2e2907d276fbbbe1d9c41a4d495c-ol9_aarch64_appstream
java-11-openjdk-jmods-fastdebug-11.0.16.0.8-1.0.1.el9_0.aarch64.rpm4b1ec0ee7885f2cae2b3c5059a9f72c3af7eba21d51395a8d989b9494795f232-ol9_aarch64_codeready_builder
java-11-openjdk-jmods-slowdebug-11.0.16.0.8-1.0.1.el9_0.aarch64.rpm5db4b3be6db6ab3698b40e1623176db5c85a42f3b91c2e71cc8881decb19a279-ol9_aarch64_codeready_builder
java-11-openjdk-slowdebug-11.0.16.0.8-1.0.1.el9_0.aarch64.rpm39a980a25c3e0b275641765165d9a777d6e62f74a4f7f30d5a3c9956d2a6b49b-ol9_aarch64_codeready_builder
java-11-openjdk-src-11.0.16.0.8-1.0.1.el9_0.aarch64.rpm449641113b58a5be205ab96066005153ef8a8adc87a9ff24ec1d797f1e9bab05-ol9_aarch64_appstream
java-11-openjdk-src-fastdebug-11.0.16.0.8-1.0.1.el9_0.aarch64.rpmc70ca85b8db3ac286882ff2ceee6564904ed0d8f2fbfdcf88b184453331e4352-ol9_aarch64_codeready_builder
java-11-openjdk-src-slowdebug-11.0.16.0.8-1.0.1.el9_0.aarch64.rpm789bb8b5d36d2d633d505a9ecb04d2391af06df37a879099068d80744f79cac7-ol9_aarch64_codeready_builder
java-11-openjdk-static-libs-11.0.16.0.8-1.0.1.el9_0.aarch64.rpmac8114b6085aa5203f7fcb6ab4dbc100b2afd2d527e87dd57d7609b832ad76f9-ol9_aarch64_appstream
java-11-openjdk-static-libs-fastdebug-11.0.16.0.8-1.0.1.el9_0.aarch64.rpme52a93d5fffc821dd3e491a2144cea24fb06d3aa27b15cf7ec726f6a433c1cf9-ol9_aarch64_codeready_builder
java-11-openjdk-static-libs-slowdebug-11.0.16.0.8-1.0.1.el9_0.aarch64.rpm461c9a295302e441f8472f138fc73abf4244d376db223c49945290a413437b8e-ol9_aarch64_codeready_builder
Oracle Linux 9 (x86_64) java-11-openjdk-11.0.16.0.8-1.0.1.el9_0.src.rpm4d1d701c144a64a826bfc036db816e8e7106c117ad7c31eb697be70edcd611b3-ol9_x86_64_appstream
java-11-openjdk-11.0.16.0.8-1.0.1.el9_0.src.rpm4d1d701c144a64a826bfc036db816e8e7106c117ad7c31eb697be70edcd611b3-ol9_x86_64_codeready_builder
java-11-openjdk-11.0.16.0.8-1.0.1.el9_0.x86_64.rpm8f245db0125d7973856bc301c967022d01ee7098bc4bb327fbf3878cf4803ef7-ol9_x86_64_appstream
java-11-openjdk-demo-11.0.16.0.8-1.0.1.el9_0.x86_64.rpm50996467a9016c6ec4181965f3136af0c5b9f2443dc3048576241751b3e81917-ol9_x86_64_appstream
java-11-openjdk-demo-fastdebug-11.0.16.0.8-1.0.1.el9_0.x86_64.rpmff70ed6ea263151a35ef5e2b3ad62d10f6bd5848ad5b470df78b2cba429ea797-ol9_x86_64_codeready_builder
java-11-openjdk-demo-slowdebug-11.0.16.0.8-1.0.1.el9_0.x86_64.rpm4788440f5cf02f4535828e28d8f6b69138aedf60f263cdf845d2efdb82ec463f-ol9_x86_64_codeready_builder
java-11-openjdk-devel-11.0.16.0.8-1.0.1.el9_0.x86_64.rpmfdb31824f9c0dd99bbb76c13bda24d2df0fb0bf6af82353b0e6a914c95ff673f-ol9_x86_64_appstream
java-11-openjdk-devel-fastdebug-11.0.16.0.8-1.0.1.el9_0.x86_64.rpmc8883d3a746635ddd9ef8780acb8f7ea1df4797cf6874df367764b75faa7a970-ol9_x86_64_codeready_builder
java-11-openjdk-devel-slowdebug-11.0.16.0.8-1.0.1.el9_0.x86_64.rpm614eef2a0b81c2dcd8e1f078a08195b75beb7c4f54dbffb026148e9446a8a290-ol9_x86_64_codeready_builder
java-11-openjdk-fastdebug-11.0.16.0.8-1.0.1.el9_0.x86_64.rpmdbc05fbd2e5e2f5f5ce736f42d4f29ead4ead4d79e43bc844cee757e39e3322c-ol9_x86_64_codeready_builder
java-11-openjdk-headless-11.0.16.0.8-1.0.1.el9_0.x86_64.rpmec82f5294359a0ea20bf05786472620f7b43cad15381c40b36e270ab8832092d-ol9_x86_64_appstream
java-11-openjdk-headless-fastdebug-11.0.16.0.8-1.0.1.el9_0.x86_64.rpm9200d54b97068feb72143a5da25c0295da5c12c19d7dedf03a72e5c91b8671ab-ol9_x86_64_codeready_builder
java-11-openjdk-headless-slowdebug-11.0.16.0.8-1.0.1.el9_0.x86_64.rpm8758c8b510361e151093fe59c7dd35dfd14fed722bf70ecfe703a1690fae0823-ol9_x86_64_codeready_builder
java-11-openjdk-javadoc-11.0.16.0.8-1.0.1.el9_0.x86_64.rpm31432b8916fe8b50a6833768a1c765f9d61179bc68fa8bc472fed9142c285cd2-ol9_x86_64_appstream
java-11-openjdk-javadoc-zip-11.0.16.0.8-1.0.1.el9_0.x86_64.rpm66b4f11da58419474f87e635a96e35dc267e9f1993453b3af81e3bc5f18ce065-ol9_x86_64_appstream
java-11-openjdk-jmods-11.0.16.0.8-1.0.1.el9_0.x86_64.rpm0fc52def1fbe96d6122fd6053a07f359b8e4971ee80590ae54b55154e7a3ceeb-ol9_x86_64_appstream
java-11-openjdk-jmods-fastdebug-11.0.16.0.8-1.0.1.el9_0.x86_64.rpm00d563138e1776ed120488c44ac1f1b2ee59e89c5f0ba2a01ec59f3d41db165e-ol9_x86_64_codeready_builder
java-11-openjdk-jmods-slowdebug-11.0.16.0.8-1.0.1.el9_0.x86_64.rpm37b7ba177ffd3489c7d60031240ff28788d664c79f36de32075a6c2e7e6a06a0-ol9_x86_64_codeready_builder
java-11-openjdk-slowdebug-11.0.16.0.8-1.0.1.el9_0.x86_64.rpm3a9a1d9179151d91b428724e6091b31ff66235caecd1b3268e8171bb1e7b8692-ol9_x86_64_codeready_builder
java-11-openjdk-src-11.0.16.0.8-1.0.1.el9_0.x86_64.rpme0c1ded48298ae9235f3555d2569fb3f9352e0ec72d87d029665780051590313-ol9_x86_64_appstream
java-11-openjdk-src-fastdebug-11.0.16.0.8-1.0.1.el9_0.x86_64.rpmf8b9f002ab5571faab030e438c26d440cd999ca238e8020e2dd2edf4c9b8412c-ol9_x86_64_codeready_builder
java-11-openjdk-src-slowdebug-11.0.16.0.8-1.0.1.el9_0.x86_64.rpmbf02578e4de34a708762d8a0521b2388f408007e5584336f69cf2d35518fd6a5-ol9_x86_64_codeready_builder
java-11-openjdk-static-libs-11.0.16.0.8-1.0.1.el9_0.x86_64.rpmce94e4bf83b86ba59f4e96f3a29a3b7c839836840c10c505a26e307f89fd9e16-ol9_x86_64_appstream
java-11-openjdk-static-libs-fastdebug-11.0.16.0.8-1.0.1.el9_0.x86_64.rpm73d24f32a8ac4d84f5165f0d55e87be2e56fee044be9118b4f7ebfc50e71b25e-ol9_x86_64_codeready_builder
java-11-openjdk-static-libs-slowdebug-11.0.16.0.8-1.0.1.el9_0.x86_64.rpm69514d4c734d621a021f030777a748539b5e070f64cf3d625ee82d1c85220b59-ol9_x86_64_codeready_builder



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete