ELSA-2020-4305

ELSA-2020-4305 - java-11-openjdk security and bug fix update

Type:SECURITY
Impact:MODERATE
Release Date:2020-10-22

Description


[1:11.0.9.11-0]
- Update to jdk-11.0.9+11
- Update release notes for 11.0.9 release.
- Add backport of JDK-8254177 to update to tzdata 2020b
- Require tzdata 2020b due to resource changes in JDK-8254177
- Delay tzdata 2020b dependency until tzdata update has shipped.
- This tarball is embargoed until 2020-10-20 @ 1pm PT.
- Resolves: rhbz#1876665

[1:11.0.9.10-0.0.ea]
- Update to jdk-11.0.9+10 (EA)
- With Shenandoah now upstream in OpenJDK 11, we can use jdk-updates/jdk11 directly
- Following JDK-8005165, class data sharing can be enabled on all JIT architectures
- Update tarball generation script to use PR3802, handling JDK-8233228 & JDK-8177334
- Remove JDK-8252258/RH1868406 now applied upstream.
- Improve quoting of vendor name
- Resolves: rhbz#1876665

[1:11.0.9.10-0.0.ea]
- Set vendor property and vendor URLs
- Made URLs to be preconfigured by OS
- Moved vendor_version_string to a better place
- Resolves: rhbz#1876665

[1:11.0.9.10-0.0.ea]
- Update static-libs packaging to new layout
- Resolves: rhbz#1876665

[1:11.0.9.1-0.1.ea]
- Cleanup architecture and JVM feature handling in preparation for using upstreamed Shenandoah.
- Resolves: rhbz#1876665

[1:11.0.9.1-0.0.ea]
- Update to shenandoah-jdk-11.0.9+1 (EA)
- Switch to EA mode for 11.0.9 pre-release builds.
- JDK-8245832 increases the set of static libraries, so try and include them all with a wildcard.
- Resolves: rhbz#1876665

[1:11.0.8.10-2]
- Add JDK-8252258 to return default vendor to the original value of 'Oracle Corporation'
- Include a test in the RPM to check the build has the correct vendor information.
- Use 'oj_' prefix on new vendor globals to avoid a conflict with RPM's vendor value.
- Resolves: rhbz#1873390

[1:11.0.8.10-1]
- Added scriplet to handle dir->symlink change when updating el7->el8
- Symlink hunk moved behind the main copy logic, to be more user-friendly with multiple installs
- Resolves: rhbz#1871709


Related CVEs


CVE-2020-14803
CVE-2020-14782
CVE-2020-14779
CVE-2020-14797
CVE-2020-14796
CVE-2020-14781
CVE-2020-14792

Updated Packages


Release/ArchitectureFilenamesha256Superseded By AdvisoryChannel Label
Oracle Linux 8 (aarch64) java-11-openjdk-11.0.9.11-0.el8_2.src.rpmeca1b836c824305ff901f4006d5c8871270e0209a0a9448b8cae786a0d81da63-ol8_aarch64_appstream
java-11-openjdk-11.0.9.11-0.el8_2.aarch64.rpm138a831f30180d8f1d9b32379184d4ed851c7f18e8864a97880589fda4a7b74f-ol8_aarch64_appstream
java-11-openjdk-demo-11.0.9.11-0.el8_2.aarch64.rpme07d3c135b07dd6d81537712e8a1f5d15068716c2df6cc4adfa88fb6b2ebccb7-ol8_aarch64_appstream
java-11-openjdk-devel-11.0.9.11-0.el8_2.aarch64.rpma4b9a11c7385a3ff7f2ea624e122b8166657f901ae1366eb6139ff2f8f329f6a-ol8_aarch64_appstream
java-11-openjdk-headless-11.0.9.11-0.el8_2.aarch64.rpmd6d3d3abbb75a70a4a9be24c916cd3259fc817962237ebef1d7e3a9bb4b8fda1-ol8_aarch64_appstream
java-11-openjdk-javadoc-11.0.9.11-0.el8_2.aarch64.rpmef609e0d40297cb30ccec2a7d1beae5ab0bc1f8f4b02a96cfc3834d2382a8815-ol8_aarch64_appstream
java-11-openjdk-javadoc-zip-11.0.9.11-0.el8_2.aarch64.rpmaf1f924ba3ca14fe7a93c158973bed44f3bfc6ac00370207714a80bef1e2a339-ol8_aarch64_appstream
java-11-openjdk-jmods-11.0.9.11-0.el8_2.aarch64.rpm0b8322d7c2d35ae7fa3e29d6e8c44cd4e31e95afba8b505a7a3f234e422a766c-ol8_aarch64_appstream
java-11-openjdk-src-11.0.9.11-0.el8_2.aarch64.rpm0ffeb2d424602073de2bae10622b7c167150244c370b9159c1366475bd356d44-ol8_aarch64_appstream
java-11-openjdk-static-libs-11.0.9.11-0.el8_2.aarch64.rpm263e312b0f75f439f01cf0dbe0fbfbb6005cb0673d5de09635e55b7eb345717f-ol8_aarch64_appstream
Oracle Linux 8 (x86_64) java-11-openjdk-11.0.9.11-0.el8_2.src.rpmeca1b836c824305ff901f4006d5c8871270e0209a0a9448b8cae786a0d81da63-ol8_x86_64_appstream
java-11-openjdk-11.0.9.11-0.el8_2.x86_64.rpme733d1d332aa6a71b7902e907628353b8af8106c78c65e911ffc8894142e12a3-ol8_x86_64_appstream
java-11-openjdk-demo-11.0.9.11-0.el8_2.x86_64.rpmd95be1ca023a341d5fcc7c858ff3e54c2d2fa570f1b7f10154cf052bef3b3942-ol8_x86_64_appstream
java-11-openjdk-devel-11.0.9.11-0.el8_2.x86_64.rpm0788162a3df462124f38e7ad7a743edfca45ebf7e910e3775200810220c51c51-ol8_x86_64_appstream
java-11-openjdk-headless-11.0.9.11-0.el8_2.x86_64.rpmeeb1b13d4d57eeb70ca08ddb516a3bb0ea7c4509cbf2ee1e2986df98fd15bb4e-ol8_x86_64_appstream
java-11-openjdk-javadoc-11.0.9.11-0.el8_2.x86_64.rpmae4c50d1fc88f7a7b3808d1b67c3729e9f19b8e5539b411f45e5b89b73086f17-ol8_x86_64_appstream
java-11-openjdk-javadoc-zip-11.0.9.11-0.el8_2.x86_64.rpmdf552adb2bbd62837a0fb753af75469324a43d38ead0a808dbab3206b2e291bd-ol8_x86_64_appstream
java-11-openjdk-jmods-11.0.9.11-0.el8_2.x86_64.rpmef6f2a5c5a75ac045a5dda5d7e6c3f5dab94c1572698d17c35ac22f131131e2c-ol8_x86_64_appstream
java-11-openjdk-src-11.0.9.11-0.el8_2.x86_64.rpm73f0c75e5f8f8a1325b2e4d46ce41b7181ab4e06073d19bcc5344265595c0f13-ol8_x86_64_appstream
java-11-openjdk-static-libs-11.0.9.11-0.el8_2.x86_64.rpm1cdc783fa79eddbdae9eba9f7f9913027d0b96483af52be8f9b1d707d9238fd6-ol8_x86_64_appstream



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete