ELSA-2022-5683

ELSA-2022-5683 - java-11-openjdk security, bug fix, and enhancement update

Type:SECURITY
Impact:IMPORTANT
Release Date:2022-07-21

Description


[1:11.0.16.0.8-1]
- Update to jdk-11.0.16+8
- Update release notes to 11.0.16+8
- Use same tarball naming style as java-17-openjdk and java-latest-openjdk
- Drop JDK-8257794 patch now upstreamed
- Print release file during build, which should now include a correct SOURCE value from .src-rev
- Update tarball script with IcedTea GitHub URL and .src-rev generation
- Use 'git apply' with patches in the tarball script to allow binary diffs
- Include script to generate bug list for release notes
- Update tzdata requirement to 2022a to match JDK-8283350
- Make use of the vendor version string to store our version & release rather than an upstream release date
- Explicitly require crypto-policies during build and runtime for system security properties
- Rebase FIPS patches from fips branch and simplify by using a single patch from that repository
- * RH2036462: sun.security.pkcs11.wrapper.PKCS11.getInstance breakage
- * RH2090378: Revert to disabling system security properties and FIPS mode support together
- Rebase RH1648249 nss.cfg patch so it applies after the FIPS patch
- Enable system security properties in the RPM (now disabled by default in the FIPS repo)
- Improve security properties test to check both enabled and disabled behaviour
- Run security properties test with property debugging on
- Resolves: rhbz#2106514
- Resolves: rhbz#2099917
- Resolves: rhbz#2108248
- Resolves: rhbz#2084649

[1:11.0.16.0.8-1]
- Add additional patch during tarball generation to align tests with ECC changes
- Related: rhbz#2084649

[1:11.0.16.0.8-1]
- RH2007331: SecretKey generate/import operations don't add the CKA_SIGN attribute in FIPS mode
- Resolves: rhbz#2108251


Related CVEs


CVE-2022-21541
CVE-2022-21540
CVE-2022-34169

Updated Packages


Release/ArchitectureFilenamesha256Superseded By AdvisoryChannel Label
Oracle Linux 8 (aarch64) java-11-openjdk-11.0.16.0.8-1.el8_6.src.rpm4facc3b75a4af5f768c466153a67f1b4431b1021a8fc2d3fe88f1487cbb645ef-ol8_aarch64_appstream
java-11-openjdk-11.0.16.0.8-1.el8_6.src.rpm4facc3b75a4af5f768c466153a67f1b4431b1021a8fc2d3fe88f1487cbb645ef-ol8_aarch64_codeready_builder
java-11-openjdk-11.0.16.0.8-1.el8_6.aarch64.rpm1b74baa1b2f28c897885bb10f5b627b7b399ca1e7312a32176b45bf422b15f6d-ol8_aarch64_appstream
java-11-openjdk-demo-11.0.16.0.8-1.el8_6.aarch64.rpm568adb3176b8b3a1b8e88e1209ca8ce20d54274c08f3e83118443bc6276d2ddb-ol8_aarch64_appstream
java-11-openjdk-demo-fastdebug-11.0.16.0.8-1.el8_6.aarch64.rpmcadcd1bb429c76a00a425d7e6daa34c29145f3580025e552d1594e77cfc70565-ol8_aarch64_codeready_builder
java-11-openjdk-demo-slowdebug-11.0.16.0.8-1.el8_6.aarch64.rpm37e5a2d203375464db6bfd3488fb91030b0a821a41479d6aa01c74a01bbb07c3-ol8_aarch64_codeready_builder
java-11-openjdk-devel-11.0.16.0.8-1.el8_6.aarch64.rpm938b0502dc18b54a669e4482524b7a2cbe8528dcf8f186fe339f62061d2c52ff-ol8_aarch64_appstream
java-11-openjdk-devel-fastdebug-11.0.16.0.8-1.el8_6.aarch64.rpm2cd27a43d7ac52fc7787884df1fdc16c6e26f0e8d9d04c41c9a7da17767ec4d2-ol8_aarch64_codeready_builder
java-11-openjdk-devel-slowdebug-11.0.16.0.8-1.el8_6.aarch64.rpmae4ff711786f37ab3ed0afe4661c834a3283daef2d7d80ce873d832dbbaaecf6-ol8_aarch64_codeready_builder
java-11-openjdk-fastdebug-11.0.16.0.8-1.el8_6.aarch64.rpm567c374331dcd7b79adff32f3f990ecc00bf6b6c86223b29dab756c1cf2f064c-ol8_aarch64_codeready_builder
java-11-openjdk-headless-11.0.16.0.8-1.el8_6.aarch64.rpma6e39c99d0a063b5474fbc7ad232693615cae0efb748848ebf820391278473d2-ol8_aarch64_appstream
java-11-openjdk-headless-fastdebug-11.0.16.0.8-1.el8_6.aarch64.rpma287c9aa455f2e6c7c17016e6441c55afde14f1f27badca796ac09dbeb75d84b-ol8_aarch64_codeready_builder
java-11-openjdk-headless-slowdebug-11.0.16.0.8-1.el8_6.aarch64.rpmc1121982bf6346ab5da865ada8198f0b8de283cba2c77f5127ff073298e7fe9f-ol8_aarch64_codeready_builder
java-11-openjdk-javadoc-11.0.16.0.8-1.el8_6.aarch64.rpm2b639e9826953e1873bdfa929231a913b1c43c25f63fd35d9369b644e7831cd2-ol8_aarch64_appstream
java-11-openjdk-javadoc-zip-11.0.16.0.8-1.el8_6.aarch64.rpm505b2c7fa36d233ccdc02d25baaf02f675faf566b9a840ff910d4058958deba6-ol8_aarch64_appstream
java-11-openjdk-jmods-11.0.16.0.8-1.el8_6.aarch64.rpmf37efdc6b71d493dea588e0987def280fac2397583e1b3eaedb4fc0a728e38fd-ol8_aarch64_appstream
java-11-openjdk-jmods-fastdebug-11.0.16.0.8-1.el8_6.aarch64.rpm5f163ad39b2a7c1e3b65269c3dbc292a522d781d479b0665ad0c61ffaae73311-ol8_aarch64_codeready_builder
java-11-openjdk-jmods-slowdebug-11.0.16.0.8-1.el8_6.aarch64.rpmffa56a8a007f7b0da79d7b2e516b323f0f4a6039615db33dce34825dc97d3bb8-ol8_aarch64_codeready_builder
java-11-openjdk-slowdebug-11.0.16.0.8-1.el8_6.aarch64.rpm25d87a760a20bd2264301a1e78c4cef457afc8e2e5e17bff08eee18902be9900-ol8_aarch64_codeready_builder
java-11-openjdk-src-11.0.16.0.8-1.el8_6.aarch64.rpm8bafca831cd5ebc97ffe82ee7eabad302d9d1a1d631c50b181143c633394173c-ol8_aarch64_appstream
java-11-openjdk-src-fastdebug-11.0.16.0.8-1.el8_6.aarch64.rpm763954d3190a50ca15cc07c5ef1689604d474363597899b5f2839e1f11297a23-ol8_aarch64_codeready_builder
java-11-openjdk-src-slowdebug-11.0.16.0.8-1.el8_6.aarch64.rpm79290bdbd2ad176827ed8edb9d908f112048c75af1d180a88f736381b835a024-ol8_aarch64_codeready_builder
java-11-openjdk-static-libs-11.0.16.0.8-1.el8_6.aarch64.rpm275ba3f71901caee99e49bfdfc90705d4b47a033c66474a6e9ed9926a8cc25e6-ol8_aarch64_appstream
java-11-openjdk-static-libs-fastdebug-11.0.16.0.8-1.el8_6.aarch64.rpma592c6d21b4c74373ba6a8e8a92d06a9419a36d07c650be2c6b63b09b118cd02-ol8_aarch64_codeready_builder
java-11-openjdk-static-libs-slowdebug-11.0.16.0.8-1.el8_6.aarch64.rpm95ddb013e107550f5fe50bee0f355eacfce74e0e3ceb6069516b335861adc4e6-ol8_aarch64_codeready_builder
Oracle Linux 8 (x86_64) java-11-openjdk-11.0.16.0.8-1.el8_6.src.rpm4facc3b75a4af5f768c466153a67f1b4431b1021a8fc2d3fe88f1487cbb645ef-ol8_x86_64_appstream
java-11-openjdk-11.0.16.0.8-1.el8_6.src.rpm4facc3b75a4af5f768c466153a67f1b4431b1021a8fc2d3fe88f1487cbb645ef-ol8_x86_64_codeready_builder
java-11-openjdk-11.0.16.0.8-1.el8_6.x86_64.rpm407222128307f9bd74347ba92774f8f589a73b11d96d443e4f3fd3b2e84b1ed0-ol8_x86_64_appstream
java-11-openjdk-demo-11.0.16.0.8-1.el8_6.x86_64.rpmc8c4529003063c211a9fdf34bc70f603d234290451afab30526c8143c6996f03-ol8_x86_64_appstream
java-11-openjdk-demo-fastdebug-11.0.16.0.8-1.el8_6.x86_64.rpm9369d803da2ad08ec4fa43297926370a8c3fd3453972f582211182c258d3c774-ol8_x86_64_codeready_builder
java-11-openjdk-demo-slowdebug-11.0.16.0.8-1.el8_6.x86_64.rpmc428b5d4a98ce63ba91189baaaac1f078223cd04ec7a4034f42210db4823529e-ol8_x86_64_codeready_builder
java-11-openjdk-devel-11.0.16.0.8-1.el8_6.x86_64.rpm3027027fd65e35ff0d716b56f7d23a36de1e31884cd1b4cd83a672ca1ea5213b-ol8_x86_64_appstream
java-11-openjdk-devel-fastdebug-11.0.16.0.8-1.el8_6.x86_64.rpme74ff20275c616b40ec2f01d2a5286b76826f726f5ccd4d0ecebba4184d0f7e1-ol8_x86_64_codeready_builder
java-11-openjdk-devel-slowdebug-11.0.16.0.8-1.el8_6.x86_64.rpmfbd564499bc8cbc20af18319eb4f314801c08e9c019be175d91b2ed006449719-ol8_x86_64_codeready_builder
java-11-openjdk-fastdebug-11.0.16.0.8-1.el8_6.x86_64.rpmd5110ae3767fee1070e3f8e0c7e329b52ba20151209797c2480dd9c43c0892c0-ol8_x86_64_codeready_builder
java-11-openjdk-headless-11.0.16.0.8-1.el8_6.x86_64.rpm84af139eb23089cf3c267b59288bb308d94d297221051d83d6a97791eaac83b5-ol8_x86_64_appstream
java-11-openjdk-headless-fastdebug-11.0.16.0.8-1.el8_6.x86_64.rpm11e5e9996e7e30a42ad29e1d02603f5f122050677de627368836926de382baa9-ol8_x86_64_codeready_builder
java-11-openjdk-headless-slowdebug-11.0.16.0.8-1.el8_6.x86_64.rpm094a3e647bb1d0f19375a6c94207fcdabf23258f2044e4acbeb41edad0509491-ol8_x86_64_codeready_builder
java-11-openjdk-javadoc-11.0.16.0.8-1.el8_6.x86_64.rpm13da7d7dac855495dfdb3b748373a3f4ef9dbc87a6b55e8460eb492176df7b28-ol8_x86_64_appstream
java-11-openjdk-javadoc-zip-11.0.16.0.8-1.el8_6.x86_64.rpm33ce9c55317ba911d91f22bdb25d3bf4612c5314cdb11616ad8e552ff3844f67-ol8_x86_64_appstream
java-11-openjdk-jmods-11.0.16.0.8-1.el8_6.x86_64.rpm7b4b0a617cd912f2b1153faa55498a40449b2833cf853bf7e9f92e2e70ad92b4-ol8_x86_64_appstream
java-11-openjdk-jmods-fastdebug-11.0.16.0.8-1.el8_6.x86_64.rpm09676cb2ab46cff3e2e6322fe0a00bfd297729bd6759720ac0706574329f7db6-ol8_x86_64_codeready_builder
java-11-openjdk-jmods-slowdebug-11.0.16.0.8-1.el8_6.x86_64.rpm6bb97bb75f7ca59cebb4d708b3ab250632d38040616e31a809e51c2ec62616fa-ol8_x86_64_codeready_builder
java-11-openjdk-slowdebug-11.0.16.0.8-1.el8_6.x86_64.rpm90bce4c2d9d97cbca5e75ae61c592a5b7c641ca672c2a64276c4205c0db6021e-ol8_x86_64_codeready_builder
java-11-openjdk-src-11.0.16.0.8-1.el8_6.x86_64.rpm70290d277e494af40a09b6476ddd0ab071c3ea0d605c1119638e0050a2dca0f6-ol8_x86_64_appstream
java-11-openjdk-src-fastdebug-11.0.16.0.8-1.el8_6.x86_64.rpm2c8b036d27d0f7bb3d5cd87dea6c4ec523962e7a862971f1ddf364a1e2fb667f-ol8_x86_64_codeready_builder
java-11-openjdk-src-slowdebug-11.0.16.0.8-1.el8_6.x86_64.rpmc09a19591b0ae1bccf16add7db941bd15d6ff2d00f0eb2d3a3590c95e8a38f90-ol8_x86_64_codeready_builder
java-11-openjdk-static-libs-11.0.16.0.8-1.el8_6.x86_64.rpm280cfb5050d7331647a115d10f86b3783a6e4b25e590522baf3dc97d4db5ad47-ol8_x86_64_appstream
java-11-openjdk-static-libs-fastdebug-11.0.16.0.8-1.el8_6.x86_64.rpmee13e358a7fd92d7929ff68ba476c3b61589092b153e4e1409a6a4d2cd85e5af-ol8_x86_64_codeready_builder
java-11-openjdk-static-libs-slowdebug-11.0.16.0.8-1.el8_6.x86_64.rpmc785e0ae45fcd97d625ce71651e4f8a4ffa4d5ae854001ee6e43f85b869481cf-ol8_x86_64_codeready_builder



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete