ELSA-2020-4305

ELSA-2020-4305 - java-11-openjdk security and bug fix update

Type:SECURITY
Severity:MODERATE
Release Date:2020-10-22

Description


[1:11.0.9.11-0]
- Update to jdk-11.0.9+11
- Update release notes for 11.0.9 release.
- Add backport of JDK-8254177 to update to tzdata 2020b
- Require tzdata 2020b due to resource changes in JDK-8254177
- Delay tzdata 2020b dependency until tzdata update has shipped.
- This tarball is embargoed until 2020-10-20 @ 1pm PT.
- Resolves: rhbz#1876665

[1:11.0.9.10-0.0.ea]
- Update to jdk-11.0.9+10 (EA)
- With Shenandoah now upstream in OpenJDK 11, we can use jdk-updates/jdk11 directly
- Following JDK-8005165, class data sharing can be enabled on all JIT architectures
- Update tarball generation script to use PR3802, handling JDK-8233228 & JDK-8177334
- Remove JDK-8252258/RH1868406 now applied upstream.
- Improve quoting of vendor name
- Resolves: rhbz#1876665

[1:11.0.9.10-0.0.ea]
- Set vendor property and vendor URLs
- Made URLs to be preconfigured by OS
- Moved vendor_version_string to a better place
- Resolves: rhbz#1876665

[1:11.0.9.10-0.0.ea]
- Update static-libs packaging to new layout
- Resolves: rhbz#1876665

[1:11.0.9.1-0.1.ea]
- Cleanup architecture and JVM feature handling in preparation for using upstreamed Shenandoah.
- Resolves: rhbz#1876665

[1:11.0.9.1-0.0.ea]
- Update to shenandoah-jdk-11.0.9+1 (EA)
- Switch to EA mode for 11.0.9 pre-release builds.
- JDK-8245832 increases the set of static libraries, so try and include them all with a wildcard.
- Resolves: rhbz#1876665

[1:11.0.8.10-2]
- Add JDK-8252258 to return default vendor to the original value of 'Oracle Corporation'
- Include a test in the RPM to check the build has the correct vendor information.
- Use 'oj_' prefix on new vendor globals to avoid a conflict with RPM's vendor value.
- Resolves: rhbz#1873390

[1:11.0.8.10-1]
- Added scriplet to handle dir->symlink change when updating el7->el8
- Symlink hunk moved behind the main copy logic, to be more user-friendly with multiple installs
- Resolves: rhbz#1871709


Related CVEs


CVE-2020-14779
CVE-2020-14781
CVE-2020-14796
CVE-2020-14797
CVE-2020-14803
CVE-2020-14782
CVE-2020-14792

Updated Packages


Release/ArchitectureFilenameMD5sumSuperseded By Advisory
Oracle Linux 8 (aarch64) java-11-openjdk-11.0.9.11-0.el8_2.src.rpmcd2f85902a5242992f3cade9e9dd2675-
java-11-openjdk-11.0.9.11-0.el8_2.aarch64.rpm9366be541b64b7dadc96c2ffe8847b97-
java-11-openjdk-demo-11.0.9.11-0.el8_2.aarch64.rpm9a5cdf1a1ead3aeacecd31bd61169a25-
java-11-openjdk-devel-11.0.9.11-0.el8_2.aarch64.rpm2064d006f3cabb46429b66b120831416-
java-11-openjdk-headless-11.0.9.11-0.el8_2.aarch64.rpm4d2ef2aaff2a20dac91ceb010f5dab28-
java-11-openjdk-javadoc-11.0.9.11-0.el8_2.aarch64.rpmff1ef98becfe9ecde806c5b8048655aa-
java-11-openjdk-javadoc-zip-11.0.9.11-0.el8_2.aarch64.rpm9f56821cbe1ed1e59001d686acecb111-
java-11-openjdk-jmods-11.0.9.11-0.el8_2.aarch64.rpmba9a12aa80d9abe705673af90b7eb001-
java-11-openjdk-src-11.0.9.11-0.el8_2.aarch64.rpm53a4982a05bb79207db94307eb006d24-
java-11-openjdk-static-libs-11.0.9.11-0.el8_2.aarch64.rpmd9e267fbb426f7504a2c4047909a0faa-
Oracle Linux 8 (x86_64) java-11-openjdk-11.0.9.11-0.el8_2.src.rpmcd2f85902a5242992f3cade9e9dd2675-
java-11-openjdk-11.0.9.11-0.el8_2.x86_64.rpmacfa2dd9d81b9b541f9f7c2c1ee88cf2-
java-11-openjdk-demo-11.0.9.11-0.el8_2.x86_64.rpm833ec3fc3b440e650339b3b1e0d4cf1c-
java-11-openjdk-devel-11.0.9.11-0.el8_2.x86_64.rpm77c32c45a1ef97a1ac38ae7bde2a8cea-
java-11-openjdk-headless-11.0.9.11-0.el8_2.x86_64.rpma9934c8e12a64ec5f5755964b6fd0d65-
java-11-openjdk-javadoc-11.0.9.11-0.el8_2.x86_64.rpmc7b9170048581905128239c7065065bb-
java-11-openjdk-javadoc-zip-11.0.9.11-0.el8_2.x86_64.rpm91c7fc8306b8b9c4cfbc6db9be20fa6c-
java-11-openjdk-jmods-11.0.9.11-0.el8_2.x86_64.rpm3aa5c3e7c1f01beea53fba5d02245c22-
java-11-openjdk-src-11.0.9.11-0.el8_2.x86_64.rpm45b4e8449e56169144235e42c151a457-
java-11-openjdk-static-libs-11.0.9.11-0.el8_2.x86_64.rpm1438097660d5df561af54b16d0f6166d-



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete